Exposure Management Was Supposed to Fix a 30-Year-Old Problem. It Hasn’t.

Exposure management promised a shift from reactive patching to proactive risk reduction. It hasn't delivered: the average serious vulnerability still takes 60 to 100 days to fix. The reason is structural, built around activity instead of decisions.

Onit Security | Apr 28, 2026

TL;DR

  • Exposure management in cybersecurity was supposed to move organizations from reactive patching to proactive risk reduction. It hasn't, because the model is built around activity, not decisions.
  • Most exposure management software and exposure assessment platforms are built around tasks as the unit of work. A new finding becomes a new ticket, a new owner, a new review, even if you've seen this exact exposure pattern a hundred times before. The work repeats. It never compounds.
  • Exposure management vs vulnerability management isn't just a naming debate: vulnerability management tracks CVEs; exposure management is supposed to drive verified risk reduction across the full attack surface.
  • Decision-Based Exposure Management, the operating model we're building at Onit Security, changes the unit of progress from tasks to decisions. Humans define how recurring exposure patterns should be handled. Agents execute at machine speed. MTTR drops from weeks to hours.

In 2021, a sophisticated Iranian threat actor breached a well-regarded network access control company. Its CEO, Ofer Amitai, would later become one of Onit Security's co-founders. The forensics was thorough. The root cause, when it was finally uncovered, was almost mundane: a single vulnerability, rated medium severity, that had never been remediated. Not because the team was negligent or lacked tools, but because the vulnerability never surfaced to the top of a backlog. It was drowned out by noise.

That breach shaped how we think about exposure management. The lesson wasn't "patch faster." It was that the system itself is broken.

So let's start with the basic question: what is exposure management, really? In cybersecurity, exposure management is the practice of continuously identifying, prioritizing, and reducing the attack surface across an organization's assets, vulnerabilities, misconfigurations, identity risks, and more. It sits above vulnerability scanning: where a scanner tells you what exists, a cybersecurity exposure management practice  is supposed to tell you what actually matters, who needs to fix it, and whether it got fixed. The operative words are "supposed to."

Thirty years of vulnerability management came first, and it produced an industry built around activity, not outcomes. Exposure management was supposed to change that.

Organizations have invested heavily in scanners, dashboards, orchestration platforms, and AI-powered prioritization engines. And yet the average time to remediate a serious vulnerability still runs between 60 and 100 days by sector, according to Edgescan's vulnerability statistics. The queue never shrinks. Boards still ask the same unanswerable question: "Are we improving?"

We believe the reason is structural. And structural problems don't get fixed by adding more tools on top of them.

The Real Problem Isn't Volume. It's Missing Context.

When Gartner introduced the concept of Continuous Threat Exposure Management (CTEM) in 2022, it was a genuine step forward, a framework that pushed security teams to think beyond scanning and toward continuous validation of exposure risk. But even CTEM, in most implementations, runs into the same wall: findings that lack the context required to act on them intelligently.

Consider what a modern enterprise scanner actually produces. Tens of millions of findings, each with a CVE ID and a severity score. What those findings typically don't tell you:

  • Is this vulnerability actually exploitable in our specific environment, given our network topology, our compensating controls, our WAF rules?
  • Does this asset sit inside our PCI cardholder data environment, or in a dev sandbox that gets rebuilt weekly?
  • Who, among the 10 people with some claim to ownership over this asset, has the authority to approve a remediation action?

Without answers to those questions, prioritization is theater. You're sorting a list by CVSS score and calling it a risk management program.

We've seen versions of this at organizations of every size. A Fortune 500 retailer running three separate vulnerability management platforms, none of which could tell their TVM team whether a flagged Apache Struts instance was internet-facing or sitting behind three layers of network controls. A healthcare system with a 400,000-finding backlog where fewer than 2% had confirmed ownership assigned. The tools were generating data. The data was not generating decisions.

Exposure Assessment vs. Exposure Management: A Critical Distinction

Part of why the market has struggled to make progress is a category confusion that the vendor landscape has never fully resolved. Many of what the industry calls "exposure assessment platforms" are exactly that: assessment tools. They scan, they score, they report. They're exceptionally good at answering "what is exposed?" They are structurally unable to answer "what are we doing about it, and is it working?"

This is the core difference between exposure assessment and cybersecurity exposure management programs:

Exposure assessment platforms produce a picture of risk at a point in time. They tell you your attack surface exists. Leading tools in this space, Tenable, Qualys, Rapid7, and the newer CAASM players like Axonius, have made that picture increasingly rich and accurate. That's valuable. But a picture doesn't remediate anything.

Exposure management is the operational layer that sits on top of that picture and drives it to resolution. It answers the harder questions: who is accountable, what is the remediation path, has it been executed, and has risk actually decreased? This is where most organizations have a gap, and where most exposure management software has historically underdelivered.

The distinction matters even more when you introduce the comparison of exposure management vs vulnerability management. Vulnerability management, as a practice, is largely asset-and-CVE-centric: you track individual findings against individual assets and measure your patch rate. Exposure management broadens the aperture to include business context, attack path analysis, and organizational accountability. A vulnerability management program can report 90% of criticals patched and still leave the organization exposed, if the 10% that remain are the ones an attacker would actually use.

