<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Emma Carter</title>
    <description>The latest articles on DEV Community by Emma Carter (@emma_carter_bdab91baabd59).</description>
    <link>https://dev.to/emma_carter_bdab91baabd59</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4072654%2F80bd0b39-f7b6-4ba0-acf7-d0ea8d1bd961.png</url>
      <title>DEV Community: Emma Carter</title>
      <link>https://dev.to/emma_carter_bdab91baabd59</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/emma_carter_bdab91baabd59"/>
    <language>en</language>
    <item>
      <title>How Security Teams Can Reduce Alert Fatigue with CTEM</title>
      <dc:creator>Emma Carter</dc:creator>
      <pubDate>Mon, 17 Aug 2026 00:11:20 +0000</pubDate>
      <link>https://dev.to/emma_carter_bdab91baabd59/how-security-teams-can-reduce-alert-fatigue-with-ctem-48e1</link>
      <guid>https://dev.to/emma_carter_bdab91baabd59/how-security-teams-can-reduce-alert-fatigue-with-ctem-48e1</guid>
      <description>&lt;p&gt;Security teams have never had more visibility into their environments. Vulnerability scanners identify thousands of weaknesses, SIEM platforms process millions of events, and threat intelligence feeds continuously deliver new indicators of compromise. Despite this abundance of information, many security operations centers continue to struggle with a growing problem: alert fatigue.&lt;/p&gt;

&lt;p&gt;The issue is not that organizations lack security data. The issue is that they are overwhelmed by it. Every security tool generates findings that require attention, investigation, and prioritization. As environments become more complex, the volume of alerts grows faster than security teams can manage. Analysts spend their days reviewing notifications, validating findings, and determining which issues deserve action. The result is a cycle where security teams become increasingly focused on processing alerts rather than reducing risk.&lt;/p&gt;

&lt;p&gt;Over time, this creates significant operational challenges. Analysts are forced to investigate large numbers of findings that may never pose a meaningful threat. Response times slow down, important alerts become harder to identify, and security teams struggle to maintain confidence in the systems designed to protect the organization. What begins as a visibility challenge eventually becomes a prioritization problem.&lt;/p&gt;

&lt;p&gt;Many organizations attempt to address this challenge by adding more security tools, expanding monitoring coverage, or creating additional detection rules. While these efforts often improve visibility, they rarely improve decision-making. In fact, they frequently increase alert volume without providing the context needed to determine which findings actually represent risk.&lt;/p&gt;

&lt;p&gt;The fundamental problem is that most security programs are designed to identify issues, not validate them. A vulnerability may be classified as critical, but that does not necessarily mean it can be exploited. An exposed asset may generate alerts, but that does not automatically mean it creates a path to sensitive systems. Without understanding exploitability, security teams are forced to spend valuable time investigating findings that may have little real-world impact.&lt;/p&gt;

&lt;p&gt;This is why many organizations are adopting Continuous Threat Exposure Management (CTEM). Rather than focusing solely on detection, CTEM focuses on understanding exposure. It helps organizations continuously discover, validate, prioritize, and remediate risks based on real-world exploitability and business impact. The goal is not to generate more alerts but to identify which exposures create meaningful opportunities for attackers.&lt;/p&gt;

&lt;p&gt;One of the primary causes of alert fatigue is the assumption that every vulnerability deserves equal attention. Security tools often prioritize findings based on severity scores, yet severity alone rarely provides a complete picture of risk. A critical vulnerability may be protected by existing controls and inaccessible to attackers, while a lower-severity issue could become highly dangerous when combined with weak credentials, excessive permissions, or a misconfigured service.&lt;/p&gt;

&lt;p&gt;Without validation, security teams are forced to investigate both scenarios. This increases workload, slows response efforts, and diverts attention away from the exposures most likely to contribute to a breach. CTEM addresses this challenge by continuously validating exposures and helping organizations determine which risks are reachable, exploitable, and capable of supporting an attack path.&lt;/p&gt;

&lt;p&gt;Another factor contributing to alert fatigue is the lack of context surrounding security findings. Most alerts explain what happened but not why it matters. Analysts may know that a vulnerability exists or that suspicious activity has been detected, yet they often lack visibility into the broader business impact. They may not know whether the finding affects a critical application, supports lateral movement, or creates a path to sensitive data.&lt;/p&gt;

&lt;p&gt;CTEM helps close this gap by connecting technical findings to exposure and business risk. Instead of viewing vulnerabilities, identity risks, and misconfigurations as isolated issues, security teams gain visibility into how these weaknesses interact. This allows organizations to understand which findings contribute to exploitable attack paths and which represent lower-priority concerns.&lt;/p&gt;

&lt;p&gt;As prioritization improves, so does operational efficiency. Analysts spend less time investigating noise and more time addressing risks that could realistically lead to compromise. This not only reduces alert fatigue but also improves the overall effectiveness of the security program.&lt;/p&gt;

&lt;p&gt;The need for this shift is highlighted in this article &lt;a href="https://www.cybermindr.com/blog/how-to-implement-a-ctem-strategy-without-overhauling-your-existing-security-stack/" rel="noopener noreferrer"&gt;How to Implement a CTEM Strategy Without Overhauling Your Existing Security Stack.&lt;/a&gt; The article explains how organizations can improve exposure visibility and prioritization without adding unnecessary complexity to existing security operations, making it particularly relevant for teams struggling with overwhelming alert volumes.&lt;/p&gt;

&lt;p&gt;The impact of alert fatigue extends beyond productivity. When analysts repeatedly investigate alerts that turn out to be low priority, confidence in security systems begins to erode. Teams become accustomed to noise and may unintentionally overlook genuine threats. This creates a dangerous situation where important signals are buried beneath a growing volume of findings.&lt;/p&gt;

&lt;p&gt;CTEM helps address this issue by shifting security operations from reactive alert management to proactive exposure reduction. Rather than asking which alert should be investigated next, security teams begin asking which exposure should be eliminated to reduce future risk. This subtle shift changes how organizations approach cybersecurity and encourages a stronger focus on prevention rather than response.&lt;/p&gt;

&lt;p&gt;As attack surfaces continue to expand across cloud environments, SaaS applications, remote work infrastructure, and third-party ecosystems, alert volumes are unlikely to decline. Organizations cannot solve alert fatigue simply by hiring more analysts or deploying more tools. They need a better way to understand which findings matter and why.&lt;/p&gt;

&lt;p&gt;CTEM provides that framework. By continuously validating exposures, identifying attack paths, and prioritizing risks based on real-world impact, organizations can reduce noise, improve analyst efficiency, and strengthen their security posture. In a landscape where security teams are expected to do more with less, success will depend not on processing the most alerts but on focusing attention where it can make the greatest difference.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>cybersecurity</category>
      <category>security</category>
    </item>
    <item>
      <title>Why Security Validation Matters More Than Security Assumptions</title>
      <dc:creator>Emma Carter</dc:creator>
      <pubDate>Sun, 16 Aug 2026 23:40:14 +0000</pubDate>
      <link>https://dev.to/emma_carter_bdab91baabd59/why-security-validation-matters-more-than-security-assumptions-3dlo</link>
      <guid>https://dev.to/emma_carter_bdab91baabd59/why-security-validation-matters-more-than-security-assumptions-3dlo</guid>
      <description>&lt;p&gt;Every cybersecurity strategy is built on a series of decisions. Security teams decide which vulnerabilities to patch, which assets to prioritize, which controls to deploy, and which risks require immediate attention. The quality of these decisions depends on one critical factor: whether they are based on facts or assumptions.&lt;/p&gt;

&lt;p&gt;For many organizations, assumptions still drive a large portion of security operations. Teams assume that critical vulnerabilities represent the highest risk. They assume that compliance frameworks provide adequate protection. They assume that security controls are operating effectively. While these assumptions may simplify decision-making, they often create dangerous blind spots.&lt;/p&gt;

&lt;p&gt;Attackers exploit those blind spots every day.&lt;/p&gt;

&lt;p&gt;Cybercriminals do not care about vulnerability scores, compliance reports, or internal security metrics. They focus on finding the easiest path to valuable assets. If an exposure provides access to sensitive data or critical systems, it becomes a target regardless of how it appears in a dashboard.&lt;/p&gt;

&lt;p&gt;This reality has fueled growing interest in security validation and threat exposure management. Organizations are increasingly recognizing that identifying risks is not enough. They must understand which risks can actually be exploited and how those risks affect the broader attack surface.&lt;/p&gt;

&lt;p&gt;Traditional security programs are often built around detection. Vulnerability scanners detect weaknesses. Security tools detect suspicious activity. Risk assessments detect gaps in security controls.&lt;/p&gt;

&lt;p&gt;Detection is valuable, but detection alone does not answer an important question: does this finding actually matter?&lt;/p&gt;

&lt;p&gt;A vulnerability may have a severe rating but be inaccessible to attackers. A misconfiguration may appear dangerous but have compensating controls that reduce risk. Conversely, a medium-severity issue may create a direct route to sensitive systems when combined with other exposures.&lt;/p&gt;

&lt;p&gt;Security validation helps organizations answer these questions by evaluating exposures within the context of real-world attack scenarios.&lt;/p&gt;

&lt;p&gt;Rather than focusing solely on individual vulnerabilities, validation examines exploitability, attack paths, and business impact. This allows security teams to identify the exposures most likely to be leveraged by attackers and prioritize remediation accordingly.&lt;/p&gt;

&lt;p&gt;Threat exposure management extends this approach by continuously monitoring the attack surface for changes. Modern environments are dynamic. Cloud resources are deployed and removed daily. New applications are introduced. Vendors connect to internal systems. Employees adopt new technologies. Each change can introduce additional exposure.&lt;/p&gt;

&lt;p&gt;As attack surfaces grow, organizations often experience alert fatigue and remediation overload. Security teams become buried under thousands of findings, making it difficult to distinguish between urgent threats and background noise.&lt;/p&gt;

&lt;p&gt;Validation helps reduce this burden.&lt;/p&gt;

&lt;p&gt;When organizations understand which exposures create viable attack paths, they can focus resources where they will have the greatest impact. Instead of treating every finding as equally important, they can prioritize exposures based on evidence.&lt;/p&gt;

&lt;p&gt;This shift is particularly important when managing third-party risk.&lt;/p&gt;

&lt;p&gt;Third-party relationships have become a major source of cyber exposure. Vendors frequently have access to critical data, business applications, and operational systems. A weakness within a supplier's environment can quickly become a weakness within the organization's environment.&lt;/p&gt;

&lt;p&gt;Historically, third-party security assessments have relied heavily on questionnaires, audits, and compliance reviews. While these methods provide useful information, they often fail to capture rapidly changing exposure conditions.&lt;/p&gt;

&lt;p&gt;A vendor's security posture can change significantly between assessments. New vulnerabilities may emerge. Public-facing systems may become exposed. Credentials may be compromised. Attackers continuously search for these opportunities because third-party ecosystems often provide an easier path to compromise than attacking the primary target directly.&lt;/p&gt;

&lt;p&gt;For this reason, organizations are moving toward more continuous approaches to vendor security. &lt;a href="https://www.cybermindr.com/tprm/" rel="noopener noreferrer"&gt;Effective Third-Party Risk Management (TPRM)&lt;/a&gt;) increasingly incorporates ongoing exposure monitoring and validation rather than relying solely on periodic reviews. By identifying exploitable exposures across vendor ecosystems, organizations can address risks before they become entry points for attackers.&lt;/p&gt;

&lt;p&gt;Security validation also delivers strategic value beyond operational security.&lt;/p&gt;

&lt;p&gt;Executives and board members want to understand risk in business terms. They need to know which exposures threaten critical operations, customer trust, revenue, and regulatory obligations. Validation provides a clearer picture of these risks by connecting technical findings to potential business outcomes.&lt;/p&gt;

&lt;p&gt;Instead of presenting a list of vulnerabilities, security teams can demonstrate which exposures create realistic attack opportunities. This makes risk discussions more meaningful and supports better investment decisions.&lt;/p&gt;

&lt;p&gt;The future of cybersecurity will increasingly depend on an organization's ability to validate assumptions. As environments become more complex and threats become more sophisticated, relying on theoretical risk models will become less effective.&lt;/p&gt;

&lt;p&gt;Organizations need evidence-based security. They need to know whether controls work, whether exposures are exploitable, and whether remediation efforts are reducing actual risk.&lt;/p&gt;

&lt;p&gt;Security validation provides those answers. Combined with continuous threat exposure management, it enables organizations to move beyond assumptions and focus on what truly matters: preventing attackers from exploiting the exposures that can lead to a breach.&lt;/p&gt;

&lt;p&gt;In a world where cyber threats evolve constantly, assumptions create uncertainty. Validation creates confidence. And confidence, backed by evidence, is what allows organizations to stay ahead of emerging threats and build a stronger security posture.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>cybersecurity</category>
    </item>
    <item>
      <title>Measuring Cyber Risk Through the Lens of Exposure Management</title>
      <dc:creator>Emma Carter</dc:creator>
      <pubDate>Tue, 11 Aug 2026 08:53:54 +0000</pubDate>
      <link>https://dev.to/emma_carter_bdab91baabd59/measuring-cyber-risk-through-the-lens-of-exposure-management-5egh</link>
      <guid>https://dev.to/emma_carter_bdab91baabd59/measuring-cyber-risk-through-the-lens-of-exposure-management-5egh</guid>
      <description>&lt;p&gt;Cybersecurity teams have more visibility than ever, but more security data does not always mean a clearer understanding of risk. Organizations track vulnerabilities, exposed assets, patching progress, and security findings, yet these numbers often show activity rather than which weaknesses could realistically be used by an attacker.&lt;/p&gt;

&lt;p&gt;Exposure management takes a broader view by looking at how different weaknesses can connect. An exposed application, compromised credential, cloud misconfiguration, or excessive permission may seem manageable on its own, but together they can create a path toward a critical system or sensitive data.&lt;/p&gt;

&lt;p&gt;This is where attack paths become important. Instead of focusing only on the severity of individual vulnerabilities, security teams can look at how an attacker could gain an initial foothold, move through the environment, and eventually reach something valuable.&lt;/p&gt;

&lt;p&gt;That context can change remediation priorities. A critical vulnerability on an isolated system may create less practical risk than a moderate vulnerability sitting on a path toward privileged access or sensitive information. Severity still matters, but understanding where an exposure sits within the environment can provide a much clearer picture of its real significance.&lt;/p&gt;

&lt;p&gt;It also changes how organizations measure security progress. Rather than focusing only on how many vulnerabilities were closed, teams can consider whether high-risk attack paths were eliminated, whether critical assets are better protected, and whether new exposures are creating additional opportunities for attackers.&lt;/p&gt;

&lt;p&gt;Because environments constantly change, this understanding also needs to be maintained continuously. New applications, cloud workloads, third-party connections, and configuration changes can introduce new exposure between assessment cycles.&lt;/p&gt;

&lt;p&gt;The goal is not simply to reduce the number of vulnerabilities. It is to reduce the realistic opportunities attackers have to enter, move through the environment, and reach something that matters.&lt;/p&gt;

&lt;p&gt;That shift from counting findings to understanding exposure can provide a much more practical way to think about cyber risk.&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>cyberrisk</category>
      <category>exposuremanagement</category>
    </item>
  </channel>
</rss>
