Skip to content
Explore solutionsExposure Management
Solutions / By Team / Exposure Management

Work the risk before
it becomes an alert.

Imperum helps exposure teams turn scattered findings into focused remediation work. Defensum connects assets, identities and vulnerabilities with business and SOC context; Casebook carries the evidence into follow-up.

Shared asset contextExplainable priorityAccountable follow-up
One exposure, from finding to follow-upIllustrative workflow
01 · Bring the evidence
Scanner findingKnown-exploited vulnerability
Cloud inventoryInternet-facing server
Control evidenceEndpoint protection missing
Matching identifiers
tie observations to one asset.
02 · Assess the asset

web-01

Customer portal · production

85/100Critical asset risk
Evidence collected
Public exposure + KEV-listed flaw
03 · Make it actionable
Casebook
Review web-01 exposureCase created in this example
  • Asset and source evidence
  • Risk explanation
  • Recommended actions
High-risk action?Approval required

Creating the case does not authorize the change.

An operator creates a case with the asset’s risk explanation and evidence. Remediation is a separate decision, with approval required for high-risk actions.

Explore at your pace
Synthetic asset and example score. This combines supported product views to explain the workflow; it is not a customer result or a claim that the exposure has been fixed.
01 - Establish the context

Give the team one asset to work from.

Your scanner, directory and cloud platform can describe the same machine differently. Defensum matches supported identifiers and keeps source observations with the asset, so the team can review the exposure in context.

For CTEM teams

Review asset posture alongside user and non-human identity risk. Missing protection, excessive privilege and risky credentials become specific work to investigate, rather than disconnected lists.

For vulnerability teams

Use findings from configured scanners such as Tenable or Qualys. Imperum adds asset and control context to the scanner’s findings, helping you explain why a particular system needs attention.

Source observationsKeep the provenanceMatching identifiersResolve the assetControl healthLocate the gap

Matching depends on the identifiers available. Unknown or stale control evidence needs follow-up; it is not proof that a control is working.

Explore asset and identity posture in Defensum
02 - Choose the work

Explain why this exposure comes first.

Exposure-prioritization teams need a defensible decision. Defensum combines vulnerability severity and known-exploited vulnerabilities with internet exposure, control gaps, business criticality and available SOC context in its asset-risk assessment.

In the illustrative web-01 scenarioA reachable server with a known-exploited flaw
Can it be reached?The asset is reported as internet-facing.
Is exploitation known?The open vulnerability is on CISA’s Known Exploited Vulnerabilities list.
What protection is missing?Endpoint protection is reported missing on this asset.
What should happen next?Review the critical exposure and carry its evidence into a case.

Connect risk to the business

Business-service criticality can feed the asset score. Derived attack paths and blast-radius views help your team examine how exposure could affect critical assets.

Bring in the SOC’s evidence

Available alerts and cases add investigation context when they can be matched to the asset. A potential attack path describes a relationship to investigate, not proof that an attacker followed it.

Asset, identity and exposure signals are reviewed across their relevant views. This is not a single universal queue that ranks every kind of exposure.

03 - Cover the surface

Include the estate beyond the patch list.

Attack-surface teams need to understand both public-facing systems and the AI tools used across the business. These require different sources and controls.

Your external surface

Defensum’s external attack-surface workflow assesses declared targets. Accept the rules of engagement, verify ownership and meet scan-eligibility requirements before scanning with a configured engine.

Keep external assessment within the scope your organization owns and authorizes.

See external-surface management

Your AI estate

Virtus Sentinel brings AI-asset observations from deployed endpoint, browser, gateway and platform sources into its inventory, including MCP servers and AI agents.

Identify AI use that needs review. Coverage depends on deployed sources and the Sentinel entitlement.

Explore AI discovery in Virtus Sentinel
04 - Coordinate remediation

Hand over the evidence with the work.

An exposure decision becomes useful when someone can act on it. Create or open a Casebook case from a finding, with its risk explanation, recommended actions and evidence references. Use remediation assignments and campaigns to give the follow-up an owner and a deadline.

  1. 01

    Keep the finding connected

    The case links back to the exposure. An existing matching open case can be updated instead of creating another record for the same work.

  2. 02

    Review the proposed action

    High-risk and critical remediation actions require approval. Lower-risk actions may execute with the required permissions and configured tools; opening a case alone does not authorize remediation.

  3. 03

    Check the latest evidence

    Return to the asset’s reported control health as new observations arrive. A closed ticket alone does not establish that a control is healthy or that a vulnerability is gone.

A decision the next person can use.

The affected asset, why it matters and what needs review stay with the work. Your team spends less effort rebuilding the context for each handoff.

See how Casebook supports the follow-up

Questions from exposure teams

1Do we keep our vulnerability scanner?

Yes. This workflow consumes findings from supported, configured scanners such as Tenable or Qualys. Defensum adds asset, control and risk context. Its separately configured external attack-surface scanning workflow has its own scope, ownership and authorization requirements.

2Can exposure work start before an alert exists?

Yes. Asset posture, scanner findings and identity risk can support exposure work without a matched alert. Available SOC evidence adds context; missing or unmatched evidence should not be read as proof that the asset is safe.

3Does a critical risk score automatically change the asset?

No. The asset’s risk score and a proposed action’s risk classification are separate. High-risk or critical remediation actions require approval. Lower-risk actions can execute when the necessary permissions and tools are in place.

4Where should our team start?

Choose one asset group and the tools that already report on it. Check source coverage and identity matches, review the risk explanation, then take one finding into a case. Add external-surface or AI discovery where it fits your scope and enabled capabilities.

Have another question? Talk to our team

Bring the finding
you keep deferring.

See how asset context, exposure evidence and an accountable handoff could change the next decision your team makes.