The Wrong North-Star
Executives shouldn't judge attack surface management by how many assets are discovered. They should judge it by how quickly newly discovered assets are identified, assigned an owner, and brought under governance.
Many attack surface management programs report to executives by describing what the program did: assets discovered, ownership-assignment percentages, routing-completion rates, new-asset detection speed. These numbers describe program activity. On their own they are weak signals for the decisions leadership actually owns — where to invest, where to enforce accountability, and how much ungoverned surface the organization is willing to tolerate.
The more common framing error is the implied goal. A report that leads with "is the unknown, unmanaged surface shrinking?" sets up the wrong scoreboard.
For an organization that is growing, adopting cloud, or acquiring, total surface and newly-discovered unknown surface will trend upward for the foreseeable future. Judged against a shrinkage target, that program looks like it is failing every month — when the business is simply expanding. A north-star that a healthy, growing organization is structurally unable to hit is the wrong north-star.
The metric that holds up is not absolute shrinkage but dwell time and ratio: how long surface stays unknown or ungoverned after it appears, and whether governance converts unknown into classified-and-owned faster than discovery surfaces new unknowns. A program can absorb rising discovery indefinitely as long as the ungoverned backlog clears at or above the rate it fills. That is a target a growing organization can meet — and it is the question executives can actually act on.
A better measure is how quickly new assets move from unknown to known, owned
, and governed. The key questions become: How long does an asset remain unmanaged? And is the organization bringing new assets under governance as quickly as they are being discovered?
This insight already lives inside the evidence model below, in change-response timing. The reframe here is to promote it from a buried detail to the headline: report the velocity and the standing ratio of ungoverned surface, not the raw direction of a count.
Governance Coverage Is a Process Metric, Not a Risk Metric
A second framing problem is conflation. "Exposure," "risk," and "ungoverned surface" are often used interchangeably, but they measure different things, and treating them as one misleads the board.
Governance coverage — is this asset discovered, classified, owned, routed? — is a process metric. It describes whether the operating machine has the asset under management. It does not describe whether the asset is dangerous. A well-owned, well-routed asset can still be a critical exposure: an internet-facing host carrying a known-exploited vulnerability is severe regardless of how cleanly it is owned. An unowned asset may be trivial — an internal, unreachable, low-value service. Governance hygiene and risk severity are different axes.
Boards increasingly ask about risk, not governance hygiene. So executive ASM reporting that reports only on coverage answers a question leadership did not ask. The fix is to carry a risk dimension alongside the governance dimension: exploitability, asset criticality, external reachability, exposure severity, and known-exploited-vulnerability status. The governance evidence tells leadership whether the surface is
managed; the risk dimension tells leadership whether it is
dangerous. A useful report crosses the two — for example, the count and dwell time of surface that is both ungoverned and high-severity, which is the subset that should be governed first.
This is also where prioritization enters. Executives rarely want uniform governance applied evenly across, say, fifteen thousand assets. They want the crown-jewel, internet-exposed, exploitable subset governed first. A reporting model with no severity or criticality dimension reads as naive to a security leader and is hard to act on.
Where This Sits Relative to Established Frameworks
This model is a reporting layer, not a new methodology, and it is most useful when positioned against the frameworks a CISO already expects.
- Gartner CTEM (Continuous Threat Exposure Management) is the dominant industry framing for this problem and covers scoping, discovery, prioritization, validation, and mobilization. The evidence model here is intended as a way to report on the discovery, prioritization, and mobilization stages of a CTEM program to an executive audience — not as a replacement for it. CTEM's prioritization and validation stages are precisely the risk and confirmation dimensions this article folds in.
- CISA's Known Exploited Vulnerabilities (KEV) catalog and Cross-Sector Cybersecurity Performance Goals (CPGs) give the risk dimension an external anchor: KEV status is a concrete, defensible severity signal for the exploitability axis, and the CPGs frame baseline expectations executives can be measured against.
- NIST Cybersecurity Framework maps cleanly: discovery and classification serve the Identify function, and ownership, accountability, and the decision record serve the Govern function added in CSF 2.0.
- FAIR (Factor Analysis of Information Risk) is the reference model when leadership wants exposure expressed in quantified, financial terms rather than asset counts.
