Security News

Cybersecurity news aggregator

INFO News SC Media

Why Attack Surface Reporting Should Change for Executives

  • What: Discussion on how attack surface reporting should change for executives
  • Impact: Organizations and IT leadership
Read Full Article →

Attack surface management , Automated penetration testing , Breach and attack simulation Why Attack Surface Reporting Should Change for Executives July 24, 2026 Share By SC Media Editorial Intelligence, reviewed by Michael Tayo The Wrong North-Star Executives shouldn't judge attack surface management by how many assets are discovered. They should judge it by how quickly newly discovered assets are identified, assigned an owner, and brought under governance. Many attack surface management programs report to executives by describing what the program did: assets discovered, ownership-assignment percentages, routing-completion rates, new-asset detection speed. These numbers describe program activity. On their own they are weak signals for the decisions leadership actually owns — where to invest, where to enforce accountability, and how much ungoverned surface the organization is willing to tolerate. The more common framing error is the implied goal. A report that leads with "is the unknown, unmanaged surface shrinking?" sets up the wrong scoreboard. For an organization that is growing, adopting cloud, or acquiring, total surface and newly-discovered unknown surface will trend upward for the foreseeable future. Judged against a shrinkage target, that program looks like it is failing every month — when the business is simply expanding. A north-star that a healthy, growing organization is structurally unable to hit is the wrong north-star. The metric that holds up is not absolute shrinkage but dwell time and ratio: how long surface stays unknown or ungoverned after it appears, and whether governance converts unknown into classified-and-owned faster than discovery surfaces new unknowns. A program can absorb rising discovery indefinitely as long as the ungoverned backlog clears at or above the rate it fills. That is a target a growing organization can meet — and it is the question executives can actually act on. A better measure is how quickly new assets move from unknown to known, owned , and governed. The key questions become: How long does an asset remain unmanaged? And is the organization bringing new assets under governance as quickly as they are being discovered? This insight already lives inside the evidence model below, in change-response timing. The reframe here is to promote it from a buried detail to the headline: report the velocity and the standing ratio of ungoverned surface, not the raw direction of a count. Governance Coverage Is a Process Metric, Not a Risk Metric A second framing problem is conflation. "Exposure," "risk," and "ungoverned surface" are often used interchangeably, but they measure different things, and treating them as one misleads the board. Governance coverage — is this asset discovered, classified, owned, routed? — is a process metric. It describes whether the operating machine has the asset under management. It does not describe whether the asset is dangerous. A well-owned, well-routed asset can still be a critical exposure: an internet-facing host carrying a known-exploited vulnerability is severe regardless of how cleanly it is owned. An unowned asset may be trivial — an internal, unreachable, low-value service. Governance hygiene and risk severity are different axes. Boards increasingly ask about risk, not governance hygiene. So executive ASM reporting that reports only on coverage answers a question leadership did not ask. The fix is to carry a risk dimension alongside the governance dimension: exploitability, asset criticality, external reachability, exposure severity, and known-exploited-vulnerability status. The governance evidence tells leadership whether the surface is managed ; the risk dimension tells leadership whether it is dangerous . A useful report crosses the two — for example, the count and dwell time of surface that is both ungoverned and high-severity, which is the subset that should be governed first. This is also where prioritization enters. Executives rarely want uniform governance applied evenly across, say, fifteen thousand assets. They want the crown-jewel, internet-exposed, exploitable subset governed first. A reporting model with no severity or criticality dimension reads as naive to a security leader and is hard to act on. Where This Sits Relative to Established Frameworks This model is a reporting layer, not a new methodology, and it is most useful when positioned against the frameworks a CISO already expects. Gartner CTEM (Continuous Threat Exposure Management) is the dominant industry framing for this problem and covers scoping, discovery, prioritization, validation, and mobilization. The evidence model here is intended as a way to report on the discovery, prioritization, and mobilization stages of a CTEM program to an executive audience — not as a replacement for it. CTEM's prioritization and validation stages are precisely