Buying a breach intelligence feed is easy. Turning it into measurable risk reduction is a programme, and programmes need an operating rhythm. This is the one that works.
1. Baseline before you monitor
Starting with continuous monitoring and an empty queue hides your actual position. Run the historic index against your assets first. The baseline is usually uncomfortable, and it is the number you will measure everything else against.
2. Define the asset scope properly
Most missed exposure is missed because nobody registered the asset. Include acquired brands, regional domains, legacy portals, and the supplier systems your staff hold accounts on. If it can authenticate one of your people, it is in scope.
3. Triage by identity type, then severity
Volume is not a priority signal. Sort by who the identity belongs to — employee, third party, customer — and then by what the credential unlocks. An administrator account on an SSO endpoint outranks ten thousand newsletter signups, every time.
4. Put remediation on a clock
Agree an SLA per severity tier before the first finding arrives, and measure against it. Without a clock, the queue becomes a backlog and the programme becomes a report nobody reads.
Remediation for a confirmed employee exposure is usually: force a password reset, revoke all active sessions, check for anomalous activity in the window, and — if the device is identifiable — take the machine out of service.
5. Close the loop with the user
An exposure almost always means a compromised device, not a careless password. Resetting the credential without addressing the machine means the next log will contain the new one. This is the step most programmes skip, and it is why some organizations keep finding the same person.
6. Report in the business’s terms
Leadership does not need record counts. It needs to know whether exposure is trending up or down, which decisions are outstanding, and what the programme has prevented. Report monthly, keep it to a page, and lead with the decisions.
What good looks like after six months
- Time from exposure appearing to session revocation, measured in hours.
- A falling count of repeat-exposed identities — the signal that device remediation is working.
- Supplier exposure raised and tracked, not just observed.
- A monthly one-pager that leadership reads without asking for a translation.