Quanto sei stato esposto dal tuo ultimo pentest?

Un pentest è un'istantanea, e il rischio non si ferma una volta che è stato consegnato. L'Exposure Clock mostra esattamente quante vulnerabilità, comprese quelle sfruttabili dall'esterno, sono emerse dalla tua ultima valutazione.

No items found.
Strategia di sicurezza
-
5
mins read
-
September 29, 2026

What continuous exposure management looks like in a critical infrastructure environment

-
Alan Lucas - CISO - Worldstream
What continuous exposure management looks like in a critical infrastructure environment

Continuous exposure management is easy to describe and hard to operationalize. For Worldstream, a Dutch critical infrastructure provider, it meant replacing point-in-time snapshots with a real-time, outside-in view of its external attack surface, and turning validated exploitability, not CVSS scores, into the signal its teams act on. The result is a security function that keeps pace with an environment that never stops changing.

Most security teams already accept the theory:  new vulnerabilities are disclosed daily and internet-facing assets are probed around the clock, so ideally visibility and testing should be continuous too. Putting that into practice across a large, live estate is where the difficulty starts. Assets appear and disappear, findings pile up faster than anyone can triage them, and the gap between "we scanned this" and "this is actually exploitable" widens.

Worldstream is a useful example of what closing that gap looks like in practice, because the stakes are unusually explicit. The company designs, builds, and manages its own data centers and its own European network, running more than 15,000 physical servers for over 2,500 customers who host mission-critical workloads with it. When security is part of what customers are buying, "we review it periodically" is not a strong enough answer.

The problem with point-in-time visibility

For an infrastructure provider, the attack surface is not a fixed thing to be assessed once a quarter. It grows and shifts with every new customer deployment, every expanded service, and every network change. A snapshot taken on any given day starts going out of date the moment it's captured.

Worldstream's security monitoring team needed to account for every externally exposed asset as the infrastructure evolved, not at the next scheduled review. Mapping the environment from the outside in with Hadrian, the team now sees new assets and domains the moment they appear. Growth from new deployments or network changes is caught as it happens, so the environment never outpaces what the team can see, and the attack surface never drifts unmonitored.

That distinction, continuous versus point-in-time, is the whole game for a critical infrastructure provider. It's also the difference a pentest alone can't cover: a test establishes what could be validated inside its window, but it can't account for everything introduced or disclosed afterwards.

From CVSS scores to validated exploitability

Like many mature teams, Worldstream had been managing a large, complex estate through traditional vulnerability management, ranking findings by CVSS score. The trouble with that model is well understood: a severity score describes a vulnerability in the abstract, not whether it can actually be exploited in your specific environment. Teams end up working through long lists of possibilities, most of which represent no real risk.

Worldstream's team now works the other way around. Each finding is checked against real-world exploitability and business context before it reaches them, so a long list of scored possibilities becomes a short list of confirmed priorities. Rather than acting on what a scoring model suggests might matter, the team acts on what has been shown to matter, validated exposures instead of theoretical ones.

That shift also changes how the program is measured. Worldstream tracks its security score across the external attack surface, the percentage of assets under continuous scanning, and mean time to identify, contain, eradicate, and recover, all mapped to the NIST Cybersecurity Framework. Those metrics now run on a live, validated foundation rather than a periodic one, which matters for a provider operating under PCI DSS, preparing for NIS2, and serving as an ICT third-party service provider under DORA. Continuous, defensible evidence of control is both an operational and a commercial requirement.

Why validation makes every escalation count

Its incident response function is made up of senior experts drawn from across the organization, each with deep domain knowledge, on standby for critical findings. That model only works if an escalation is genuinely worth their time. Pull those experts in for a false alarm and you've spent scarce, expensive capacity on noise.

Because Hadrian confirms exploitability before a finding reaches the security monitoring team, the decision to escalate carries real confidence. The monitoring team knows what it's passing on has been tested and confirmed, not flagged on suspicion. The incident response team, in turn, receives validated findings with the full context to act immediately, without re-investigating from scratch. Every escalation is warranted, every response is precise, and the working relationship between the two teams is built on signal rather than noise, which is what lets the security function operate at the speed and scale the infrastructure demands.

When visibility becomes a customer promise

For Worldstream, continuous exposure management isn't only an internal security objective. It's part of what customers are buying when they choose to host critical workloads with a provider that controls its own infrastructure chain. They expect infrastructure that is continuously secured, monitored, and in control of its own exposure, and that's a promise periodic assessments simply can't keep.

{{quote-1}}

The broader lesson generalizes past this one customer. Continuous visibility and validated exploitability aren't separate features; together they turn exposure management from a reporting exercise into an operating capability. See how continuous exposure management with Hadrian gives security teams a real-time, validated view of their external attack surface, or read the full Worldstream story.

{{related-article}}

What continuous exposure management looks like in a critical infrastructure environment

{{quote-1}}

“
Con Hadrian hai un partner davvero solido per operazionalizzare la gestione continua delle esposizioni su scala. Richiede poco sforzo per la configurazione, migliora l’efficienza nella mitigazione dei risultati e nella riduzione del rischio, ed è davvero facile da usare, scalabile e ripetibile.
”
Alan Lucas
CISO
,
Worldstream

{{quote-2}}

“
”
,

Related articles.

All resources
No items found.

Related articles.

All resources

Strategia di sicurezza

What is offensive security? A practical guide

What is offensive security? A practical guide

Strategia di sicurezza

Security teams know the scores are wrong.

Security teams know the scores are wrong.

Strategia di sicurezza

Exploitation is now the leading path into breaches. Security programs need to respond accordingly

Exploitation is now the leading path into breaches. Security programs need to respond accordingly

get a 15 min demo

Start your journey today

Hadrian’s end-to-end offensive security platform sets up in minutes, operates autonomously, and provides easy-to-action insights.

What you will learn

  • Monitor assets and config changes

  • Understand asset context

  • Identify risks, reduce false positives

  • Prioritize high-impact risks

  • Streamline remediation

The Hadrian platform displayed on a tablet.
No items found.