|
Getting your Trinity Audio player ready...
|
The problem with traditional vulnerability and risk management programs hasn’t been discovery, and that’s to take nothing away from the groundbreaking frontier models that have come to grab seemingly every headline in the last few months. These models have re-written the rules (literally and figuratively) on how this industry discloses and addresses software vulnerabilities, but have they actually fundamentally changed the status quo?
We always want to know if we’re exposed, of course, but our teams have been drowning for years – this didn’t change with Mythos or Daybreak. No, the problem hasn’t been discovery of risk, the conundrum has always been: what do we do with ALL of the findings that we already have?
When teams talk about mobilization – a Gartner term referring to the process of getting validated findings to the right people fast enough to matter – the debate almost always centers on how automated it should be. How much can we hand to AI? How comfortable are we with machines making remediation decisions? When does a human need to be in the loop? These are real questions, and it’s very likely that the future involves fighting the AI fire with more AI fire (the good kind). But they come second, not first.
The first question to ask is: what’s underneath all of it? What’s the foundational platform that makes any operating model – human-led, human in the loop, or fully autonomous – actually function at the level security teams need it to?
Garbage In, Garbage Out: Start With the Foundation Or End In the Same Place
Most mobilization failures aren’t failures of process. They’re failures of context.
No matter how well you architect your agentic army, they are at the end of the day only as good as the context you can feed them with. And if you don’t have that in place first, the operating model debate is almost academic.
Today, the market for agentic security tends to look suspiciously like the same operating siloes that traditional security tools are fraught with, driven by familiar problems: blind spots, interoperability limitations and a struggle to extend logic across a diverse set of data models.
- A ticket gets created for a finding that can’t actually be patched in the current environment.
- A vulnerability gets escalated as critical, but it exists on an asset that has no viable attack path to anything sensitive.
- A remediation team closes a finding without realizing that the same exposure exists in three other places through different vectors.
- A fix was implemented in production but the same vulnerable image re-deployed a vulnerability, wasting time and effort.
These aren’t coordination problems, they’re information problems. The people responsible for acting on findings don’t have the full picture. And when the full picture isn’t available at the moment of action, mobilization grinds to a halt – or worse, generates a lot of activity that doesn’t translate to meaningful risk reduction.
Here’s the harder truth: as teams introduce AI agents and automation into their remediation workflows, information problems don’t get easier. They get worse. Agents are siloed by nature. They can act quickly within their domain, but they can’t reason across disparate data models. An agent that knows your vulnerability scan data doesn’t inherently know your network topology, your asset criticality, or whether the attack path to your crown jewels runs through the system it’s remediating. Without a shared context layer, you get agents optimizing locally while the actual risk picture stays fragmented.
This is the challenge that’s harder to solve. The automation works. The engine driving it fails.
The Three Operating Models and What They All Have in Common
Now, I am not trying to say operating models aren’t important, and it is critical that your team aligns on what model is right for your organization. Let’s take a look at the three primary models that are emerging, at a high-level:
| Human-led | Human in the loop | Fully Autonomous |
| Still the dominant model for most enterprises. Security teams identify findings, validate them, and route them manually to the appropriate owners. It’s deliberate, it maintains human judgment at every step, and it’s appropriate for environments where change carries significant risk or where organizational authority to force action is still being established. | Where most mature teams are headed. Agents and automation handle the routing, prioritization, and initial triage. Humans review and approve before action is taken. It’s faster than fully manual, and it preserves meaningful oversight. | It’s real, and it’s happening in specific contexts to resolve low-risk, high-confidence, high-volume finding types where the cost of action is low and the cost of delay is high. |
| Limitation: Scale
Human-led processes top out, and the volume of exposures in most environments already exceeds what teams can address manually at the pace attackers move. |
Limitation: Bottlenecks and Rubber-Stamping
The human approval step only works if the recommendation being approved is trustworthy and the agent is surfacing the right finding, in the right context, with the right remediation guidance. A rubber-stamp approval process isn’t oversight either, it’s the illusion of oversight and a false sense of security. |
Limitation: Risk Appetite and Authority
The organizations doing this well have very specific conditions in place: high environmental standardization, defined risk appetite, and clear organizational authority to act without manual sign-off. Many teams simply can’t operate this way, even if they wanted to. |
Here’s what’s striking about all three: the limiting factor in each case isn’t the operating model itself. It’s the quality of the underlying context.
Human-led teams make better decisions when they’re working from pre-validated findings tied to real attack paths, not raw scanner output. Human-in-the-loop teams approve faster and with more confidence when the agent’s recommendation is grounded in exposure context they can actually evaluate. Autonomous systems produce outcomes rather than just activity when they’re operating from a shared understanding of what matters and why.
The operating model is the what. The exposure and attack path platform is the why and without it, none of the models perform the way they’re supposed to.
What the Right Foundation Actually Looks Like
A unified exposure and attack path platform does three things that make every operating model work better.
- It brings attack surface and threat intelligence together in one place. Not as separate feeds that someone has to correlate manually. Not as bolt-on integrations that lag by hours or days. As a continuous, unified view of what’s exposed, what’s exploitable, and where the real attack paths run, so that every finding carries the context needed to prioritize it correctly and act on it confidently.
- It becomes the primary brain for any agent or automation layer you introduce. This is the piece that most teams aren’t thinking about yet, but will be soon. As autonomous agents proliferate in security workflows, the question of what they’re reasoning from becomes critical. Agents that operate from different, disconnected data models will reach different conclusions about the same environment. They’ll conflict. They’ll create noise. They’ll generate remediation activity that doesn’t map to actual risk reduction. A unified exposure platform gives every agent in your stack a shared context layer so that the automation works from the same picture that your human analysts are working from.
- It tells you which operating model is actually appropriate for each finding. Not every exposure belongs in a fully automated workflow. Not every finding needs a human decision. A mature exposure platform helps you route intelligently, pushing high-confidence, low-risk remediations toward automation, escalating complex, high-stakes findings to human review, and flagging findings that require compensating controls before a ticket is even created. That routing intelligence is only possible when you have the full exposure picture in one place.
The Question to Ask Before You Start Talking About Automation
Security leaders are under real pressure to show progress on mobilization. The board wants to see the mean time to remediate come down. The CISO wants to demonstrate that the team is moving at the pace of the threat. The vendors are all telling you that AI will close the gap. Some of that is true. But the teams that are actually making progress aren’t starting with the automation question.
They’re starting with questioning the foundation:
- What is our authoritative source of attack surface context?
- How is that context being surfaced to the people, systems and processes responsible for acting on it?
- Are our agents and automation tools reasoning from the same picture, or are they optimizing in silos?
When the foundation is right, the operating model almost picks itself. High standardization, defined risk appetite, and clear authority means you can push further toward autonomous. Less standardization, higher blast radius, and more organizational complexity, human oversight makes more sense, and the platform makes that oversight faster and more confident.
The goal isn’t autonomous remediation. The goal is effective mobilization. And effective mobilization, at any level of automation, runs on a foundation of unified exposure context. Everything else is downstream of that.
XM Cyber’s Exposure Management Platform brings attack surface visibility and attack path analysis together as a single, continuous context layer, enabling security teams to mobilize faster, prioritize with confidence, and support any operating model their environment requires. Download our ebook on effective mobilization to go deeper.