Exposure Management: The New Cyber Risk Strategy

Mark Thurmond (COO & Co-CEO · Tenable)

RSA Conference 2025 · Day 4 · West Stage · Keynote

Overview

Tenable Co-CEO Mark Thurmond made the case at RSA Conference 2025 that the cybersecurity industry's dominant model — deploying more tools, more alerts, more specialized teams — has fundamentally failed. The replacement he proposed is exposure management: a continuous, AI-driven discipline that unifies fragmented visibility, contextualizes risk through predictive modeling, and is evolving toward autonomous remediation. The talk was delivered in honor of Tenable founder Amit Yoran, who died earlier in 2025 and had originally been scheduled to give it. ---

Watch on YouTube

Visual summary for Exposure Management: The New Cyber Risk Strategy by Mark Thurmond
Visual summary for Exposure Management: The New Cyber Risk Strategy by Mark Thurmond

Key moments

  1. 2:03 Talk delivers Amit Yoran's planned exposure management vision
  2. 4:05 Cyber assets grew 133% YoY; 2,000+ assets per employee
  3. 4:27 CVEs grew 20% in last 12 months alone
  4. 5:17 Average org deploys 83 tools from 29 vendors
  5. 7:38 97% of attacks hit known unpatched vulnerabilities; 180-day remediation
  6. 11:44 Password attacks jumped from 1,000 to 7,000 per second
  7. 12:14 Cybercrime projected to reach $10.5 trillion by 2029
  8. 16:56 AI automation cuts breach lifecycle from 322 to 214 days

The Old Cybersecurity Model Is Broken. Exposure Management Is What Comes Next.

Speakers: Mark Thurmond, Co-CEO, Tenable

Conference: RSA Conference 2025 — April 28–May 1, 2025, Moscone Center, San Francisco

YouTube: https://www.youtube.com/watch?v=-7gtEQ9iswA

Reading time: ~8 min

TL;DR

Tenable Co-CEO Mark Thurmond made the case at RSA Conference 2025 that the cybersecurity industry's dominant model — deploying more tools, more alerts, more specialized teams — has fundamentally failed. The replacement he proposed is exposure management: a continuous, AI-driven discipline that unifies fragmented visibility, contextualizes risk through predictive modeling, and is evolving toward autonomous remediation. The talk was delivered in honor of Tenable founder Amit Yoran, who died earlier in 2025 and had originally been scheduled to give it.

Introduction

RSA Conference 2025 carried an unusual emotional weight for the Tenable contingent. Mark Thurmond, the company's Co-CEO, opened his keynote by acknowledging that the ideas he was presenting were not originally his to present. They belonged to Amit Yoran, Tenable's founder and longtime CEO, who had championed the concept of exposure management for years before his death. Tenable executives and Yoran's family — including his brothers and mother — were in the front row.

The context framed everything that followed. This was not a routine product narrative. It was an argument Thurmond described as a complete shift in how the security industry needs to think about risk — one Yoran believed in deeply enough that it was to be his keynote at the industry's flagship event.

What Thurmond laid out was a diagnosis of why the current model is failing, a framework for what replaces it, and a progression toward security that operates at machine speed.

The Scale of the Failure

▶ Watch: The attack surface by the numbers (4:00)

The numbers Thurmond presented were stark. Cyber assets have grown 133% year over year, driven by cloud expansion, IoT proliferation, and bring-your-own-device policies. The average organization manages more than 2,000 assets per employee. Reported vulnerabilities, per NIST data, have grown at an average rate of over 65% per year since 2016. In the last 12 months alone, the number of exploited CVEs grew 20%.

The response from the industry has been to add more tooling: the average organization now deploys 83 security tools from 29 different vendors. That fragmentation has created a corresponding organizational problem — six to eight specialized security teams, each seeing a partial slice of risk, each reporting in its own language. When a CEO asks whether the company is exposed, too often there is no confident, data-backed answer.

The result, as Thurmond put it: "fractured visibility, disjointed action, and uncertainty right when clarity matters the most."

The operational toll is quantifiable. Thirty-two percent of critical vulnerabilities remain exposed for more than 180 days. Tenable's own research found that 97% of all cyberattacks target known vulnerabilities that simply have not been remediated yet. The most widely used security tool, Thurmond noted with deliberate irony, remains Microsoft Excel.

AI Is Accelerating the Gap

▶ Watch: AI-fueled attack economics (10:00)

Thurmond placed the current crisis in the context of AI-driven threat escalation. The argument was not that AI is introducing categorically new attack types, but that it is transforming the economics of attacks that already work — making them faster, cheaper, and more scalable.

One data point illustrated the shift concretely: password attacks grew from 579 per second in 2021 to more than 7,000 per second in 2024. That is an AI-fueled escalation that makes brute-force attacks exponentially more viable against organizations that have not hardened their authentication infrastructure.

Gartner data cited in the talk found that four out of five senior risk and assurance executives identified AI-driven attacks as a top business risk in 2024. Conservative estimates put global cybercrime damages at $10.5 trillion in 2025, projected to grow to $15.6 trillion by 2029 — the equivalent, Thurmond observed, of wiping out the combined market capitalization of the four largest companies in the world in a single year.

