Continuous Threat Exposure by Human Managed
Exposure you can prove you closed.
Continuous Threat Exposure is the operated exposure module inside invicta.io. It reads findings from the tools you already own, turns each one into a contracted Outcome with a Metric, and runs the work against that Metric at an agreed autonomy level. You see the whole chain: finding, decision, action, evidence. The Outcome state only moves when the source system still agrees on re-query.
Everyone can show you findings. Almost nobody can show you the close.
Your scanner produces findings. Your SIEM produces alerts. Your ticketing system produces closed tickets. What none of them produce is the line between the two: which finding, which decision, whose action, and whether the underlying condition actually changed.
That gap is where exposure programmes stall. The ticket closes, the metric is asserted, and nobody re-queries the source a week later to check it held. Continuous Threat Exposure is built around that missing link. A closed ticket is a claim. Validation is the answer.
Three inputs. One confidence score.
A confidence number you cannot audit is decoration.
Confidence is one of the ten fields on the panel above, and it is the one that tells you how far to trust the other nine. Continuous Threat Exposure derives it from three weighted inputs and prints the working next to the number, so a reader can tell a measurement from an assumption.
How much of the estate can this measurement actually see?
What the number is based on, and what it misses
Coverage asks whether the measurement observes the contracted estate or only the convenient part of it. In the worked ownership example, ownership resolves only for domain-joined assets, so coverage caps at 90 per cent. The eight per cent that is not domain-joined is named on the record rather than rounded away.
- In-scope estate against observable estate
- Sources connected per domain, and sources missing
- Entities counted once across every Outcome
- Asset criticality alignment on what is covered
- Blind spots flagged, not silently excluded
45% of the confidence score
In scope
- Domain-joined endpoints and servers
- Active Directory ownership attributes
- CMDB records under contract
- HR org feed for owner resolution
- Asset criticality tiers in scope
Outside the boundary
- Non-domain-joined workstations
- Shadow IT not in any inventory
- Third-party SaaS outside identity scope
- Decommissioned assets still in DNS
Pending decisions
The artifact register is not published for ownership coverage yet, so nothing here is counted.
Live work
Owner assignment campaign tracking 1,442 of 1,520 in-scope assets. No tracker rows exist for blind-spot remediation yet.
How old is the source behind the number?
Source age, judged against the source's own cadence
Freshness compares when a source last published against how often it says it publishes. A feed that carries no as-of date is treated as stale rather than carried with a footnote, which lands freshness at 55 per cent in the worked example. Adding that date back is usually the cheapest confidence gain available.
- Source as-of date, taken from the source system
- Stated cadence for that feed
- Last evaluated and next due on the Metric
- Staleness discount applied when a date is missing
- Feeds behind cadence listed by name
30% of the confidence score
71%
weighted confidence
45% coverage · 30% freshness · 25% verification
Coverage
90% at weight 45%
Freshness
55% at weight 30%
Verification
55% at weight 25%
Fastest gain: add as-of date to source feed
What kind of evidence is the movement resting on?
Not every record counts the same, and the score knows it
Verification reads the evidence behind the claimed movement and weights it by kind. A validation that re-queries the source counts in full. An attestation that nobody can re-query is discounted instead. In the worked example, V-1 holds at 49 of 50 but the crown-jewel input behind it is attested, which puts this input at 55 per cent.
- Validation at source counted in full
- Completion alone counted as a claim, not a result
- Attestation discounted, however senior the attester
- Reverted items returned to the campaign
- Actions with no evidence recorded as none yet
25% of the confidence score
Completion
1,442
assets claimed · sampling: stratified 50
Method: AD ownership assignment
Completed: 14 Mar 2026
Work claimedValidation
49 / 50
HOLDS · AD re-query +7 days
- 49 assets still resolve owner in Active Directory
- 1 reverted on re-provisioning · returned to campaign
Outcome state: Open until validation holds at scale
Weighted 45 / 30 / 25, the three inputs above produce the 71 per cent confidence score shown on the dashboard.
Eight Outcome families. One intelligence fabric.
Continuous Threat Exposure Outcomes span cyber, risk, fraud, digital and compliance. They consume each other's intelligence instead of duplicating collection, and every entity is counted once. You do not need all eight running on day one, but the ones you are not running are named rather than left out of the picture.
