If there's one certainty in life for CISOs it is that when it is time to buy into a new or consolidating security technology niche, they're going to have to eat their fair share of alphabet soup. Tech analysts and marketers do love their acronyms after all. We've got our SIEMs, our SOCS, and our MFAs and MDRs to prove that one out.
So, it should come as no surprise that security's newest patch of hotly-contested real estate—exposure management—is now awash in 'market defining' acronyms. We've got external attack surface management (EASM), continuous attack surface management (CASM), just plain ASM, and now from Gartner, continuous threat exposure management (CTEM). Add to that mix the overlapping and adjacent tech areas like cloud native application protection platforms (CNAPP) and application security orchestration and correlation (ASOC), and the category definition for exposure management becomes about as clear as mud for security pros trying to build out their security stack.
But the fundamental driving force behind exposure management doesn't need to be so confusing once we wade through the acronyms and get to the heart of things. Exposure management is bubbling up to serve the security team's need for better visibility into the state of assets that goes beyond the rudimentary CVEs of traditional vulnerability management.
CISOs want that clear visibility for their team so they can proactively act to improve that state. And they also want it so they can prove to the board that these actions are meaningfully reducing risk.
Market Confusion Is Natural In An Evolving Security Niche
Of course, there are many ways to slice that visibility onion from a technology perspective. And that's where a lot of the confusion about exposure management has set in. It's just a natural consequence of tech evolution and consolidation, explains John Bambenek, a longtime cybersecurity practitioner and president of Bambenek Consulting, LTD.
"The reason that it is a hard market to define is because how we are using technology is shifting rapidly, and a lot of vendors are applying point solutions to solve very specific parts of this problem," he explains. "There is nothing inherently wrong with that, but it means we haven’t settled on a consensus, which takes a longer time to achieve than the time it takes to deploy a new technology paradise."
All of the experimentation in various exposure management products is driven by the new realities of how infrastructure is deployed today compared to a couple decades ago, he explains.
"Twenty years ago, you could use a vulnerability scanner because all of your infrastructure was on premises, and you had to worry about network-based attacks. In a cloud-first world you have an entirely different set of risks to worry about. For instance, no vulnerability scanner is going to protect you against your private source code being put in a public repository with secrets," Bambenek says. "Shadow IT is also another manifestation of this problem."