<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Emma Carter</title>
    <description>The latest articles on DEV Community by Emma Carter (@emma_carter_bdab91baabd59).</description>
    <link>https://dev.to/emma_carter_bdab91baabd59</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4072654%2F80bd0b39-f7b6-4ba0-acf7-d0ea8d1bd961.png</url>
      <title>DEV Community: Emma Carter</title>
      <link>https://dev.to/emma_carter_bdab91baabd59</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/emma_carter_bdab91baabd59"/>
    <language>en</language>
    <item>
      <title>Measuring Cyber Risk Through the Lens of Exposure Management</title>
      <dc:creator>Emma Carter</dc:creator>
      <pubDate>Tue, 11 Aug 2026 08:53:54 +0000</pubDate>
      <link>https://dev.to/emma_carter_bdab91baabd59/measuring-cyber-risk-through-the-lens-of-exposure-management-5egh</link>
      <guid>https://dev.to/emma_carter_bdab91baabd59/measuring-cyber-risk-through-the-lens-of-exposure-management-5egh</guid>
      <description>&lt;p&gt;Cybersecurity teams have more visibility than ever, but more security data does not always mean a clearer understanding of risk. Organizations track vulnerabilities, exposed assets, patching progress, and security findings, yet these numbers often show activity rather than which weaknesses could realistically be used by an attacker.&lt;/p&gt;

&lt;p&gt;Exposure management takes a broader view by looking at how different weaknesses can connect. An exposed application, compromised credential, cloud misconfiguration, or excessive permission may seem manageable on its own, but together they can create a path toward a critical system or sensitive data.&lt;/p&gt;

&lt;p&gt;This is where attack paths become important. Instead of focusing only on the severity of individual vulnerabilities, security teams can look at how an attacker could gain an initial foothold, move through the environment, and eventually reach something valuable.&lt;/p&gt;

&lt;p&gt;That context can change remediation priorities. A critical vulnerability on an isolated system may create less practical risk than a moderate vulnerability sitting on a path toward privileged access or sensitive information. Severity still matters, but understanding where an exposure sits within the environment can provide a much clearer picture of its real significance.&lt;/p&gt;

&lt;p&gt;It also changes how organizations measure security progress. Rather than focusing only on how many vulnerabilities were closed, teams can consider whether high-risk attack paths were eliminated, whether critical assets are better protected, and whether new exposures are creating additional opportunities for attackers.&lt;/p&gt;

&lt;p&gt;Because environments constantly change, this understanding also needs to be maintained continuously. New applications, cloud workloads, third-party connections, and configuration changes can introduce new exposure between assessment cycles.&lt;/p&gt;

&lt;p&gt;The goal is not simply to reduce the number of vulnerabilities. It is to reduce the realistic opportunities attackers have to enter, move through the environment, and reach something that matters.&lt;/p&gt;

&lt;p&gt;That shift from counting findings to understanding exposure can provide a much more practical way to think about cyber risk.&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>cyberrisk</category>
      <category>exposuremanagement</category>
    </item>
  </channel>
</rss>
