Group Purchasing
Group Purchasing

2027 SANS Exposure Management Survey: From Attack Surface Visibility to Action

  • Tue, Oct 20, 2026
  • 10:30AM - 1:30PM EDT
  • English
  • Jonathan Risto
  • Industry Research Presentation
Login to register
Webcast Hero

Attack surface management helps security teams see what is exposed. Vulnerability management helps them identify and address weaknesses. But as assets, findings, and alerts multiply, a harder question remains: Are organizations getting better at reducing the exposures attackers can actually use?

The 2027 SANS Exposure Management Survey examines how organizations turn visibility into action. It explores how teams combine vulnerability data, asset context, threat intelligence, identity risk, cloud posture, business criticality, and attack-path analysis to decide what matters most and drive remediation.

The survey will also investigate the role of AI, automation, continuous threat exposure management (CTEM), and security validation. Are these capabilities helping teams identify exploitable exposures, prioritize more accurately, and confirm that fixes worked? Or are they adding more signals and complexity without improving outcomes?

Beyond technology, the research will look at how these programs work in practice: who owns exposure risk, how security and IT teams coordinate remediation, how exceptions are governed, and which metrics show whether risk is being reduced.

The findings will give security leaders and practitioners benchmarks for evaluating their programs and identifying practical improvements. Ultimately, the research asks: Are organizations getting better at finding exposures—or at eliminating the ones most likely to lead to compromise?

Why Join?

  • Benchmark your exposure management practices against industry peers.
  • See how teams turn attack surface and vulnerability data into remediation priorities.
  • Explore how AI, automation, CTEM, and security validation are affecting risk reduction.
  • Identify practical approaches to ownership, remediation, governance, and measurement.
  • Earn 3 CPE credits.

Meet Your Speaker

Jonathan Risto
Jonathan Risto

Jonathan Risto

Technical Director, Cyber Posture Management Program at Government of Canada

Jonathan Risto is a Principal Instructor at the SANS Institute and Technical Director for the Canadian Cyber Posture Program. Co-author of LDR516: Strategic Vulnerability and Threat Management, he helps leaders turn exposure data into actionable risk programs through frameworks like VMMM and CTEMMM.

Read more about Jonathan Risto