An exposure becomes organizational risk when it is reachable, relevant to something the business cares about, and left without accountable follow-through. A public service, vulnerable product, stale certificate, ownership gap, or configuration finding is useful evidence, but severity alone does not tell the organization what to fix first or whether the fix worked.
Threat Foundry connects External Attack Surface Management, Asset Inventory, vulnerability intelligence, investigation, remediation, and reporting so teams can move from an approved external finding to an owned and verifiable outcome.
Start with an approved external scope
Useful exposure management begins with authority. Threat Foundry EASM is designed around customer-approved domains, IP addresses, CIDR ranges, targets, and selected ports. It is not a generic internal scanner and should not be used to discover infrastructure outside the customer’s authorized scope.
Within that boundary, teams can review external assets, observed services, HTTP and TLS evidence, risky-service findings, freshness, and ownership gaps. The first objective is to establish what is currently visible and how confident the team is in that observation.
Discovery evidence should retain its collection time, source, target, and lifecycle. A finding from an old snapshot should not carry the same weight as a current observation against an approved asset.
Add business context before prioritizing
The same exposed service can represent very different risk on a temporary test system and a production identity service. Asset Inventory adds the context a scanner usually cannot infer: owner, business unit, environment, application, criticality, and other approved metadata.
Use that context to answer practical questions:
- Which business service depends on the asset?
- Who can authorize or implement a change?
- Does the asset handle sensitive data or privileged access?
- Is the observed service expected and documented?
- How recently was the asset or finding verified?
Scanner CSV or JSON findings and supported vulnerability-management integrations can enrich the record when they are configured. They should supplement approved inventory and evidence, not silently redefine ownership or scope.
Prioritize evidence, exploit context, and consequence
A critical label is not always the most useful first queue. Combine technical severity with business criticality, observed exposure, ownership, freshness, and credible exploitation context.
CISA KEV status identifies vulnerabilities known to have been exploited. EPSS context, when available, can add another prioritization signal. Neither replaces verification that the affected product and version are present on the customer asset.
High-value queues often include:
- KEV-related findings on critical or internet-facing assets.
- New or materially changed services.
- Risky services with no accountable owner.
- Overdue findings whose evidence is still current.
- Items awaiting a focused retest after reported remediation.
This approach reduces risk more effectively than sorting by scanner severity alone because it directs limited time toward exposures with both evidence and organizational consequence.
Use attack-path analysis as a reviewable hypothesis
An exposed asset may be an entry point, but it does not automatically prove a path to a sensitive system. Use architecture context, ATT&CK techniques, identity reach, linked assets, KEV evidence, and available telemetry to form a bounded hypothesis.
The Attack Path Builder and Threat Modeling workspaces can help reviewers ask what an attacker would need next, which trust boundary could be crossed, and what data would confirm or reject the path. A linked hunt can then test whether relevant behavior appears in customer telemetry.
An attack path is a claim to investigate, not a conclusion produced merely because two records are related.
Preserve assumptions and missing evidence. An unknown identity relationship or absent log source should remain visible rather than being treated as proof that the path is safe.
Turn the finding into accountable remediation
A material exposure needs more than a status label. Assign an owner, due date, ticket or reference, lifecycle state, and the evidence required for closure. When multiple teams are involved, create a triage or case handoff that preserves the original asset and finding context.
Record decisions explicitly:
- Remediate: remove, patch, reconfigure, restrict, or otherwise reduce the exposure.
- Accept: document the authorized rationale and review or expiry terms.
- False positive: retain the evidence and reviewer reasoning.
- Suppress: apply a bounded exception without deleting history.
- Escalate: move the work into a broader risk, architecture, detection, or incident workflow.
Keeping these outcomes visible prevents the queue from looking better simply because findings disappeared from the default view.
Retest before claiming closure
After remediation, run a focused retest against the same approved scope and relevant service. A finding that is absent from a later snapshot should become a retest question, not automatic proof of remediation. Collection differences, timing, network conditions, or asset changes can also explain an absence.
An analyst should compare the original and current evidence, confirm the intended change, and record the validation result. If the result is incomplete or the source is stale, keep the outcome open or indeterminate.
Measure whether exposure work changes risk
Useful reporting goes beyond the number of open findings. Track:
- Critical assets with current exposure evidence.
- KEV-related findings by owner and due state.
- New and changed external services.
- Unknown-owner and stale-evidence queues.
- Time from discovery to ownership and treatment.
- Retest results and reopened findings.
- Accepted or suppressed exposures approaching review.
These measures show whether the organization is reducing uncertainty, assigning responsibility, and verifying outcomes.
A practical starting sequence
- Confirm the approved external scope and source freshness.
- Resolve business criticality and ownership for exposed assets.
- Prioritize current KEV, new or changed, unknown-owner, and overdue findings.
- Investigate plausible paths without overstating relationships as proof.
- Assign treatment, owner, due date, and validation criteria.
- Run a focused retest and require analyst review before closure.
- Use material outcomes to inform the organization’s Risk Register, threat modeling, hunts, and detections through the applicable governed workflows.
Exposure management reduces organizational risk when every material finding remains traceable to current evidence, business context, an accountable owner, a treatment decision, and a validated outcome.