BLOG

Cybersecurity insights.

Technical analysis of exposure management, written by the people who work on attack surface every day.

See all tags (53)

Featured #exposure validation

Exposure validation when the exploit arrives in hours

The gap between a CVE going public and a working exploit shrank from 756 days to minutes. Weekly scanning and a CVSS-ordered queue no longer keep up with that clock.

#exposure management#preemptive

Is your program preemptive or just periodic? Two tests

Preemptive became a sales adjective and stopped carrying information. What is left is two numbers you can gather in a single afternoon.

#incident response#attack surface

What external visibility gives an incident response team

Sizing an incident is the hardest part of responding to one, and NIST says so in writing. Two lists built from outside change that estimate.

#attack surface#CTEM

Why a company that got hit tends to get hit again

The second incident almost never reuses the first one's vector. What repeats is the condition that opened it, and that survives the response.

#CTEM#exposure management

CTEM, PEM, PTEM, and proactive security: what changes

Five names reached the market in two years for nearly the same work. The difference that decides a purchase is in none of them.

#ransomware#CTEM

Ransomware attack: how it works and how to prevent it

How a ransomware attack works stage by stage, the types that exist, and the ten-item prevention checklist that closes the doors attackers use.

#validation#exploitability

Exploitability validation: confirm before you report

Technically confirming that an exposure is exploitable before reporting it removes false-positive noise and orders remediation by real risk.

#EASM#ASM

EASM: discovering and classifying what you expose online

EASM continuously discovers exposed assets from the root domain, assigns an owner, and classifies exposures, with no agents to install.

#TPRM#vendor risk

Third-party risk (TPRM) in Brazil: BACEN and LGPD

TPRM extends risk management to the supplier chain. In Brazil, BACEN and LGPD make continuous monitoring of third parties a requirement.

#CRQ#FAIR

Taking a cyber risk number to the board

Boards rarely reject the number for being large. They reject it because they cannot see where it came from. What belongs on the page first.

#third-party risk#vendor risk management

Third-party risk: why breaches begin at the supplier

The third-party share of breaches doubled in a single year. Why the point-in-time questionnaire failed, and what replaces it.

#supply chain#supply chain attack

Supply chain attacks doubled in 2025: how to react

Supply chain attacks doubled in 2025, and one in five incidents involved third parties. Understand what changed and how to reduce your exposure.

Page 1 of 2