Positioning the report against these frameworks does two things: it tells leadership the program is not inventing private vocabulary, and it makes the risk dimension auditable against external standards rather than internal assertion.
A Caveat Before the Evidence: Data Quality
Every evidence type below assumes the underlying discovery, classification, and ownership data is accurate. In practice that assumption is the hardest part of the program, and it deserves to be stated to executives rather than hidden.
Two failure modes matter most. First, discovery is rarely provably complete — you can only measure dwell time for the unknowns you actually found, so a "shrinking" ungoverned ratio can reflect narrowed discovery scope as easily as real progress. False positives, duplicate assets, and discovery blind spots all distort the denominator.
Second, ownership is the most decay-prone field in any ASM or CMDB program. Owners change roles, assets transfer between teams, ownership is shared or disputed, and an "owner" recorded a year ago may no longer be accountable. Presenting an ownership percentage as clean executive evidence without addressing how ownership is
confirmed — and how often it is re-validated — would not survive scrutiny from a knowledgeable reviewer.
These are not reasons to avoid reporting. They are reasons to report ownership coverage with a freshness and confirmation-method qualifier, and to treat any single coverage number as an estimate with a known error mode rather than a precise finding. The same discipline guards against metric gaming: aggressive classification can inflate "owned" counts, and narrowed discovery can make unknown surface appear to shrink. Both are worth watching as incentives, not just measurements.
The Four Evidence Types
The model proposes four evidence types. Each answers a leadership question that an activity count does not. The illustrative figures used here are hypothetical and internally consistent — they show shape, not findings.
Ungoverned-Surface Dwell and Ratio EvidenceThis is the reframed headline. Rather than asking whether an absolute count is shrinking, it reports how long surface stays unknown or ungoverned (dwell time, as a distribution) and what share of total surface is ungoverned at a point in time (the standing ratio). Together these show whether governance is keeping pace with discovery: if the ungoverned ratio holds steady or falls while discovery rises, the program is converting unknown into owned at least as fast as new unknowns appear. Required data: total discovered assets, total classified-with-confirmed-ownership, ungoverned dwell-time distribution, and the ungoverned ratio over rolling 30/60/90-day periods, broken down by surface type. Leadership decisions it supports: whether classification and ownership capacity matches the current discovery rate, and whether an acquisition or cloud-expansion event has pushed dwell time or ratio past tolerance.
Ownership Coverage Evidence (with a data-quality qualifier)This shows what share of classified surface has a named accountable owner in a confirmed role, broken down by surface type and business unit, and crucially
how that ownership was confirmed and when it was last validated. It reveals where accountability gaps concentrate. Required data: classified assets with confirmed ownership by role, unowned assets by surface type and business unit, ownership-gap age distribution, and ownership freshness or last-confirmed date. Leadership decisions it supports: whether a specific business unit needs intervention, whether vendor-surface ownership gaps need contractual changes, and whether acquisition-integration timelines are producing ownership gaps that persist too long. Reported without the freshness qualifier, an ownership percentage tends to overstate how settled accountability really is.
Routing-and-Resolution EvidenceThe sharpest distinction in the original model was between a notification
sent and a confirmed intake
record — a handoff the program announced versus one a control team actually accepted as a work item. That distinction holds: a high notification-delivery rate can sit alongside control-team intake gaps, which is an asserted pattern worth measuring rather than assuming. But intake is one link short of what leadership cares about. The chain that matters is
intake → action → resolution: did the exposure get assigned, worked, and closed? Intake itself can be gamed — a record can be created and then stall — so the executive-grade version reports confirmed intake, time-in-progress, and resolution outcome, ideally weighted toward the high-severity subset. Required data: owned assets with confirmed intake records, time-in-progress and resolution timestamps by destination team, routing and resolution SLA compliance, and age distribution of unresolved items. Leadership decisions it supports: whether a control team needs intake or remediation capacity, whether routing rules have coverage gaps, and whether the SLA structure between ASM and control teams needs renegotiation.
