A
AEV, short for adversarial exposure validation, is the market category Gartner named on 24 March 2026 for technologies that deliver consistent, continuous and automated evidence of the feasibility of an attack. They run attack scenarios against the real environment and measure the outcome, proving that an exposure exists and is exploitable on that asset.
The set of controls for AI systems that act on their own: they call tools, reach data, and execute tasks without a human approving each step.
A security operations center where language models and autonomous agents take over alert triage, correlation, and first-pass investigation, leaving decision and response to the human analyst.
An autonomous component of a security operations center that takes an alert, gathers context from other tools, and returns an investigated case, with no human-defined step-by-step.
API (Application Programming Interface)
A programming interface that allows different systems to communicate and share data
The continuous process of discovering, analyzing, monitoring, and remediating attack vectors
Asset
Any digital resource that belongs to the organization and can be a target of attacks
The process of identifying and cataloging all of an organization's digital assets
The sequence of steps an attacker could take, from an exposed asset to a valuable target, chaining exposures and relationships between assets.
The total set of attack vectors an attacker could exploit within an organization
The continuous work of cutting the number of points an adversary can reach from the internet, switching off what does not need to be exposed and fixing what does.
Attack vector
A specific path or method an attacker can use to compromise a system
B
The extent of potential damage if an exposed asset is compromised, considering the systems and data the asset can reach.
C
Cyber Asset Attack Surface Management: consolidating the inventory of internal and external assets by integrating with existing tools to provide unified visibility of posture.
Cloud security
Protection of data, applications, and infrastructure stored with cloud providers
Recurring re-examination of an exposure and of the fix applied to it, with the evidence recorded on every pass. It confirms the exposure is still closed and reorders the queue when exploit intelligence changes.
Exposure of corporate credentials: usernames and passwords: in data breaches and dark web sources, often associated with initial-access attacks.
Cyber risk quantification (CRQ) is the practice of expressing security risk in money and probability instead of color scales. The result puts cyber risk in the same unit as the company's other exposures, and leadership decides investment on that basis.
Continuous Threat Exposure Management: an operational program defined by Gartner that organizes cyber risk reduction into a continuous five-stage cycle: scoping, discovery, prioritization, validation, and mobilization.
CVE (Common Vulnerabilities and Exposures)
A unique identifier for known, publicly disclosed security vulnerabilities
CVSS (Common Vulnerability Scoring System)
A standard system for assessing the severity of security vulnerabilities
Cyber threat intelligence
The collection and analysis of information about known and emerging cyber threats
D
DDoS (distributed denial of service)
An attack that attempts to overwhelm a system or network to make it unavailable
The set of third parties and vendors that make up an organization's digital infrastructure
DNS (Domain Name System)
The system that translates domain names into IP addresses for internet routing
E
EASM (external attack surface management)
External Attack Surface Management: continuous discovery and monitoring of an organization's internet-facing assets, assessed from an external attacker's perspective, with no agents or internal network access.
Endpoint
A device such as a computer, smartphone, or server that connects to a network
EPSS is the 0-to-1 score that estimates the probability a vulnerability will be exploited in the wild over the next thirty days. FIRST computes and publishes it every day, for every registered CVE. The file dated 16 September 2026 carried 374,847 scored CVEs, with a median of 0.0066. The score is a forecast, with the hits and misses a forecast carries.
Exploit
A technique or code that takes advantage of a vulnerability to compromise a system
Technical confirmation that a discovered exposure is actually exploitable, performed before reporting the finding. It reduces false-positive noise and focuses effort on what poses concrete risk.
Exposure management
The discipline that brings discovery, prioritization, and validation of an organization's exposures into a continuous process. Same subject as threat exposure management, where the developed entry lives.
The interval between when an exposure arises and when it is remediated. Scheduled scans widen this window; continuous monitoring narrows it.
All assets and systems accessible over the internet without authentication
F
FAIR (Factor Analysis of Information Risk) is the open model that quantifies information risk in financial terms. It breaks risk into loss event frequency and loss magnitude, and it underpins most cyber risk quantification (CRQ) programs.
