Ai
September 27, 2026
2 views
2 min read

The Anatomy of Exposure: Why the Market Cannot Agree on What Counts as One

Curated by Patrick
Source: HackerNoon
The Anatomy of Exposure: Why the Market Cannot Agree on What Counts as One
Tech Daily Byte Analysis

In May 2024 XM Cyber and the Cyentia Institute reported that an average enterprise harbors about 15,000 exposures, of which fewer than one percent map to CVE‑listed vulnerabilities and roughly 80 percent stem from credential or identity misconfigurations. The authors point out that traditional vulnerability scanners can surface tens of thousands of findings, yet the broader “exposure” metric yields a much smaller figure because each tool measures a different unit—conditions, findings, affected assets, or attack paths. This discrepancy means that a single environment might be described as having 40,000 scanner findings, 8,000 compromised assets, 600 viable attack routes, and 900 exposures, all without any arithmetic error.

The divergence is not merely semantic. Vendors such as Wiz, XM Cyber, and Gartner each publish exposure‑management platforms, but they adopt distinct definitions. Wiz treats an exposure as a reachable weakness, essentially a vulnerable component that an attacker can access from the internet or through excessive permissions. XM Cyber, by contrast, bundles a vulnerable resource with a plausible threat technique along a concrete attack path, while Gartner’s language leaves room for a vulnerability or misconfiguration to count as an exposure outright. Because each model counts different elements, their reported exposure totals are not comparable, and product demos rarely expose these methodological gaps.

These conflicting taxonomies create real‑world challenges for security teams trying to benchmark risk. Without a common unit, organizations cannot reliably compare the output of competing platforms or gauge progress over time. The lack of consensus also hampers third‑party assessments and may lead to either over‑ or under‑investment in remediation. Stakeholders should watch for emerging standards or industry consortia that attempt to harmonize exposure definitions, and they should demand transparency from vendors about what exactly is being counted and from which attacker perspective.

Key Takeaways

XM Cyber and Cyentia’s estimate shows that identity‑related misconfigurations dominate exposure counts, not traditional CVE vulnerabilities.

Wiz, XM Cyber, and Gartner each use a different exposure definition, so their platform numbers cannot be directly compared.

The same environment can produce wildly different metrics—findings, assets, attack paths, and exposures—depending on the measurement granularity.

Security leaders should require vendors to disclose their counting methodology and attacker starting point to avoid misleading exposure totals.

About the Source

This analysis is based on reporting by HackerNoon. Here is a short excerpt for context:

Two exposure tools can scan the same environment and return 40,000 findings or 900 exposures — both correct, because each counts a different object.
Read the original at HackerNoon

More in Ai