Change-Response EvidenceThis measures time from new-surface detection to classification, ownership confirmation, and routing — the velocity behind the dwell-time headline. Reported as P50 and P90 by surface type, it shows where the governance chain slows and by how much, and whether high-velocity surface types (cloud deployments, shadow SaaS) need faster SLAs. Required data: detection, classification-completion, ownership-confirmation, and routing-completion timestamps per asset, with P50 and P90 by surface type. The P50/P90 framing is the model's most operationally credible piece: it captures the typical case and the tail, which is where ungoverned exposure tends to hide.
Operational versus Executive Reporting
Operational reporting serves practitioners running the daily program; executive reporting gives leadership evidence for governance decisions. The boundary is between input measurement and decision evidence: operational reports describe what was discovered, classified, and routed, while executive reports translate that into dwell time, the ungoverned-and-severe subset, ownership coverage by business unit, and resolution outcomes.
Operational data is the source material; the executive layer is the translation. Without that translation, leadership receives activity descriptions that do not map to a decision, and operational teams may optimize for metrics that drift from real risk reduction. Many mature programs already report a blended view rather than raw counts; the point here is to make the translation deliberate and risk-aware rather than incidental.
The Decision Record
ASM evidence is only useful if the decisions it surfaces are tracked. A decision record links each evidence finding to the leadership action it calls for: investment to clear an ownership backlog, an accountability intervention in a business unit with persistent ungoverned-and-severe surface, or an acquisition-surface governance requirement raised to the board. It captures the decision category, the owner, and the implementation status.
This overlaps deliberately with the risk-acceptance log and risk register most GRC programs already maintain — it is not a novel ASM artifact, and presenting it as one would reinvent existing terminology. The contribution is narrower: ASM evidence feeds the existing risk-register and risk-acceptance process with surface-specific findings, rather than standing up a parallel log. Where a GRC risk register already exists, the ASM decision record should be a view into it, not a competitor to it.
Executive Evidence Model Table
| Evidence Type |
What It Shows |
Data Required |
What Leadership Decision It Supports |
Activity Metric Commonly Substituted (and Its Limit) |
| Ungoverned-Surface Dwell and Ratio Evidence |
How long surface stays unknown/ungoverned (dwell distribution) and the standing ungoverned ratio; whether governance converts unknown into owned at or above the rate discovery adds new unknowns |
Total discovered assets, total classified-with-confirmed-ownership, ungoverned dwell-time distribution, ungoverned ratio over 30/60/90 days, breakdown by surface type |
Whether classification/ownership capacity matches the current discovery rate; whether an acquisition or cloud-expansion event pushed dwell time or ratio past tolerance |
"Total assets discovered" shows how much surface the program can see; a rising count is ambiguous (better discovery or worse governance) and penalizes growing organizations against an absolute-shrinkage target |
| Ownership Coverage Evidence (with data-quality qualifier) |
Share of classified surface with a named owner in a confirmed role, where gaps concentrate, and how/when ownership was confirmed |
Owned-by-role counts, unowned by surface type and business unit, ownership-gap age distribution, ownership freshness/last-confirmed date |
Whether a business unit needs intervention; whether vendor-surface gaps need contractual changes; whether acquisition timelines leave ownership gaps too long |
A single ownership percentage shows a fraction owned but hides concentration, gap age, and — without a freshness qualifier — overstates how settled accountability is given ownership-data decay |
| Routing-and-Resolution Evidence |
Confirmed intake records (not just notifications sent), time-in-progress, and resolution outcome, weighted toward the high-severity subset |
Owned assets with confirmed intake records, time-in-progress and resolution timestamps by team, routing/resolution SLA compliance, age distribution of unresolved items |
Whether a control team needs intake or remediation capacity; whether routing rules have gaps; whether the ASM–control-team SLA needs renegotiation |
"Routing completion" based on notification delivery shows handoffs were sent, not accepted, worked, or resolved; even confirmed intake can stall, so it stops short of "did the exposure get fixed?" |
| Change-Response Evidence |
Time from detection to classification, ownership confirmation, and routing — the velocity behind dwell time — as P50/P90 by surface type |
Detection, classification, ownership-confirmation, and routing-completion timestamps per asset, P50/P90 by surface type |
Whether governance-chain speed fits risk tolerance; whether high-velocity surface types need faster SLAs; whether capacity holds during expansion |
"New asset detection rate" shows how fast surface is found, not how long it takes to become governed; fast detection can sit alongside slow governance |
Sources