Exposure Window

The interval between when an exposure arises and when it is remediated. Scheduled scans widen this window; continuous monitoring narrows it.

Two dates, and the distance between them

An exposure window is the time an asset stayed reachable and vulnerable before the organization closed that door. Two dates measure it: when the asset began answering on the internet in that state, and when it stopped answering, was fixed, or was protected.

The subtraction is the window. It is a number in hours or days, per asset, and the median across the set describes the program better than any composite index.

Why it is the metric that survives

An open vulnerability count measures the volume a tool produces. Two companies with the same real risk can show 3,000 and 40 items, depending on how many assets each scanner sees and how each one classifies.

Percentage remediated within SLA measures adherence to a deadline the organization set itself. It improves when the deadline loosens.

The exposure window has neither escape. It is measured against the adversary's clock, which nobody on the inside controls, so it does not improve by changing an internal criterion.

The two clocks

Two stopwatches run on the same asset, and the defense is the gap between them.

The adversary's clock starts when the asset becomes reachable. Automated internet-wide scanning runs in cycles of hours, so that is the real discovery time on the other side, regardless of company size.

Your clock starts when someone on the security team knows the asset exists. If that date comes days after the first, the adversary had days of head start, and the rest of the program operates on a delay no prioritization recovers.

The case where the metric cannot be computed

Many organizations try to measure the window and find they do not have the first date.

That is not a measurement failure. It is the result. Not knowing when an asset became exposed means nobody is watching the surface from outside, and that is the gap to close before any refinement of prioritization.

One caution voids the number when it slips through: measuring the window against your own inventory guarantees a good and false result. The asset that matters for the count is precisely the one that was not on the list.

Practical references

A median in hours indicates a program running at the cadence of the change. One day is acceptable in most contexts. A week means every new asset handed over six days of head start before entering the radar.

The window and MTTR measure different things and are often confused. MTTR counts from the moment the problem entered the queue. The window counts from the moment it came into existence, which is why it captures the delay MTTR hides.

Veja isso na sua superfície

Análise preliminar gratuita