Featured

Cyber Security
Ben Mudie Of Tenable Explains Why Cybersecurity Needs Unified Exposure Management Across Identity, Cloud, And Vulnerabilities To Prioritize Risk And Strengthen Resilience
Overview
Ben also explores the growing security challenges around Active Directory and Microsoft Entra ID, fragmented multi-cloud environments, attack-path visibility, and expanding machine identities. He highlights the importance of continuous assessment, automated remediation, and translating technical exposure into business impact, while also sharing how customer and threat intelligence can help cybersecurity vendors build product roadmaps around real-world security challenges.
Here is a brief introduction of Ben:
Ben Mudie is Field CTO for Asia Pacific and Japan at Tenable, where he provides strategic guidance to enterprise customers and serves as a direct link between frontline customer needs and Tenable’s product and engineering teams. With a background in security engineering, he focuses on translating high-level cybersecurity strategy into practical, technically grounded outcomes.
With experience spanning security engineering, identity security, cloud security, solution architecture, product design, and IT infrastructure, Ben brings deep expertise in exposure management, Active Directory, Microsoft Entra ID, and multi-cloud environments. Throughout his career, he has worked across technical and customer-facing roles, helping organizations address complex security challenges. In this conversation, he discusses unified exposure management, identity and cloud risk, attack-path visibility, automated remediation, and how customer insights can shape more effective cybersecurity product strategies.
TD Editor: How should enterprises evolve from traditional vulnerability management toward a broader exposure management strategy that prioritizes the risks most likely to affect the business?
Vulnerability management tells you where security gaps exist. Exposure management builds on that layer to help businesses understand the risk each gap actually carries and prioritize vulnerabilities based on context and a complete view of risk across the attack surface. Getting there starts with bringing exposure data into one place, so vulnerabilities are assessed based on context like which systems they sit on, what access they touch, and how they could cascade into larger damage if exploited. That context is what strengthens prioritization. Treating every finding as equally urgent isn’t a viable option in this age of the “vulnami,” a tsunami of vulnerabilities.
Teams can align security data with business context to identify which vulnerabilities need immediate attention and which can wait, and route those insights directly into existing workflows so remediation happens quickly. Periodic scanning alone cannot promise resilience. As threats and attack techniques grow more sophisticated, defense has to evolve at the same pace or faster. This calls for continuous, real-time visibility and treating exposure management as an ongoing discipline rather than a periodic exercise.
TD Editor: Why have Active Directory and Microsoft Entra ID become such critical attack surfaces, and what commonly overlooked weaknesses should security leaders address first?
Identity remains a key attack vector for cyberattacks in India. Active Directory and Entra ID reside at the center of that risk because they govern both human and machine identities.
The potential impact of the problem is bigger than most security teams assume. Tenable's Cloud and AI Security Risk Report 2026 found that 65% of organizations carry unused or unrotated cloud credentials, "ghost" secrets sitting dormant with access no one is tracking, and 49% of identities holding critical-severity excessive permissions are dormant altogether. As 47% of Indian organizations now run multiple AI use cases in production, every one of those overprivileged, unmonitored identities becomes an open invitation for adversaries.
To make matters worse, AD and Entra ID are rarely secured as one system. As hybrid environments become the norm within organizations, the separation between on-premises and cloud-based IAM creates a gap attackers actively look for, bypassing whichever half of the defense happens to be watching. It's similar to securing one entrance to a house while leaving another unlocked. Once an attacker gets a foothold, the next move is almost always the same, which is to escalate to high-level privileges and build backdoor access that goes unnoticed for months. Security leaders should fix this by treating AD and Entra ID as one interdependent system, with unified monitoring across both, because an identity security strategy is only as strong as its most vulnerable directory.
TD Editor: How can organizations create a consistent cloud security strategy across AWS, Azure, Google Cloud, and Oracle Cloud without losing visibility or creating fragmented controls?
The problem begins when businesses treat each cloud as a separate security domain. Each cloud environment has its own identity model, policy language, logging approach, and control framework, making consistent governance difficult. For instance, a misconfiguration in AWS might look harmless on its own, but if it connects to an over-permissioned Azure identity or a misconfigured on-prem file share, the exposure can be damaging. Relying solely on each cloud's native tools isn’t the best option either. Although these tools can provide deep visibility within their respective environments, they can make it difficult for security teams to correlate risks across clouds and understand how identity, workload, and data exposures interact.
What businesses need is a unified view to secure everything in multi-cloud and hybrid cloud environments. A unified exposure management approach enables this, allowing security teams to correlate individual findings and identify vulnerabilities that sit between assets and identities to visualize the impact, prioritize, and act. It also helps monitor identity, roles, and policies regardless of whether they're currently active or unused. In most cases, stale or unused entitlements are exactly what expand the attack surface without anyone noticing. This granular level of visibility enables businesses to enforce least privilege and reduce the attack surface.
