A Lorenz Curve is a graph used to show how unevenly a resource is distributed across a set of items. In security analysis, it can illustrate whether vulnerabilities, misconfigurations, or other findings are concentrated in a few assets or spread evenly across the codebase.
Expanded Definition
A Lorenz Curve plots cumulative share against cumulative population or asset count, making inequality visible at a glance. Outside economics, the same shape helps security teams see whether risk is concentrated in a small number of systems, repositories, accounts, or findings rather than distributed uniformly.
The useful boundary is that a Lorenz Curve describes distribution, not root cause. It can show that a few assets hold most vulnerabilities, but it cannot explain why those assets are high risk, whether the pattern is normal for the environment, or whether the concentration reflects exposure, scan coverage, or genuine control weakness. That distinction matters in security reporting because a steep curve can mean either a manageable hotspot or a structural blind spot, depending on what is being measured.
In practitioner terms, the curve is most helpful when the counted unit is well defined. If one team counts findings by host and another counts them by service, the resulting curves are not directly comparable. The same caution applies when the subject is code quality, misconfigurations, or identity-related exposure, because the measurement boundary changes the interpretation.
Examples and Use Cases
Security teams use Lorenz Curves to make concentration patterns easier to discuss than raw totals. The graph is especially useful when leaders need to understand whether a small set of assets or control owners is carrying most of the operational burden.
- A vulnerability program plots open findings by host and sees that a handful of internet-facing servers account for most unresolved issues.
- A cloud security team compares misconfigurations by account and finds that one business unit contributes a disproportionate share of policy drift.
- A code scanning team uses the curve to show that most high-severity defects are concentrated in a few repositories with unusually high change velocity.
- An identity team examines privileged access exceptions and sees whether a small number of systems or admin groups create most of the exception workload.
The main tradeoff is interpretability versus precision. A Lorenz Curve is excellent for spotting skew, but it does not replace root-cause analysis, severity weighting, or exposure context. Two environments can produce similar curves while having very different operational meaning.
Security Implications
When the distribution is highly unequal, the security implication is often concentration risk: a small number of assets or owners can drive most of the exposure, remediation effort, or operational noise. That creates a practical problem because failures in those hotspots can affect a large share of the environment, and teams may mistakenly assume the broader estate is equally healthy.
A steep curve can also hide measurement issues. If the scanner has poor coverage, if one asset class is inspected more heavily than others, or if findings are grouped inconsistently, the curve may reflect visibility bias rather than true concentration. In that case, the graph can support the wrong priority decisions.
The observable symptom is not the curve itself but the pattern it reveals: repeated findings in the same few places, repeated exceptions for the same owners, or repeated control breaks in the same service tier. For NHI Management Group, that matters because concentration patterns are often the first signal that a small set of identities, repositories, or workloads deserves deeper control review.
Domain and Governance Relevance
In governance terms, a Lorenz Curve helps decide whether risk treatment should focus on the tail of the distribution or on the estate as a whole. It is not a control by itself, but it is a strong prioritisation aid when leaders need to justify where remediation effort will have the greatest impact.
For identity, access, and machine-related security programs, the curve becomes more valuable when it reveals that a narrow group of privileged accounts, service accounts, or automated workflows accounts for most exceptions or most exposure. That does not automatically make the subject an NHI problem, but it does change how ownership and lifecycle controls should be interpreted. The issue is then not just how many findings exist, but whether the same entities keep accumulating them.
Used well, the Lorenz Curve supports governance conversations about fairness, concentration, and control coverage. Used poorly, it becomes a visually compelling summary that hides the operational question of what is driving the inequality in the first place.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | ID.RA-1 — Risk Assessment | Distribution plots help prioritise where risk concentrates. |
| GV.RM-01 — Risk Management Strategy | Concentration evidence informs treatment priorities and ownership. | |
| Recommendation — Use ID.RA-1 to identify concentrated exposure hotspots and focus assessment on the highest-burden assets. Use GV.RM-01 to set remediation priority based on the most concentrated risk segments. | ||
| CIS Controls v8 | CIS 7 — Continuous Vulnerability Management | Curves often summarise skew in vulnerability backlogs. |
| CIS 4 — Secure Configuration of Enterprise Assets and Software | Uneven misconfigurations often appear as concentrated control drift. | |
| Recommendation — Apply CIS 7 to target remediation where findings cluster most heavily. Use CIS 4 to reduce configuration drift in the few systems driving most exceptions. | ||
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 10, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org