Infrastructure visibility
The foundation Outcome. Multiple inventories reconciled into one record per asset, with ownership, criticality and dependency attached.
Identity exposure
Who holds access, which accounts carry privilege, and which of them resolve to a named owner.
Data exposure
Where sensitive data sits, who can reach it, and how much of the estate classification actually covers.
Vulnerability and patch state
Findings from your scanner, weighted by the criticality of the assets they affect rather than by severity alone.
Control assurance
Whether the controls you have contracted for are operating, measured against evidence instead of a control register.
Threat context enrichment
The cross-domain hub. Every context column names the Outcome that supplied it, and columns that do not resolve show as gaps.
Incident containment
Containment made impact-aware by reading the dependency graph from the infrastructure visibility Outcome.
Third-party exposure
Supplier and partner connections treated as part of your estate, with the same evidence rules as anything you own.
Seven links. Named, dated, owned.
Every piece of work runs the same path, and nothing is claimed as movement before the last link. Tool-led exposure programmes typically stop after link four, at a prioritised list and a closed ticket.
Reported by your tools, not ours
A finding is a named, dated, counted statement attributed to the system that produced it. For example: 13,699 assets have no owner attribute in Active Directory plus the HR org feed, as of 2026-08-01. The source tool is on the record, which is why disputes go back to the tool and why the as-of date is theirs.
The finding, made decidable
Findings are correlated across domains and joined to asset criticality, ownership and dependency. Every finding names the intelligence artifact it becomes, and every intelligence artifact names the decision it raised.
Baseline, target and current, under contract
Each Outcome carries a Metric with ten fields, drawn in full and evaluated on a fixed cadence: baseline, current, target, delta, trend, confidence, evidence, owner, evaluation and contribution. Most exposure reporting shows the second and third of those and calls it a commitment. Where no baseline exists, it is measured during transition and countersigned before a target becomes contractual.
Who decides is set in the contract, per decision
Each decision record leads with what raised it, then what it rests on, then who decides. Guardrails are explicit and quantified. An action that would cross an agreed threshold escalates instead of proceeding.
Dated plan, named owner, live tracker
Work packages carry committed dates and a running count of what is done against the total, tracked against a stated unit.
The change itself, in your environment
Executed at the autonomy level your contract sets for that decision type: Human Managed recommends and you approve, acts inside agreed guardrails, or acts and reports with approval and override rates reviewed.
Completion is not validation, and neither is an attestation
Completion says the work was done: 1,442 assets claimed, 50 sampled, 49 verified, sampling method stated. Validation says the source still agrees: Active Directory re-queried seven days later, 49 still resolving, one reverted on re-provisioning and returned to the campaign. Crown-jewel classification is an attestation, so it is discounted rather than counted. The three are never merged, and only validation moves an Outcome state.
Explainability
When a number moves, ask why it moved.
Explain sits on every finding, Metric, decision and evidence record. Your team can ask in plain language why a score is where it is, and get the working rather than a definition.
The reasoning is drawn from the engagement's own data, not a generic model of what should be true. When the answer is that a claim cannot yet be made, that is what it says.
The chain feeds the rest of invicta.io.
Outcomes do not sit in their own corner. They consume each other's intelligence rather than duplicating collection, and you see the result.
Enrichment recalculates when an upstream Outcome moves
On a 2026 network operations engagement, nine security Outcomes fed 23 consumption edges back into infrastructure Outcomes inside the same scope. Every context column names the Outcome that supplied it, and a column that stops resolving shows as a gap instead of a stale value.
Containment knows what it will take offline
Incident containment reads asset criticality and the dependency graph from the infrastructure visibility Outcome, so an impact-aware action is the default rather than a manual check before you pull something.
Escalations and state changes on the record
Reclassifying 412 assets up a criticality tier against an agreed 250-per-quarter guardrail appears as a decision for a named approver, not a completed change. A 90-day ledger lists each Outcome state change with the Metric movement that crossed the threshold.
Frequently Asked Questions
Stop reporting closed tickets. Start reporting closed exposure.
Continuous Threat Exposure is available as part of invicta.io by Human Managed.