Continuous assessment of cloud resources, identities, and data helps teams prioritize exposures based on their actual business and attack-path context. Exposure management establishes a consistent way of reducing exposure across the entire hybrid and multi-cloud estate through continuous visibility, prioritization, and remediation.
TD Editor: What practical steps can security leaders take to ensure that high-level cyber strategies translate into actions that engineering and operational teams can realistically implement?
Every new technology an enterprise adopts, be it cloud services, AI agents, or third-party integrations, expands the attack surface and adds another stream of findings to a queue that was already too long. Security teams are drowning in alerts, and a growing share of what they're now responsible for isn't even human: service accounts, AI agents, and machine identities that keep multiplying and rarely get reviewed with the same discipline as human identities. The most effective discipline security leaders can bring is accepting that no team can fix everything, narrowing the universe of work down to what carries real risk. They need to prioritize risks aggressively, and a strong solution is to connect technical exposure to business impact. When security teams can correlate technical risks with financial exposure and business resilience, leadership gets the context needed to prioritize the risks that could have the greatest impact on the business.
They can also delegate repetitive, high-volume remediation to automated workflows. These workflows analyze signals from cloud, IT, OT, identity, AI, and web applications; detect and flag security gaps and misconfigurations; identify root causes; and offer remediation steps and policy recommendations to the right teams. This helps security leaders to get the full context they need to quickly and accurately address security issues.
TD Editor: How should enterprises connect identity, cloud, and vulnerability data to understand potential attack paths and prioritize remediation more effectively?
A vulnerability scan, an identity audit, and a cloud configuration review each tell a partial story on their own. Attackers don't respect those boundaries, and security teams shouldn't either. Businesses should think like an attacker before they show up. Centralized visibility into vulnerabilities, misconfigurations, and permissions can lay bare the entry points for attackers. This attack path shows not just where a weakness exists, but how a threat actor would move laterally, often undetected, to escalate privileges or reach sensitive data. Tenable research puts a number on how big this gap usually is. On average, an organization faces roughly three attack paths for every single security finding, so an environment with 50,000 findings could carry something like 150,000 potential routes to get in. A tool that works in isolation cannot tell which of those routes actually lead to what matters.
The harder problem is what happens after a path is found. AI has pushed the time between a vulnerability surfacing and being actively exploited to close to zero. Despite this compressed timeline, most security programs still run on a model built for a slower era: discovery happens fast, but remediation gets stuck behind manual handoffs and fragmented ownership. Connecting the data solves the visibility problem. It doesn't solve the speed problem on its own. Closing that gap means automating the handoff itself. Automated remediation identifies the blast radius across the environment and routes a context-rich fix to the right owner without a human having to stitch those steps together manually. This automated remediation, starting from summarizing risk to actually closing it at machine speed, is what helps businesses keep pace with attackers rather than being permanently a step behind.
TD Editor: How can cybersecurity vendors and product teams use frontline customer insights to build technical roadmaps that solve real-world security challenges rather than perceived market needs?
Most product roadmaps go wrong because they're built around what's technically interesting or competitively visible, rather than what customers are actually struggling with day-to-day. Insights generated from real support tickets, incident post-mortems, and real deployment friction can help identify the problems customers are facing recurrently. Along with customer insights, platform and threat intelligence data helps refine and build more effective capabilities. The next step is to prioritize these problems based on their frequency, severity, and potential business impact, and then validate that the proposed solution actually addresses the underlying problem. This ties the product roadmap to what's actually happening inside customer infrastructure and their pressing pain points rather than relying on guesswork or assumptions.
Fri, Aug 21, 2026
Liked what you read? That’s only the tip of the tech iceberg!
Explore our vast collection of tech articles including introductory guides, product reviews, trends and more, stay up to date with the latest news, relish thought-provoking interviews and the hottest AI blogs, and tickle your funny bone with hilarious tech memes!
Plus, get access to branded insights from industry-leading global brands through informative white papers, engaging case studies, in-depth reports, enlightening videos and exciting events and webinars.
Dive into TechDogs' treasure trove today and Know Your World of technology like never before!
Disclaimer - Reference to any specific product, software or entity does not constitute an endorsement or recommendation by TechDogs nor should any data or content published be relied upon. The views expressed by TechDogs' members and guests are their own and their appearance on our site does not imply an endorsement of them or any entity they represent. Views and opinions expressed by TechDogs' Authors are those of the Authors and do not necessarily reflect the view of TechDogs or any of its officials. While we aim to provide valuable and helpful information, some content on TechDogs' site may not have been thoroughly reviewed for every detail or aspect. We encourage users to verify any information independently where necessary.
Loading comments...