Assessment tells you what's broken. Management tells you whether it's getting fixed, and holds the organization accountable for the answer.

Decision-Based Exposure Management, the category we're building at Onit Security, goes a step further than either. It doesn't just manage the pipeline of exposure findings, it captures the organizational decisions that determine how those findings get resolved, encodes them, and executes them at machine speed. The unit of progress isn't a patched CVE or a closed ticket. It's a decision that fires automatically every time its conditions are met.

The Ownership Problem: Why "Who Owns This?" Can Take Weeks to Answer

Of all the friction points we've encountered in exposure management, ownership attribution is the one that surprises people most when they see it written down plainly. In 2026, in an enterprise running best-in-class ITSM and CMDB tooling, identifying who is authorized to approve remediation of a single vulnerability can take weeks.

Here's why. Every asset in a modern enterprise sits within a hierarchy of responsibility. A cloud instance running a vulnerable version of OpenSSL might involve:

  • The platform team that owns the underlying infrastructure
  • The DevOps team that deployed the container
  • The application owner whose service depends on it
  • The network team responsible for the subnet
  • The compliance team that governs the data classification

None of these relationships live in one place. CMDB entries are incomplete or stale. Org charts don't reflect operational reality. The person who set up the system three years ago left after an acquisition.

So the vulnerability management team does what they've always done: they open a ticket, they wait, they follow up on Slack, they escalate to a manager, they wait some more. And because most organizations have policies, intentional or de facto, that close unactioned tickets after a set period, sometimes the ticket just disappears. The vulnerability remains.

Ownership attribution isn't a data problem. It's an organizational knowledge problem, and you can't solve it by buying another SaaS integration.

Our approach at Onit Security is to build a dynamic ownership model that learns from every interaction. Each time an analyst confirms an owner, routes a ticket correctly, or resolves an assignment dispute, that signal is captured and compounds. Over time, the system develops a working model of organizational ownership that goes well beyond what any CMDB reflects, because it reflects how the organization actually operates, not how it was documented five years ago.

Decision-Based Exposure Management: The Model We Believe In

The insight at the heart of our approach is deceptively simple: most of the work in exposure management isn't unique. It's repetitive.

A specific vulnerability family appears across a class of assets with a consistent ownership profile. The right remediation path is known. The business context is understood. And yet every instance of that pattern triggers a fresh round of investigation, triage, ticket creation, ownership discovery, and back-and-forth communication. The work gets done, slowly, and then it happens again next month with the next batch of findings.

Decision-Based Exposure Management breaks that cycle by changing the unit of progress from tasks to decisions.

Instead of distributing thousands of tasks across the organization, we surface recurring patterns to human analysts and ask for a single high-level decision: given this vulnerability profile, these asset characteristics, and this ownership structure, what should happen? That decision is then encoded and executed by agents across every matching instance, automatically, without requiring a human in the loop for each one.

Think about how Cursor or GitHub Copilot changed the relationship between a senior engineer and repetitive coding tasks. The engineer doesn't stop being valuable. They become more valuable, because their judgment is now applied at scale rather than consumed by work a tool could handle. We're building the equivalent for security operations.

Humans make decisions. Agents perform the execution. That's not a philosophical position; it's an operational model that directly compresses MTTR.

The compounding effect is real and measurable. The first time an analyst defines a remediation decision for a pattern, it covers that instance. The second time a matching pattern appears, the decision fires automatically. By the tenth iteration, what used to consume days of analyst time is happening in minutes, and the organizational knowledge that produced the decision has been preserved in a form that survives team turnover, reorganizations, and acquisitions.

Institutional Knowledge Is a Security Asset, And Most Organizations Are Letting It Drain Away

When we talk about "tribal knowledge" in security operations, we're not being romantic about it. We mean something specific: the accumulated understanding of an environment that determines whether a given finding is actually dangerous, who has the authority to fix it, and what approach will work without breaking something else.

In a small organization with a strong, hands-on CISO, this knowledge is accessible and actionable. That CISO knows what every system does, who owns it, and what the remediation history looks like. When a scanner surfaces a critical finding at 2am, they can make a fast, accurate call.

At enterprise scale, particularly in organizations that have grown through M&A activity, which describes most large enterprises in 2026, that knowledge is shattered across dozens of teams, multiple documentation systems, and the memories of people who may have left the company years ago. When CrowdStrike's 2024 Falcon sensor update caused widespread outages, one of the most significant challenges organizations faced in the aftermath wasn't technical: it was organizational. Who owned the recovery decision for which systems? The companies that had that knowledge well-organized recovered faster. The ones that didn't spent days in escalation loops.

At Onit Security, we treat institutional knowledge as a first-class security asset. Our platform is designed to capture, structure, and operationalize that knowledge at every decision point, building what we describe as a decision graph that reflects the real business context of the environment, not a static snapshot from a CMDB entry.

