The Security Metric That Lies: Why Knowing Your Vulnerabilities Is Not the Same as Reducing Your Risk

Security teams are drowning in vulnerability reports yet still can't answer the one question that matters: are we actually harder to attack today than we were last year? The old way of measuring risk is the problem.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
A security operations center dashboard overwhelmed with thousands of vulnerability alerts and scan results covering every inch of multiple monitors, with a mana
Share

Key points

  • Most organisations already have more security findings than their teams can realistically fix, yet overall risk is not reliably falling.
  • Severity scores, the standard way of ranking which flaws to fix first, measure a flaw's characteristics, not whether a criminal can actually use it to cause harm.
  • Gartner's Continuous Threat Exposure Management (CTEM) framework, a structured approach for evaluating what attackers can realistically reach and exploit, has gained wide adoption as an alternative lens.
  • Exposure is broader than any single flaw: it includes weak identity controls, excessive permissions, and the trust relationships between systems that let criminals move from a minor breach to a catastrophic one.
  • The question shifting boardroom conversations is not "how many vulnerabilities did we find?" but "what can an attacker actually reach?"

For most of the past two decades, the core promise of cybersecurity was simple: find the weaknesses in your systems, rank them by severity, patch the worst ones first, repeat. That logic held when networks were small and changed slowly. It's struggling now.

Why the old approach is breaking down

The problem isn't that security teams have stopped looking. They're finding more flaws than ever. Finding a flaw and reducing the risk it creates are two different things, and the industry spent years treating them as the same.

Traditional tools assign each flaw a severity score, a number meant to signal how dangerous a weakness is. But severity scores describe the flaw in isolation. They don't describe what a criminal can do with it inside your specific environment.

A critical flaw buried deep in a system no outsider can reach may pose almost no real danger. A moderate flaw on a system that also has weak passwords and overly broad permissions, meaning settings that give users more access than their job requires, can hand a criminal the keys to your most sensitive data. Severity isn't risk.

How criminals actually attack

Criminals don't pick one vulnerability and stop. They chain weaknesses together, break into a low-value system, use lax permissions to move sideways across the network (a technique called lateral movement), and escalate their access until they reach something worth stealing or encrypting for ransom. Our 5 August story "Fixing One Hole at a Time Is No Longer Enough" documented exactly how that full-path exploitation outpaces teams testing each system in isolation.

The vulnerability that opened the door matters less than the series of conditions that let the criminal walk all the way to the safe.

This is the core idea behind Continuous Threat Exposure Management, or CTEM, developed by the research firm Gartner. Rather than cataloguing every flaw individually, CTEM asks organisations to map the realistic paths a criminal could take through their environment and focus remediation on breaking those paths.

What 'exposure' means in plain English

Exposure is a wider concept than vulnerability. It covers the combination of flaws, weak identity controls (meaning who is allowed to log in and from where), excessive permissions, trust relationships between systems, and the value of the data sitting at the end of each possible attack path.

Two minor issues that overlap can create a direct route to critical infrastructure. That's exposure. Exposure determines impact, not the severity score on any individual finding.

Concept What it measures Limitation
Severity score How dangerous a flaw looks in isolation Ignores your actual environment
Vulnerability count How many flaws were found Says nothing about exploitability
Exposure What attackers can realistically reach and do Requires broader data to calculate
CTEM Continuous mapping of realistic attack paths Newer; needs tooling and process change

Should you worry about this if you're not in security?

If you're a customer or an employee of any large organisation, this shift matters to you. Breaches that expose personal records almost never happen because one flaw went unpatched. They happen because a string of overlooked conditions created an open road to sensitive data.

Organisations moving from counting vulnerabilities to measuring exposure are asking a harder question, but the right one: not "what is broken?" but "what can a criminal do with what is broken?"

If your employer or a company that holds your data asks you to use strong unique passwords or report suspicious emails, those small actions close off parts of that road. They reduce exposure even when the underlying software flaw hasn't yet been patched.

The honest read on this shift: counting vulnerabilities was always a proxy metric, not a safety guarantee. The gap between completing work and actually reducing risk is where breaches still happen, as our 6 August survey piece found. Watch whether organisations start reporting exposure reduction alongside patch rates. That's when the measurement actually means something.

© 2026 Threat Vectr