Exposure Management Quick-Start Checklist
Retrospective: this article looks back at events from November 2024, written in 2026 with the benefit of hindsight.
Use this checklist to start an exposure management program with Microsoft Defender tools.
Setup
- Defender for Cloud with Defender CSPM enabled for production subscriptions and AWS/GCP connectors.
- Defender for Endpoint, Defender for Identity and Defender for Office 365 data feeding Exposure Management.
- Roles assigned for Exposure Management viewers and contributors.
Critical assets
- Predefined critical asset classifications reviewed.
- Custom critical assets added (crown-jewel databases, storage, apps).
- Owners recorded for each critical asset.
Attack paths
- Top 20 attack paths reviewed.
- Choke points identified.
- Remediation tickets created with owners and due dates.
Initiatives
- Exposure initiatives reviewed (for example, ransomware, BEC, cloud security).
- Two or three initiatives chosen as priorities for the quarter.
Integration
- Findings linked to your ticketing system.
- Vulnerability management and cloud posture processes use attack path context for prioritization.
Reporting
- Monthly report: attack paths to critical assets, choke points fixed, initiative scores.
- Quarterly review with leadership.
Ongoing
- New critical assets added as they're created.
- Exposure review included in change management for major projects.
- Microsoft Ignite 2024: Security Exposure Management and the Windows Resiliency Initiative Platform Changes
- How to Use Attack Path Analysis to Prioritize Cloud Fixes How-To & Hardening
- CIO Brief: From Alert Counts to Exposure Management CIO Briefings