# How to build an exposure management program the business trusts: Lessons from Tenable's CSO

DevFeed: [How to build an exposure management program the business trusts: Lessons from Tenable's CSO](<https://devfeed.tech/articles/how-to-build-an-exposure-management-program-the-business-trusts-lessons-from-tenable-s-cso-8265.md>)

Original publisher: [Read original article](<https://www.tenable.com/blog/how-to-build-an-exposure-management-program-the-business-trusts-lessons-from-tenables-cso>)

Author: Robert Huber

Published: 2026-08-27T14:30:00Z

Content type: tutorial

Language: en

Sources: [Tenable Blog](<https://devfeed.tech/sources/tenable-blog.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [data](<https://devfeed.tech/topics/data.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [data](<https://devfeed.tech/tags/data.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [exposure-management](<https://devfeed.tech/tags/exposure-management.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [metrics](<https://devfeed.tech/tags/metrics.md>), [security](<https://devfeed.tech/tags/security.md>), [tools](<https://devfeed.tech/tags/tools.md>), [visualization](<https://devfeed.tech/tags/visualization.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

## AI overview

Tenable's article explains how an exposure management program can reduce security tool sprawl, unify fragmented security data, improve visibility across the attack surface, and connect cyber-risk metrics with business priorities. It also discusses the challenges of maintaining security and speed while organizations rapidly adopt AI.

## Source excerpt

Discover how Tenable's shift to an AI-driven exposure management program helped Tenable's CSO, Robert Huber, overcome tool sprawl, unify data silos, mitigate the risk of rapid AI adoption, and shift from presenting granular, technical metrics to communicating business risk that the C-suite and the board can understand. Key takeaways Security tool sprawl and data silos make it difficult for CISOs to holistically and accurately assess their organizations' cyber risk. An exposure management program consolidates fragmented security data into a single unified view of cyber risk across the entire attack surface. Aided by exposure management, CISOs can align security metrics with business priorities and quantify risk for key revenue-generating business units, answering the board's main question: "Are we secure?" What is trust in cybersecurity? And more importantly, how do you earn it? Here's a hint: It's not easy, especially in this AI era. As the Chief Security Officer at Tenable, my mandate is to ensure our organization operates securely, but with the speed required to succeed in a very competitive business environment. In recent years, achieving this delicate balance -- an agile yet cyber secure business -- had become progressively more difficult, as we grappled with increasingly fragmented data, siloed teams, and security tool sprawl. In this blog, I'll explain how exposure management helped my team: Tackle security tool sprawl Bridge operational and data silos Take a more proactive approach to security Attain visibility and control over Tenable's attack surface Continuously and precisely assess our cyber risk posture The operational impact of security data silos and tool sprawl For years, the cybersecurity industry's answer to every new threat or policy mandate was simple: Buy another tool, which in many -- maybe most -- organizations resulted in a bad case of tool sprawl. A typical large enterprise might juggle 70 or more security technology vendors, each promising to so