Hans Christian Anderson’s classic tale of the emperor that gets duped into a fancy, new, and invisible wardrobe provides lessons in swindling, pride, and truth. It’s only when the emperor struts in front of the commoners that a child finally states, “wait a minute, there’s nothing to this outfit, he’s not wearing anything”.
As security vendors parade out Exposure Management from their portfolios through sales pitches and product marketing, garbed in the similar style of Vulnerability Risk Management (VRM), we must be that child that stops and asks: what exactly comprises the Exposure Management’s outfit? (And since vendor definitions vary from platform to category to solution, we still need to ask what the outfit even is.) Furthermore, is this a new category, the same packaging in the same old outfit, or is this product as naked as the exposed assets it claims to cover?
I spend a lot of time being briefed by vendors and even more time talking to organizations about their security programs. In the past six months, many of my vendor briefings have been about the vendor’s shift towards Exposure Management. And if you look up “exposure” in any thesaurus, you’ll find that it’s just another synonym for “vulnerability”. So while security vendors have their sights on usurping Vulnerability Risk Management (VRM) products, and VRM vendors are shifting towards Exposure Management, teams adopting it will still need to deal with all the same old security problems like prioritization, process, remediation ownership, and obtaining cultural buy-in. Vendors continue to create new categories, while users of their products continue to just need their long-lived problems fully dressed.
Exposure Management Won’t Do Everything, But It Will Help You Prioritize
We do not see Exposure Management as a magic bullet for solving VRM team’s common challenges. However, there is one challenge that Exposure Management is uniquely positioned to address: prioritization. That’s why it’s the focal point of Forrester’s definition of Exposure Management which states:
Exposure Management is a platform that consolidates vulnerabilities and exposures with an organizational perspective, maps them on an attack path, and identifies choke points for remediation teams to prioritize.
In theory, identifying the most critical choke points is an interesting approach to the prioritization problem. As a CISO in a large financial services organization recently told me, “Measuring the ROI of a proactive security program is practically difficult. It’s much easier to measure whether a breach occurred – so why not focus on the vulnerabilities and exposures closest to what would have led to the breach?”
The challenge is that Exposure Management still runs the risk of snowballing into the same challenges around volume, workflow, and analyst experience (AX) that we have with VRM today.
Attack Path Modeling Is Exposure Management’s Flashy Jewelry: Looks Cool, But Low Utility
The most common feature in Exposure Management is attack path modeling. This is a fancy looking screen that maps assets to a graph, shows how these assets are connected, and showcases exposures an attacker could potentially leverage (along with how far they could get).
For most proactive security team members, like vulnerability risk analysts, leveraging the attack path requires a lot of clicking to identify exposures and remediations that may need escalating, when the reality is they need better upfront information, risk calculations and remediation workflows.
Due to its current AX, attack path modeling is unlikely to replace the tidier tactical dashboards common in VRM product. And while the attack path optics are visually interesting, they can be blackholes that lead to misguided escalations or inconclusive information. It simply does not currently fit into the workflow of a vulnerability risk analyst, though the delivery of prioritization insights could be improved through technologies like Generative AI. If anything, the current iteration is better suited to assist SOC roles, like threat hunters, red teamers, and incident responders.
Exposure Management Is Here to Stay
Given the breadth of inputs required for Exposure Management, like asset inventories and vulnerability and security validation assessments, and the depth of insight it’s aiming to provide, Exposure Management is unlikely to become a feature in other products. Instead, it will remain a standalone platform and integrate into larger portfolios from vendors like CrowdStrike or Microsoft. This means more licenses, and more of your wallet dedicated to your existing vendors. We expect all major security portfolio and SecOps vendors to have an Exposure Management offering within the next 12 months alongside stand-alone Exposure Management platforms, like XM Cyber, and existing VRM vendors that are shifting towards exposure management, such as Tenable.
What should you do when your vendor wants to demo their newest Exposure Management solution? Hear them out but take a lesson from that child from The Emperor’s New Clothes, or perhaps your fashionable teenager side-eyeing the drip you plan to wear to that concert. Scrutinize how they address key use cases around visibility, prioritization, and remediation response, and how their specific solution could play into your vendor consolidation strategy. The biggest differentiators for Exposure Management as a market category will be how it addresses the long-lived challenges for proactive security teams, how it improves analyst experience, and what breadth of inputs can provide visibility and context for users.
Schedule a guidance session or inquiry with me to discuss Exposure Management and ways to cut through the noise. Better yet, join me at the Forrester Security & Risk event in November. I’ll be speaking on proactive security in the session, “Activate Proactive Security.”