Avantec AG
Zürich
Exposure Management – AVANTEC
- 07 August 2026
- 100%
- Permanent position
- Zürich
About the job
…Or how digital exhibitionists can deal with their exposureIn terms of exposure, it is probably not as wild for most as it apparently is on Werd Island in Zurich. (Note from the editor: no personal relevant experience available). Yet some might be surprised at which systems are indeed exposed to unwanted glances or access in one way or another.I admit, the title was deliberately somewhat sensational. After all, no responsible admin or security officer wants to intentionally present their crown jewels to the public. Unlike what seems to be the case on Werd Island. But if you are still reading this far, the clickbait probably worked What is meant by Exposure Management?Most will be familiar with "Vulnerability Management." There are already a few articles about it on our blog. Exposure Management is basically the same concept but goes a step further. Unlike pure "Vulnerability Management," Exposure Management not only shows the open security gaps on various assets but also helps us understand how attackers find the systems and possibly even move between them. The goal is to proactively identify exposed systems and be able to act early. Below are some of the key core functions.External Attack Surface Management – the complement to internal vulnerability scansThe name says it all. External Attack Surface Management (EASM) continuously scans domains and/or public IP ranges from the outside. This provides the same external view as a potential attacker would have. To find the assets of the respective company, proven OSINT-based "passive data gathering" methods are used: domain registration, DNS records, SSL transparency logs or public cloud information.Once the assets are discovered, they are scanned for vulnerabilities. But not only outdated software is the focus, for example, whether default credentials are still used on found systems or if there are exposed services or ports. The results are then enriched with threat intelligence depending on the vendor and evaluated accordingly using a risk matrix. Criteria include whether a vulnerability is already actively exploited in known attacks or how easy it is to exploit a vulnerability.A conceivable use case for EASM would be the topic of Shadow IT: perhaps there are web services or cloud instances operated without the IT department's knowledge? Unfortunately, this happens more often than one might think.Attack Path AnalysisThanks to internal and external vulnerability scans, you can see which systems are vulnerable. The "Attack Path Analysis" goes a step further and also provides an answer as to how these vulnerabilities could actually be exploited. In combination with telemetry data collected from other sources, e.g. EDR sensors, the connections of internal and external assets are shown. What network connections exist and which users use the systems? This information is then presented in neat diagrams, illustrating the paths attackers might take. Perhaps an internal, supposedly well-isolated server is actually reachable from the internet by indirect routes?Security Configuration AssessmentEven better than finding and patching gaps would be if these gaps did not exist in the first place. Unfortunately, this is usually not in our hands due to the use of various software components. One way to counteract this somewhat is the use of security benchmarks such as CIS, NIST or HIPAA. Because even if a server is up-to-date with the latest patches, it may still be vulnerable due to open ports. A good example here is the Printer Spooler service on a domain controller. The service is active by default on all Windows systems but is rarely really needed and remains an attractive target. For example, the Stuxnet worm exploited a vulnerability in the Printer Spooler in 2010. More recently, the "PrintNightmare" bug from 2021. Such and other configurations can be defined in benchmarks. Deviations from these are then clearly displayed in dashboards.Effective added value – or just another deep red dashboard?Clearly, without effort from users, even the best tool is of little use. As with vulnerability management, work is required to process the results found. One of the challenges with "conventional" vulnerability management solutions is prioritisation. Seeing a huge number of critical vulnerabilities in the dashboard is not encouraging. Which patches should be prioritised on which systems is often the responsibility of the admin. And this is exactly where I see the added value of the more holistic "outside-in" approach of exposure management: the system takes over part of the prioritisation and shows me exactly which systems are really vulnerable and therefore must be the focus.Further linksCyber Defense Center – AVANTECManaged Detection & Response Service – AVANTECManaged Detection & Response Service – Vulnerability Management – AVANTECCyber Crisis Management – AVANTEC WebinarThe article Exposure Management first appeared on Tec-Bite.