Firewall
A security system that monitors and controls network traffic
FQDN (fully qualified domain name)
A complete domain name that includes the subdomain and the extension
I
IoC (indicator of compromise)
Technical evidence that a system has been compromised by an attacker
IP address
A unique identifier that allows devices to communicate over the internet
K
KEV is CISA's catalog of vulnerabilities with confirmed exploitation against real targets. It was created on 3 November 2021 by binding operational directive BOD 22-01, and it requires United States federal civilian agencies to remediate each entry by a published due date. Version 2026.09.16 held 1,713 entries, which is 0.46% of the CVEs carrying an EPSS score on that date.
L
LGPD (Brazilian General Data Protection Law)
The Brazilian law that regulates the protection of personal data
M
Malware
Software designed to cause harm, steal data, or gain unauthorized access
Misconfiguration
An error in system configuration that creates a security weakness
Mean Time to Remediate: a metric measuring how long, on average, an organization takes to fix an exposure from when it is identified. A central indicator of an exposure program's maturity.
P
Patch management
The process of updating software with security fixes
Preemptive exposure management (PEM) is the practice of finding, validating, and closing exposure before anyone exploits it, working on the reachable asset and the flaw with known exploitation while the adversary has not arrived yet. Gartner placed preemptive cybersecurity among its 2026 strategic technology trends and expects half of security spending to go to these solutions by 2030.
Penetration testing
An authorized test that simulates attacks to identify vulnerabilities
Phishing
An attack that attempts to deceive users in order to steal credentials or sensitive data
Preemptive cybersecurity is the umbrella of technologies that act before an attack instead of reacting to it. Gartner placed it among the ten strategic technology trends for 2026, in the October 20, 2025 announcement, forecasting that preemptive solutions will reach half of security spending by 2030.
Proactive security is the posture of working to reduce the chance of an incident instead of waiting for an alert, covering everything from patching and configuration hardening to threat hunting and team training. It is the oldest and broadest term in the family that now includes preemptive cybersecurity.
An attack in which an instruction hidden inside content read by a language model makes the system follow the attacker's order instead of the user's.
Preemptive threat exposure management (PTEM) is the program that finds what a company exposes on the internet, confirms what is exploitable, and orders remediation by attacker activity observed right now, with the goal of shortening the exposure window. The name appeared in August 2026, at one vendor's platform launch, and no analyst firm has adopted it.
R
Ransomware
Malware that encrypts data and demands payment to restore it
Risk assessment
The process of identifying and analyzing potential security risks
S
A score summarizing an organization's security posture from externally observable signals. Useful as a comparative indicator, though it does not replace continuous discovery and validation of exposure.
Use of artificial intelligence tools by employees without approval, without a contract, and without the knowledge of security or IT.
IT services and infrastructure used without the approval or knowledge of the IT department
SIEM (Security Information and Event Management)
A platform that collects and analyzes security logs in real time
SOAR (Security Orchestration, Automation and Response)
A platform that automates and orchestrates responses to security incidents
SSL/TLS (Secure Sockets Layer / Transport Layer Security)
An encryption protocol that protects data in transit over the internet
The technique of discovering the subdomains associated with a domain. It is an initial step of external surface discovery, prior to attributing, classifying, and validating the assets.
T
Threat actor
An individual or group responsible for cyberattacks
The discipline of treating an organization's exposure as a continuously managed object, measuring what is reachable by an adversary and how much of that is genuinely exploitable right now.
Third-Party Risk Management: the practice of assessing and monitoring the security posture of vendors and partners that connect to an organization's environment or process its data, reducing risk inherited from the supplier chain.
TTP (tactics, techniques and procedures)
The methods and behavioral patterns used by attackers
V
Vulnerability
A weakness in a system that can be exploited to cause harm
The process of identifying, assessing, and remediating security vulnerabilities
Vulnerability scanning
The automated execution of tests to detect known vulnerabilities
W
WAF (web application firewall)
A specialized firewall that protects web applications from attacks
Z
Zero trust
A security model that does not automatically trust any user or device
Zero-day
A vulnerability unknown to the vendors, for which no patch is available