For all the attention given to sophisticated cyber threats and zero-day vulnerabilities, most organizations are overlooking a far more immediate danger: the risks they already know about – but haven’t fixed.
President of Technology and Services at Arctic Wolf.
Recent research paints a sobering picture of enterprise security today. Across more than 800,000 IT assets analyzed, one in three lacks at least one critical security control. Nearly one in five is running end-of-life software and 17% sit entirely outside traditional vulnerability management tools.
In other words, the modern attack surface is not just expanding – it is becoming increasingly fragmented, poorly understood and difficult to control.
Breaches built on the basics
One of the most concerning recent developments is how little attackers need to innovate. Every one of the top 10 most frequently exploited vulnerabilities in recent incident response cases had already been patched by vendors – often months earlier.
At the same time, 65% of incidents involved the abuse of remote access services such as VPNs, RDP and remote management tools. These are not obscure weaknesses; they are foundational components of modern IT environments.
The takeaway is clear: attackers are not outpacing defenders technologically. They are taking advantage of execution gaps. Organizations have become adept at identifying vulnerabilities, but far less effective at prioritizing and remediating them and the gap between knowing, prioritizing and fixing is where risk accumulates. That gap is now where most breaches begin.
The visibility problem
At the heart of the issue lies a more fundamental challenge: visibility. Enterprise IT environments have evolved into highly distributed ecosystems, spanning on-premises infrastructure, cloud services, SaaS applications, remote endpoints and third-party integrations.
Each layer is typically managed by different tools, each maintaining its own inventory. None offers a complete view, and the result is predictable. Assets fall outside patch cycles. Devices are not covered by endpoint protection. Entire systems go unscanned. Almost a fifth (17%) of assets are now not covered by vulnerability management tools at all – effectively rendering them invisible from a security standpoint.
This is not simply a technical oversight. It creates what many security leaders now recognize as a structural weakness: organizations cannot secure what they cannot see.
For UK businesses, this challenge is becoming increasingly consequential. Regulatory frameworks such as the Network and Information Systems (NIS2) Regulations – and the UK’s forthcoming Cyber Security and Resilience Bill – are placing greater emphasis on demonstrable control over assets and risk. Inaccurate inventories and fragmented data make that more and more difficult to prove.
Legacy systems: The risk that won’t go away
Compounding the visibility issue is the persistence of legacy technology. 19% of IT assets are running software or hardware that has reached end-of-life, meaning it no longer receives security updates.
These systems are particularly challenging. In sectors such as healthcare, manufacturing and financial services, they are often embedded in critical processes and cannot be easily replaced. Yet they remain permanently exposed to known vulnerabilities.
The problem is not just their existence, but their opacity. It is not unusual for organizations to believe legacy systems have been decommissioned – only to discover they were still active. This creates a persistent blind spot within the attack surface, one that attackers are quick to exploit.
A growing gap between perception and reality
Perhaps most concerning is the extent to which organizations misunderstand their own security posture. Many rely on a single system of record – such as a configuration management tool as their “source of truth”. However, these systems are often incomplete.
In one example, a company believed it had full endpoint protection coverage based on internal reporting. Independent analysis revealed that a portion of its devices were not included in the system at all. This disconnect between perception and reality creates a false sense of security – one that is increasingly untenable in a climate of rising regulatory scrutiny and board-level accountability.
Across the UK and EU, frameworks such as the Digital Operational Resilience Act in financial services and NIS2 more broadly are raising expectations. Organizations are no longer judged on whether controls are in place, but whether they are effective, verifiable and consistently applied.
From vulnerability management to exposure management
Against this backdrop, there is a broader shift in how organizations approach cybersecurity. Traditional vulnerability management, focused on identifying and scoring flaws, is no longer sufficient. The challenge is not a lack of data, but a lack of clarity about what matters most.
Exposure management, by contrast, adopts a more holistic view. It combines continuous asset discovery with data from multiple sources, applying business and threat context to prioritize risk. Crucially, it also focuses on verification – ensuring that remediation actions are actually completed.
This shift is already delivering measurable results. Organizations that adopt more mature exposure management practices see reductions of more than 40% across key risk categories, including missing controls and end-of-life assets.
A new baseline for cyber resilience
The implications for UK organizations are clear. Cybersecurity is no longer just about defending against the unknown. It is about managing the known – systematically, continuously and at scale.
This is particularly relevant as cyber risk becomes more tightly linked to regulatory compliance, insurance requirements and board-level governance. The ability to demonstrate control over the attack surface – to prove what exists, how it is protected and whether risks have been reduced – is fast becoming a baseline expectation.
Attackers are now able to achieve domain-wide control in minutes once inside an environment. In that context, delays in remediation or gaps in visibility are not just operational issues – they are critical business risks.
The organizations that will succeed are those that close the gap between insight and action. Those that move beyond assumptions and develop a clear, verifiable understanding of their exposure. Ultimately in today’s threat landscape, the greatest risk is not what organizations don’t yet know – it is what they already know, but haven’t fixed.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit