How Top CISOs Approach Exposure Management in the Context of Managing Cyber Risk
文章介绍了由Tenable赞助的Exposure Management Leadership Council的报告,指出CISO们认为暴露管理是统一主动安全的战略性方法。该方法可帮助应对从向董事会汇报网络风险到AI安全、控制监控及漏洞修复问责等多方面挑战,并为未来制定原则和最佳实践提供方向。 2025-9-18 13:0:0 Author: www.tenable.com(查看原文) 阅读量:3 收藏

Wondering what your peers think of exposure management? New reports from the Exposure Management Leadership Council, a CISO working group sponsored by Tenable, offer insights. 

Key takeaways

  1. The CISOs who make up the Exposure Management Leadership Council see exposure management as a strategic and game-changing approach to unified proactive security.
     
  2. They believe exposure management can help them address a wide variety of challenges, from reporting to the board on cyber risk to AI security, controls monitoring, and driving accountability for vulnerability and exposure remediation.
     
  3. To learn how exposure management can address these challenges, check out the inaugural report from the Exposure Management Leadership Council.

If you’re a CISO and you’re like me, you routinely seek your peers’ perspectives on emerging trends and daily challenges. From securing AI to communicating with the board about cyber risk, it’s crucial to know what’s working and what’s not.

With exposure management gaining significant market momentum, you may be wondering if your peers believe there’s any real substance to it.

The answer is a resounding yes. For proof, check out the perspectives of top security leaders who make up the Exposure Management Leadership Council, a working group dedicated to developing and advancing principles and best practices for exposure management.

The Exposure Management Leadership Council functions as a confidential, vendor-neutral forum where senior leaders can share candid insights and practical strategies for managing enterprise-wide exposure. As the Council’s sponsor, Tenable organizes quarterly meetings (which I facilitate), synthesizes meeting discussions into reports and shares these reports industrywide for the benefit of as many security practitioners as possible.

Because Council meetings operate under the Chatham House Rule to foster trust and openness, we don’t attribute any direct quotes or paraphrased statements to specific Council members.

What are CISOs saying about exposure management?

“Exposure management is extremely important for us. We have a very high threat profile and tend to be targeted heavily by advanced persistent threat groups.”

— Member of the Exposure Management Leadership Council

CISOs see exposure management as a solution to the boardroom communication gap

“Exposure management can shift the cyber conversation in the boardroom and make it more strategic.”

— Member of the Exposure Management Leadership Council

Council members believe exposure management can improve their ability to answer the following cyber-related questions that their boards of directors truly care about:

  • How much cyber risk is the organization carrying?

  • Does it exceed our appetite?

  • What’s the potential business impact of this risk?

  • What are the most critical areas to address?

  • What’s the cost of inaction, and which risks are we willing to accept?

Exposure management enables CISOs to shift from reporting on siloed security operations metrics to communicating a clear, unified and business-driven view of an organization’s end-to-end cyber exposure. Council members see the potential for exposure management to help them create a standardized, repeatable and defensible process for measuring and reporting on risk — something akin to a cyber version of the accounting industry’s generally accepted accounting principles (GAAP).

To learn how exposure management can elevate board-level discussions of cyber risk, see the Exposure Management Leadership Council report, “Board Meetings and the Dreaded Cyber Risk Update: A Use Case for Exposure Management.

How do CISOs distinguish between exposure management and vulnerability management?

Prioritizing vulnerabilities and driving accountability for remediation remains a challenge for many CISOs, according to the discussion that took place during the first Council meeting (see the executive summary). They bemoan the inadequacies of relying on CVSS scores alone for prioritization.

While exposure management, by definition, expands the scope of security issues that remediation teams need to address beyond traditional software vulnerabilities, it’s simultaneously designed to unify and enhance risk scoring and prioritization. By taking into account CVSS scores, EPSS data, threat intelligence and business and technical context, exposure management can make it easier for security teams to convince remediation owners to fix the highest-risk exposures — those toxic combinations of vulnerabilities, misconfigurations and excessive permissions that can have significant operational impact when exploited.

The really juicy part of exposure management is that it provides context.

— Member of the Exposure Management Leadership Council

What other use cases for exposure management are CISOs considering?

Council members see AI security and controls monitoring as additional use cases for exposure management. They regard AI as both a new attack surface their security teams need to monitor and a powerful threat vector. They’re concerned about data leaks and threat actors leveraging AI to execute more stealthy and pernicious attacks. Consequently, they recognize the need for exposure management programs to address the rapidly expanding AI attack surface.

Similarly, they see exposure management as a potential solution to yet another challenge: monitoring the effectiveness of their security controls. What makes controls monitoring so difficult, they say, is inadequate attack surface management and visibility:

"What good is saying that you’re 95% compliant with your internal cybersecurity controls if that 95% is based on just 10% of known assets?”

— Member of the Exposure Management Leadership Council

More to come from the Exposure Management Leadership Council

The Exposure Management Leadership Council will continue to meet quarterly and work toward its long-term goal of establishing principles, best practices, policies and frameworks for exposure management. Stay tuned for future reports and updates as we work together to advance exposure management into a strategic discipline.

Robert Huber

Robert Huber

Chief Security Officer, Head of Research and President of Tenable Public Sector

As Tenable’s Chief Security Officer, Head of Research and President of Tenable Public Sector, LLC, Robert Huber oversees the company's global security and research teams, working cross-functionally to reduce risk to the organization, its customers and the broader industry. He has more than 25 years of cyber security experience across the financial, defense, critical infrastructure and technology sectors. Prior to joining Tenable, Robert was a chief security and strategy officer at Eastwind Networks. He was previously co-founder and president of Critical Intelligence, an OT threat intelligence and solutions provider, which cyber threat intelligence leader iSIGHT Partners acquired in 2015. He also served as a member of the Lockheed Martin CIRT, an OT security researcher at Idaho National Laboratory and was a chief security architect for JP Morgan Chase. Robert is a board member and advisor to several security startups and served in the U.S. Air Force and Air National Guard for more than 22 years. Before retiring in 2021, he provided offensive and defensive cyber capabilities supporting the National Security Agency (NSA), United States Cyber Command and state missions.


文章来源: https://www.tenable.com/blog/how-top-cisos-approach-exposure-management-in-the-context-of-managing-cyber-risk
如有侵权请联系:admin#unsafe.sh