Machine-Speed Attacks Demand Machine-Speed Defense

In late 2025, Anthropic documented the first reported case of a state-sponsored group manipulating an AI agent to run a cyber-espionage campaign largely on its own, orchestrating multi-stage attacks with a speed and adaptability that manual defense cannot match. Anthropic's Claude Mythos research, published in April 2026, pushed further still: the model autonomously discovered and wrote a working exploit for a long-dormant remote code execution vulnerability in a widely used codebase, one of thousands of zero-days it surfaced across major operating systems and browsers. What previously required days of attacker effort, reconnaissance, exploit selection, lateral movement, exfiltration, is now happening in minutes. Exploit kits are being generated and evolved in real time to bypass specific security controls.

This is not a future threat. It is the current environment.

The implication for exposure management is direct: if a vulnerability exists in your environment and an attacker's AI agent identifies and weaponizes it faster than your team can investigate the finding, you've already lost. The traditional model, where mean time to remediation is measured in weeks, is not a viable posture against AI-powered adversaries.

What machine-speed defense requires is a closed loop: rapid exploitability validation, immediate ownership identification, predefined mitigation logic, and automated execution. When those elements are in place and decisions have been made in advance, remediation can occur faster than an attacker can build an exploit. That window, between vulnerability disclosure and exploit availability, is where defenders can regain the advantage. We're building toward that capability, and we're already seeing it compress remediation timelines from weeks to hours in early deployments.

What This Means for How CISOs Should Be Thinking Right Now

The model of hiring more analysts to work through a bigger backlog has hit its ceiling. The attack surface is growing faster than headcount can scale. AI-powered adversaries are operating at speeds that make manual workflows structurally inadequate.

We believe the CISOs who will be most effective over the next three to five years are the ones who make two shifts now:

First, from task distribution to decision capture. Stop building workflows that route tasks to humans for every finding. Start building systems that capture human decisions about classes of findings, and let agents execute those decisions at scale.

Second, from detection metrics to risk reduction metrics. MTTR is a useful proxy, but the real question is: how quickly are we reducing actual business risk? That requires translating vulnerability data into business context, not just surfacing CVEs, but understanding which exposures are genuinely dangerous in your specific environment, to your specific business processes, given your specific controls.

These aren't incremental improvements to existing exposure management software. They're a different operating model. The organizations that get there first won't just have better security outcomes, they'll have the only sustainable posture against the threat landscape that's already here.

Frequently asked questions

Exposure management is the continuous practice of identifying, prioritizing, and reducing an organization's attack surface, including vulnerabilities, misconfigurations, and identity risks, with direct accountability for resolution. Unlike point-in-time scanning, it connects risk findings to business context, ownership, and verified remediation outcomes. Where a scanner tells you what's exposed, an exposure management cybersecurity practice tells you what to do about it and whether it worked.

Vulnerability management is asset-and-CVE-centric: it tracks individual findings against individual assets and measures patch completion rates. Exposure management broadens the scope to include business context, attack path analysis, and organizational accountability for verified risk reduction. A vulnerability management program can report 90% of criticals patched and still leave the organization dangerously exposed, if the remaining 10% are the vulnerabilities an attacker would actually exploit. Exposure management is designed to catch that gap.

Exposure assessment platforms scan, score, and report, producing an increasingly accurate picture of what's exposed at a point in time. Exposure management is the operational layer that drives findings to resolution: assigning ownership, executing remediation, and verifying that risk actually decreased. Assessment answers "what is broken?" Management answers "what are we doing about it, and did it work?" Most organizations have invested heavily in the former and significantly underinvested in the latter.

Decision-Based Exposure Management is a new operating model, and the category Onit Security is building, that changes the unit of progress from tasks to decisions. Instead of routing every exposure finding to a human analyst for individual triage, it identifies recurring exposure patterns, captures a single human decision about how that pattern should be handled, and deploys AI agents to execute that decision automatically at scale. The result is a structural compression of MTTR: from weeks and months to hours.

MTTR stays high because the root cause is manual coordination, not insufficient tooling. Confirming exploitability, locating the right asset owner, designing a mitigation that doesn't create new dependencies, and verifying the fix, each of these steps is done manually, at scale, for each individual finding. Adding more software to a manually-operated pipeline makes the pipeline slightly faster; it doesn't eliminate the pipeline. Decision-Based Exposure Management eliminates the repetitive steps entirely by encoding them as decisions that execute automatically.

Most exposure management software speeds up the task pipeline, helping teams triage faster, assign ownership more accurately, and track remediation status. Onit Security operates at a different level: we capture the decisions that govern how exposure patterns are handled, and deploy agents to execute those decisions at machine speed. The platform gets smarter over time as decisions compound, building a persistent knowledge graph of organizational context, ownership logic, and remediation history that survives team turnover and reorganization.

Onit Security is building the agentic exposure management platform that makes this operating model possible. If you're ready to see what Decision-Based Exposure Management looks like in practice, reach out at onit.security.

Heading to Fal.Con?

Find the panthers at booth #1649

Get a Demo