the risk and confirmation dimensions this article folds in. CISA's Known Exploited Vulnerabilities (KEV) catalog and Cross-Sector Cybersecurity Performance Goals (CPGs) give the risk dimension an external anchor: KEV status is a concrete, defensible severity signal for the exploitability axis, and the CPGs frame baseline expectations executives can be measured against. NIST Cybersecurity Framework maps cleanly: discovery and classification serve the Identify function, and ownership, accountability, and the decision record serve the Govern function added in CSF 2.0. FAIR (Factor Analysis of Information Risk) is the reference model when leadership wants exposure expressed in quantified, financial terms rather than asset counts. Positioning the report against these frameworks does two things: it tells leadership the program is not inventing private vocabulary, and it makes the risk dimension auditable against external standards rather than internal assertion. A Caveat Before the Evidence: Data Quality Every evidence type below assumes the underlying discovery, classification, and ownership data is accurate. In practice that assumption is the hardest part of the program, and it deserves to be stated to executives rather than hidden. Two failure modes matter most. First, discovery is rarely provably complete — you can only measure dwell time for the unknowns you actually found, so a "shrinking" ungoverned ratio can reflect narrowed discovery scope as easily as real progress. False positives, duplicate assets, and discovery blind spots all distort the denominator. Second, ownership is the most decay-prone field in any ASM or CMDB program. Owners change roles, assets transfer between teams, ownership is shared or disputed, and an "owner" recorded a year ago may no longer be accountable. Presenting an ownership percentage as clean executive evidence without addressing how ownership is confirmed — and how often it is re-validated — would not survive scrutiny from a knowledgeable reviewer. These are not reasons to avoid reporting. They are reasons to report ownership coverage with a freshness and confirmation-method qualifier, and to treat any single coverage number as an estimate with a known error mode rather than a precise finding. The same discipline guards against metric gaming: aggressive classification can inflate "owned" counts, and narrowed discovery can make unknown surface appear to shrink. Both are worth watching as incentives, not just measurements. The Four Evidence Types The model proposes four evidence types. Each answers a leadership question that an activity count does not. The illustrative figures used here are hypothetical and internally consistent — they show shape, not findings. Ungoverned-Surface Dwell and Ratio Evidence This is the reframed headline. Rather than asking whether an absolute count is shrinking, it reports how long surface stays unknown or ungoverned (dwell time, as a distribution) and what share of total surface is ungoverned at a point in time (the standing ratio). Together these show whether governance is keeping pace with discovery: if the ungoverned ratio holds steady or falls while discovery rises, the program is converting unknown into owned at least as fast as new unknowns appear. Required data: total discovered assets, total classified-with-confirmed-ownership, ungoverned dwell-time distribution, and the ungoverned ratio over rolling 30/60/90-day periods, broken down by surface type. Leadership decisions it supports: whether classification and ownership capacity matches the current discovery rate, and whether an acquisition or cloud-expansion event has pushed dwell time or ratio past tolerance. Ownership Coverage Evidence (with a data-quality qualifier) This shows what share of classified surface has a named accountable owner in a confirmed role, broken down by surface type and business unit, and crucially how that ownership was confirmed and when it was last validated . It reveals where accountability gaps concentrate. Required data: classified assets with confirmed ownership by role, unowned assets by surface type and business unit, ownership-gap age distribution, and ownership freshness or last-confirmed date. Leadership decisions it supports: whether a specific business unit needs intervention, whether vendor-surface ownership gaps need contractual changes, and whether acquisition-integration timelines are producing ownership gaps that persist too long. Reported without the freshness qualifier, an ownership percentage tends to overstate how settled accountability really is. Routing-and-Resolution Evidence The sharpest distinction in the original model was between a notification sent and a confirmed intake record — a handoff the program announced versus one a control team actually accepted as a work item. That distinction holds: a high notification-delivery rate can sit alongside control-team intake gaps, which is an asserted pattern worth measuring rather than assuming. But intake is one link short of what leadership cares about. The chain that matters is intake → action → resolution : did t

Share this article