The Anatomy of Exposure: Why the Market Cannot Agree on What Counts as One
Two exposure-management tools can examine the same environment and return very different numbers. That does not necessarily mean that either is wrong.
15,000 exposures, fewer than one per cent of them CVEs
In May 2024, XM Cyber and the Cyentia Institute estimated that a typical organisation had about 15,000 exposures. Fewer than one per cent were vulnerabilities with CVEs [1]. Roughly 80 per cent were associated with identity and credential misconfigurations [1].
These are slightly awkward figures for vulnerability management. The familiar machinery of scanners, patching programmes, SLAs and vulnerability backlogs appears to deal with only a small part of what is now being described as exposure.
There is an awkwardness for exposure management too. A single vulnerability scanner can readily generate tens of thousands of critical findings. Yet the supposedly broader category produces only 15,000 exposures.
The difficulty is mostly one of accounting. The figures are not...
Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE