How to build an exposure management program the business trusts: Lessons from Tenable’s CSO
Discover how Tenable’s shift to an AI-driven exposure management program helped Tenable’s CSO, Robert Huber, overcome tool sprawl, unify data silos, mitigate the risk of rapid AI adoption, and shift from presenting granular, technical metrics to communicating business risk that the C-suite and the board can understand. Key takeaways Security tool sprawl and data silos make it difficult for CISOs to holistically and accurately assess their organizations’ cyber risk. An exposure management program consolidates fragmented security data into a single unified view of cyber risk across the entire attack surface. Aided by exposure management, CISOs can align security metrics with business priorities and quantify risk for key revenue-generating business units, answering the board’s main question: “Are we secure?” What is trust in cybersecurity? And more importantly, how do you earn it? Here’s a hint: It’s not easy, especially in this AI era. As the Chief Security Officer at Tenable, my mandate is to ensure our organization operates securely, but with the speed required to succeed in a very competitive business environment. In recent years, achieving this delicate balance — an agile yet cyber secure business — had become progressively more difficult, as we grappled with increasingly fragmented data, siloed teams, and security tool sprawl. In this blog, I’ll explain how exposure management helped my team: Tackle security tool sprawl Bridge operational and data silos Take a more proactive approach to security Attain visibility and control over Tenable’s attack surface Continuously and precisely assess our cyber risk posture The operational impact of security data silos and tool sprawl For years, the cybersecurity industry’s answer to every new threat or policy mandate was simple: Buy another tool, which in many — maybe most — organizations resulted in a bad case of tool sprawl. A typical large enterprise might juggle 70 or more security technology vendors, each promising to solve a specific problem. At Tenable, my team manages around 50 different security tools. We found ourselves in a situation where siloed teams were running siloed tools, with separate views, prioritization criteria, key performance indicators, remediation workflows, and reporting. To illustrate this internally, I used to present a visualization of our architecture that I called the “spaghetti chart.” It was a tangled web of inputs from endpoint detection and response (EDR) vendors, bug bounty programs, vulnerability scans, security operation center (SOC) findings, penetration tests, and more. Each tool demanded its own unique workflow. As you can see, the spaghetti chart presented a picture of chaos. It reminded me of Gen. Stanley McChrystal’s quip regarding a spaghetti chart he was presented with during the war in Afghanistan: “When we understand that slide, we’ll have won the war.” Similarly, we could have said: “When we understand that chart, we’ll have eradicated cyber risk.” The consequences of this fragmented approach to security became glaringly apparent during my board presentations. At one board meeting, I arrived with a deck consisting of 45 slides. An exhausting 30 of those slides were packed with metrics, KPIs, and raw data. My team worked incredibly hard to pull that information together to build a narrative. Yet, I faced a hard truth: many of the business leaders and board members did not understand those metrics. When you present purely operational metrics, like the raw number of vulnerabilities or the number of scanned assets, you lose the C-suite’s attention. Those numbers don’t translate to business impact. The board’s two core questions about cybersecurity At the executive leadership and board level, I generally get asked two simple questions. First: “Are we secure?” I may also get asked a variation, such as: “What’s our exposure?” From my 30 metric-heavy slides, generated from 50-plus tools with their own disparate reporting functions, I had to som…
How to build an exposure management program the business trusts: Lessons from Tenable’s CSO
Description
Discover how Tenable’s shift to an AI-driven exposure management program helped Tenable’s CSO, Robert Huber, overcome tool sprawl, unify data silos, mitigate the risk of rapid AI adoption, and shift from presenting granular, technical metrics to communicating business risk that the C-suite and the board can understand. Key takeaways Security tool sprawl and data silos make it difficult for CISOs to holistically and accurately assess their organizations’ cyber risk. An exposure management program consolidates fragmented security data into a single unified view of cyber risk across the entire attack surface. Aided by exposure management, CISOs can align security metrics with business priorities and quantify risk for key revenue-generating business units, answering the board’s main question: “Are we secure?” What is trust in cybersecurity? And more importantly, how do you earn it? Here’s a hint: It’s not easy, especially in this AI era. As the Chief Security Officer at Tenable, my mandate is to ensure our organization operates securely, but with the speed required to succeed in a very competitive business environment. In recent years, achieving this delicate balance — an agile yet cyber secure business — had become progressively more difficult, as we grappled with increasingly fragmented data, siloed teams, and security tool sprawl. In this blog, I’ll explain how exposure management helped my team: Tackle security tool sprawl Bridge operational and data silos Take a more proactive approach to security Attain visibility and control over Tenable’s attack surface Continuously and precisely assess our cyber risk posture The operational impact of security data silos and tool sprawl For years, the cybersecurity industry’s answer to every new threat or policy mandate was simple: Buy another tool, which in many — maybe most — organizations resulted in a bad case of tool sprawl. A typical large enterprise might juggle 70 or more security technology vendors, each promising to solve a specific problem. At Tenable, my team manages around 50 different security tools. We found ourselves in a situation where siloed teams were running siloed tools, with separate views, prioritization criteria, key performance indicators, remediation workflows, and reporting. To illustrate this internally, I used to present a visualization of our architecture that I called the “spaghetti chart.” It was a tangled web of inputs from endpoint detection and response (EDR) vendors, bug bounty programs, vulnerability scans, security operation center (SOC) findings, penetration tests, and more. Each tool demanded its own unique workflow. As you can see, the spaghetti chart presented a picture of chaos. It reminded me of Gen. Stanley McChrystal’s quip regarding a spaghetti chart he was presented with during the war in Afghanistan: “When we understand that slide, we’ll have won the war.” Similarly, we could have said: “When we understand that chart, we’ll have eradicated cyber risk.” The consequences of this fragmented approach to security became glaringly apparent during my board presentations. At one board meeting, I arrived with a deck consisting of 45 slides. An exhausting 30 of those slides were packed with metrics, KPIs, and raw data. My team worked incredibly hard to pull that information together to build a narrative. Yet, I faced a hard truth: many of the business leaders and board members did not understand those metrics. When you present purely operational metrics, like the raw number of vulnerabilities or the number of scanned assets, you lose the C-suite’s attention. Those numbers don’t translate to business impact. The board’s two core questions about cybersecurity At the executive leadership and board level, I generally get asked two simple questions. First: “Are we secure?” I may also get asked a variation, such as: “What’s our exposure?” From my 30 metric-heavy slides, generated from 50-plus tools with their own disparate reporting functions, I had to som…
Technical Details
- Classification
- {"confidence":0.3,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.tenable.com/blog/how-to-build-an-exposure-management-program-the-business-trusts-lessons-from-tenables-cso","fetched":true,"fetchedAt":"2026-08-27T14:31:14.496Z","wordCount":3560}
Threat ID: 6a904a32acd9273b495e86a3
Added to database: 08/27/2026, 14:31:14 UTC
Last updated: 08/28/2026, 03:01:52 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.