The business context matters here. As AI drives 10x to 100x productivity gains across enterprise operations, security cannot be the function that slows down transformation. The implication is that exposure management must have AI at its core — not as a feature, but as a structural requirement for keeping pace.

Three Dimensions of the Exposure Management Framework

▶ Watch: Fragmented to unified, static to predictive (14:00)

Thurmond organized the exposure management framework around three required transitions, each representing a departure from how security has historically been practiced.

From fragmented to unified. The first transition is about visibility. With dozens of siloed tools each showing a partial view of risk across IT, cloud, OT, identity, and application layers, attackers have a decisive advantage — they can chain exposures across boundaries that defenders treat as separate domains. Unified visibility, Thurmond argued, is no longer a feature or a premium capability. It is the baseline for survival.

From static to contextual and predictive. Traditional vulnerability management tools identify what is broken. They were not built to understand which broken things actually matter in the context of how attackers operate. This is the second transition: moving from severity-score rankings to living risk models that understand how vulnerabilities chain together, how privileges compound exposure, and which combinations represent active threats rather than theoretical ones.

▶ Watch: Predictive models and attack path simulation (18:00)

The data Thurmond cited was significant: organizations that have fully deployed security AI and automation tools have reduced their breach lifecycle from an average of 322 days to 214 — a 34% efficiency improvement. Predictive AI, he argued, goes further still, simulating attacker movement through systems, forecasting privilege escalation paths, and estimating time to compromise. The output is not just a list of what is broken, but a model of what is about to be breached.

From manual to autonomous and agentic. The third transition is the most consequential and the most fraught. Humans cannot remediate at the speed at which AI-assisted attacks now operate. Reconnaissance, lateral movement, and exfiltration can be automated in seconds. The only viable response is a progression toward autonomous remediation — security that detects, prioritizes, validates, and acts without waiting for human intervention at every step.

Thurmond was careful to frame this not as a binary switch but as a progression. The immediate need is automating the flow of confirmed exposures and prioritized guidance to the right teams at the right time. From there, automation expands gradually, with human oversight maintained at appropriate stages, eventually enabling a system capable of autonomous action on validated findings.

The Parallel to SIEM's History

▶ Watch: Lessons from the SIEM era (8:00)

One of the more analytically pointed moments in the talk was Thurmond's comparison of the current state of preventative security to the early history of SIEM. The analogy was deliberate: SIEM was born in response to the same kind of siloed, manual, alert-heavy dysfunction that now characterizes pre-breach security processes. SIEM's initial implementations were expensive, slow, and notoriously full of false positives. They relied on human-defined rules to keep pace with machine-speed threats.

Exposure management, Thurmond argued, can avoid repeating that history — but only if AI is central to its architecture from the start. "We don't need more alerts," he said. "We need clarity." The lesson from SIEM is that unifying data is not sufficient if the result is more noise at higher volume.

Notable Quotes

"Exposure management isn't just a platform. It's not a dashboard. It's not a SKU. It's not a check in the box on a compliance report. It's a complete shift in mindset."

— Mark Thurmond (2:01)

"Security teams are drowning in data, but starving for clarity."

— Mark Thurmond (8:00)

"Ninety-seven percent of all cyberattacks still target known vulnerabilities that just haven't been remediated yet."

— Mark Thurmond (6:00)

Key Takeaways

  • The average enterprise now deploys 83 security tools from 29 vendors, producing six to eight specialized security teams with partial, disconnected views of risk — a structural failure that exposure management is designed to replace.
  • Cyber assets are growing 133% year over year; exploited CVEs grew 20% in the last 12 months alone; and 32% of critical vulnerabilities remain exposed for more than 180 days — numbers that define the scale of the unresolved problem.
  • Password attacks escalated from 579 per second in 2021 to more than 7,000 per second in 2024, illustrating how AI is transforming attack economics without inventing new attack types.
  • Organizations that fully deploy security AI and automation have reduced their breach lifecycle by 34% — from 322 days to 214 — a measurable baseline for what the next phase of exposure management can achieve.
  • The path forward runs through three transitions: fragmented to unified visibility, static to contextual and predictive risk modeling, and manual to autonomous and agentic remediation — with human oversight maintained as a design principle throughout the progression.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

Tenable's Co-CEO delivers Amit Yoran's talk — and the emotional context makes it land harder than the content probably warrants on its own. The exposure management framework is coherent but not novel, and the statistics are the kind that get cited without enough scrutiny. A vendor keynote with a genuine human moment at its center, which is both its strength and the thing that makes it hard to rate on the merits.

Heather Calloway (CISO) — STRONG ACCEPT

Mark Thurmond delivers Amit Yoran's planned RSA keynote posthumously. The data: 97% of attacks exploit known, unpatched vulnerabilities; 32% of critical vulnerabilities remain exposed 180+ days after disclosure. The average enterprise runs 83 security tools from 29 vendors, managed by 6-8 siloed teams, and the most-used security tool is Excel.

→ Top-rated talks at RSA Conference 2025

All talks from RSA Conference 2025