How You’ll Be Doing Attack Surface Management Differently in 2026
Download resourcesAbout this session
Greg Young, VP Cybersecurity and Corp Dev at Trend Micro and former Gartner analyst, traces attack surface management from procurement lists through EASM and CAASM to the emerging category of cyber risk exposure management (CREM), which links asset, identity, threat and data context in one platform instead of siloed tools. He walks a real multi-step breach (initial CVE exploitation, name-resolution spoofing, password-hash cracking, lateral movement into an unprotected dev environment, credential theft, domain admin via a misconfigured AD certificate template, then ransomware) and shows where each step could have been stopped with zero-trust access, Credential Guard, EDR, and stronger password policy. He argues legacy tools give industry-average, undefendable importance scores, and that the next generation should use attack-path prediction and full telemetry to defend prioritization decisions to a board, tie remediation to compliance impact, and express risk in dollar terms using cyber risk quantification (the FAIR methodology) rather than raw CVSS scores. A Q&A covers compliance sometimes breaking when security controls change, and how AI is speeding up both attackers and defenders, especially in vulnerability triage and remediation.
The technology for understanding your attack surface is rapidly changing. Join a former Gartner analyst and CISO map out how surface management moved to include remediation, but today is migrating to bringing in more telemetry about the true importance and posture of assets, context, data and users. All the while, moving from reactive to proactive response towards Cyber Risk Exposure Management.
Key takeaways
- Stop treating external (EASM) and internal (CAASM) attack surface views as separate programs; attackers move across both continuously.
- Enforce longer, high-entropy passwords and enable Credential Guard by default; cheap cloud cracking (about 37 cents for 100 hashes) makes weak password composition the fastest path to lateral movement.
- Lock down Active Directory certificate templates and treat AD hygiene as a top security-posture indicator, since misconfigured templates are a common route to domain admin and ransomware deployment.
- Replace industry-average vulnerability scores with attack-path prediction and full telemetry so remediation priorities are defendable to a board rather than 'it's an Oracle server, so it's important.'
- Quantify risk in dollars per scenario (likelihood and cost) using a methodology like FAIR instead of raw CVSS, so leadership can weigh the cost of remediation against the cost of the incident.
Speakers

Greg Young is the Vice President of Cybersecurity and Corp Dev for Trend Micro. He has over 35 years of experience in cybersecurity. Greg was a Research Vice President and analyst with Gartner for 13 years, CISO for the Federal Department of… Read moreRead less
Greg Young is the Vice President of Cybersecurity and Corp Dev for Trend Micro. He has over 35 years of experience in cybersecurity. Greg was a Research Vice President and analyst with Gartner for 13 years, CISO for the Federal Department of Communications, Chief Security Architect for a security product company, headed several large security consulting practices, and as Captain Young served in the military police and counterintelligence branch. Greg received the Confederation Medal from the Governor General of Canada for his work with smart card security. He currently is: Member and former co-chair for the federal government’s Forum on Digital infrastructure Resilience (CFDIR), and a member of the AI Working Group, and the Supply Chain Resilience Working Group, on the federal National Cross Sectoral Forum (NCSF) for Critical Infrastructure, appointed by cabinet of the Government of Barbados as a member of their Cybersecurity Working Group, liaison to the Canadian Security Telecommunications Advisory Committee (CSTAC).

