
Every exposure management programme has a good, a bad, and an ugly. These are not three types of companies or three tidy stages in a roadmap. They are conditions that often develop inside the same programme at the same time.
One part starts to work. The team may gain better coverage of external assets, stronger evidence for remediation teams, clearer ownership, or reporting that gives leadership more than a list of unresolved findings. Another part starts to strain because each improvement creates work for the process around it. A third becomes the source of drag because the organisation cannot explain where the real bottleneck sits.
A programme can become more active as it improves, especially when better testing or discovery brings more of the external environment into view. The question is whether all that activity is helping the organisation decide what to fix, who owns it, and how quickly exposure is being reduced.
The good: where your exposure management programme starts working
The good in an exposure management programme can form in different places. For one organisation, it may be asset discovery. For another, it may be validation, where the team starts separating theoretical findings from issues an attacker can actually use. For another, it may be ownership, when exposures stop floating between teams and start landing with people who can act.
Security programmes rarely mature evenly because investment usually follows the most visible pressure. A company dealing with unknown internet-facing assets may focus on discovery. A team frustrated by false positives may improve validation. A CISO facing board pressure may strengthen reporting before the rest of the workflow has caught up. Each improvement is real, and each one tends to expose the next weak point.
Damen Shipyards gives a useful example. As the company’s digital experience became more central to customer interaction, its internet-facing footprint grew with it. A forgotten webpage was exploited for SEO poisoning, revealing the risk created by assets outside the security team’s immediate field of view. The lesson is less about that single page than the programme shift that follows: external visibility becomes something the organisation has to manage as the business changes.
For teams still defining that discipline, Hadrian’s guide to External Attack Surface Management gives a useful foundation. In practice, though, discovery is only one possible place where the good begins. A programme can also start working better through validation, ownership, reporting, or remediation.
The bad: where your exposure management programme creates more work than it can absorb
Progress usually increases the amount of work the programme has to process. Broader discovery brings more assets into scope. Stronger testing creates more evidence to review. More frequent monitoring gives the team a clearer view of change. All of this helps when the surrounding process can handle the extra volume.
The 2026 Offensive Security Benchmark Report shows the imbalance clearly. Most organisations have invested heavily in offensive security activity: 93% use vulnerability scanners, 87% conduct manual penetration testing, and 73% operate internal red teams. Only 40% have adopted automated penetration testing, leaving many teams with broad testing coverage but limited ability to validate and prioritise at the pace their environment changes.
This is where the backlog becomes a permanent member of the security team. It appears in every review, absorbs attention, and somehow keeps expanding despite receiving no formal onboarding.
The weakest point is often a handoff. A finding has to move from discovery to validation, prioritisation, ownership, remediation, and proof that the issue is closed. When any of those handoffs depends on informal coordination, repeated explanation, or heroic follow-up, the programme slows down.
Hadrian’s Atlas platform is designed around this live operating model: discovering, validating, and prioritising external exposure as the environment changes. Without that shift, the programme may produce more evidence and still struggle to show that meaningful exposure is going down.
The ugly: where your exposure management programme cannot explain its own bottleneck
The ugly part of exposure management is often described as a prioritisation problem, but programme leaders also need to know which capability is preventing prioritisation from becoming reliable.
The constraint may sit in discovery, where unknown assets still fall outside the programme’s view. It may sit in validation, where findings reach remediation teams before the risk has been proven clearly enough. It may sit in ownership, where nobody recognises the asset or has authority to change it. It may sit in remediation, where teams understand the issue but cannot close it at the pace required. It may sit in reporting, where leadership receives updates without a clear view of whether risk is actually reducing.
ICT Group shows why this becomes organisational quickly. Its security programme had to serve business unit leaders and potential partners, with internal stakeholders needing clear reporting on risks affecting their departments and external stakeholders looking at security ratings as part of their assessment. In that environment, exposure management depends on technical evidence, business ownership, and communication working closely enough to move the issue forward.
The benchmark report points to the same structural issue in CTEM programmes. Sixty seven percent of organisations measure CTEM success based on coverage gaps identified, while only 33% track reductions in exploitable exposures over time. Mean time to remediation is measured by many teams, but often without a clear connection to validation quality or whether the most important exposures are actually being removed.
A dashboard can show findings, severity, volume, and closure rates, while still leaving leaders guessing whether the weakness is asset ownership, validation quality, stakeholder alignment, remediation workflow, or reporting. Once that happens, the familiar fixes appear: add tooling, raise more tickets, schedule more meetings, and ask the backlog whether it has considered becoming smaller.
It usually has not.
The harder question is what to improve first
Security teams ask what to fix first because the daily work requires a ranked list of exposures. At the programme level, the same question has another layer: which capability should improve first so prioritisation becomes repeatable?
A team with incomplete discovery may need better coverage before its ranking model can be trusted. A team with weak validation may need stronger proof before remediation teams treat findings as credible. A team with weak ownership may need better mapping between assets, business units, and accountable teams before technical recommendations turn into action.
Testing cadence shows how easily exposure management can become inconsistent without a clear operating standard. In the benchmark report, 27% of organisations test critical assets daily, 27% test them monthly, and 27% test them annually. Across the entire external attack surface, quarterly testing is most common at 33%, with monthly and annual testing both at 27%.
For teams moving from periodic testing towards a more structured lifecycle, Hadrian’s blog on Continuous Threat Exposure Management explains how CTEM connects discovery, prioritisation, validation, mobilisation, and improvement. The challenge is that many programmes adopt the language of CTEM before the operating model underneath it is ready.
Using maturity to locate the constraint
Hadrian’s External Exposure Maturity Model gives teams a structured way to look at the programme behind the findings: how complete discovery is, how reliable validation is, how clearly ownership is assigned, how quickly exposures are closed, and whether leadership can see exposure being reduced.
A growing backlog may point to weak prioritisation, unclear ownership, or a remediation process that cannot absorb validated work. A large number of critical findings may point to genuine risk, weak validation, or poor context. Slow closure may reflect engineering capacity, but it may also reflect security tickets that do not give asset owners enough evidence to act.
The benchmark report gives the wider backdrop: security programmes have expanded in tooling and scope, while outcomes remain constrained by automation, standardisation, and verification. The maturity model turns that structural challenge into a practical diagnosis. It helps teams identify which part of the programme is working, which part is strained, and which part is making the whole system harder to improve.
Every exposure management programme has a good, a bad, and an ugly. The risk is treating all of it as one generic exposure problem.
Find out what is working, what is strained, and what is holding your exposure management programme back. Take the Hadrian Exposure Maturity Assessment to identify your stage and the next constraint to fix.






