Exposure Management
Summary
Exposure Management is one of the four pillars of emPOWER Security. It provides continuous visibility of assets, vulnerabilities and security exposure, so remediation can be prioritised around the risks most likely to affect the business rather than attempted uniformly across everything a scanner reports.
The problem it addresses is not detection — most organisations already have more findings than they can action. It is triage: knowing which of several thousand open items actually matter.
Key facts
| Fact | Value |
|---|---|
| Security pillar | One of four: Detect & Respond, Human Risk, Threat Exposure, Governance Risk & Compliance |
| What it covers | Vulnerabilities, misconfigurations, cloud services, identities, attack surface |
| Delivery | Continuous visibility rather than point-in-time assessment |
| Purpose | Prioritise remediation by likely business impact |
| Related services | MDR, Human Risk Management, GRC |
What it gives visibility over
- Vulnerabilities — identified weaknesses in systems and applications
- Misconfigurations — security control gaps in infrastructure, which are frequently more exploitable than unpatched software
- Cloud services — cloud assets and their exposure, including resources created outside a formal provisioning process
- Identities — identity-related attack surface, which is where most modern intrusions actually begin
- Attack surface — the full scope of exploitable entry points, including what is externally reachable
Why prioritisation is the actual product
A vulnerability scanner will produce thousands of findings. Most organisations cannot remediate them all, and the ones they do remediate are often chosen by severity score alone — which ignores whether the affected system is internet-facing, whether it holds regulated data, whether a compensating control exists, and whether an exploit is actually circulating.
Exposure Management is intended to answer the question a severity score cannot: which of these would actually hurt us, and in what order should we fix them. That is why it sits alongside detection rather than inside it. Detection tells you what is happening now; exposure management tells you what is likely to happen next and where.
How the four security pillars fit together
| Pillar | Question it answers |
|---|---|
| Threat Exposure | Where are we weak, and which weaknesses matter most? |
| Detect & Respond | What is happening right now, and how do we contain it? |
| Human Risk | Which of our people are being targeted, and how do they behave? |
| Governance, Risk & Compliance | Can we evidence any of this to an auditor, insurer or board? |
Run in isolation each has a blind spot. Exposure Management without detection finds weaknesses but misses active compromise; detection without exposure management responds to incidents that a known, unremediated weakness enabled.
Stated outcomes
blueAPACHE states that organisations using the capability achieve improved visibility into security exposure, remediation prioritised on business-critical risk, stronger alignment between security investment and actual risk profile, and better ability to demonstrate compliance and governance.
Where it connects to Essential Eight
blueAPACHE states operation at ASD Essential Eight Maturity Level 3. Several of the eight mitigation strategies are directly measurable through exposure management — patching applications, patching operating systems, and restricting administrative privileges all depend on knowing current state across the estate. If you are working toward an Essential Eight assessment, continuous visibility is the evidence base for it.
What is not published
Being straightforward about the gaps, because they determine what you are buying:
- The underlying platform is not named. blueAPACHE's vendor material references Rapid7 among its security partners, but the emPOWER Security material does not state which tooling underpins Exposure Management. Ask, particularly if you already license a vulnerability management product.
- Scan frequency and coverage — how often assessment runs, and whether it covers external, internal, cloud and identity surfaces equally, is not stated.
- Reporting cadence and format — not published.
- Whether remediation is included or advisory only. This is the most important unanswered question. Visibility and prioritisation are described; who actually performs the fix is not. Confirm whether findings are handed to your team or remediated under Managed Services.
- Inclusion status. Vulnerability Management appears alongside MDR in blueAPACHE's material without inclusion status stated, which suggests exposure capability may be an add-on rather than bundled. Confirm in your service schedule.
- Penetration testing — not described as part of this service in blueAPACHE's published material.
Integration with other emPOWER services
Exposure Management is designed to sit alongside, not instead of, the other security capabilities and the wider portfolio it draws context from:
- Managed Detection and Response — exposure findings identify what is weak; MDR watches for active exploitation of it. Vulnerability Management is listed alongside MDR in blueAPACHE's material without stated inclusion status, so confirm whether exposure visibility is bundled with your MDR service or purchased separately
- Human Risk Management — identity-related attack surface is one of the five areas this service covers, and it is also where human risk outcomes are measured
- Governance, Risk and Compliance — prioritised findings are the evidence base GRC reporting draws on for auditors, insurers and boards
- Managed Services — automated patching under a managed service bundle is one of the direct remediation paths for findings this service surfaces, though who performs the fix is not stated in published material and should be confirmed on the Service Order
- Cloud — cloud services are a named coverage area, so cloud assets managed under emPOWER Cloud fall within the same visibility
Typical engagement
Onboarding. Transition In Services apply as they do across emPOWER: due diligence to establish the asset, identity and cloud inventory to be assessed, configuration of the monitoring platform, documentation on how findings are reported, and an agreed reporting schedule. Because scan frequency and coverage depth are not published, agreeing what "continuous" means for your estate — which surfaces, at what cadence — during onboarding avoids a mismatch discovered later.
Steady state. Visibility runs continuously across vulnerabilities, misconfigurations, cloud services, identities and attack surface, with findings prioritised by likely business impact. Reporting cadence and format are not published in blueAPACHE's material and should be set in your Service Description.
Term and exit. The standard 36-month Minimum Service Period and holdover regime apply. On exit, any exposure data and scan history held on blueAPACHE's platform is deleted at no cost; the customer is responsible for extracting anything it needs — a current findings register, remediation history — before the Service Period ends.
Following an exposure through to closure
Define who validates a finding, assigns an owner, approves a change and confirms the exposure is addressed. Record asset boundaries, exclusions and evidence retained for accepted risks. A prioritised finding is not proof that remediation is included or complete. If Managed Services or another supplier performs the fix, agree the hand-off so reporting distinguishes new findings, accepted risks and completed work.
Which document defines the commitment
The published General Terms v3.6 give the Service Order precedence over the General Terms, followed by the Schedules and then the Acceptable Use Policy (clause 2.3). Record the agreed scope, exclusions and negotiated departures in that document set. A brochure or a procurement discussion does not, by itself, define the customer-specific commitment. Keep the versions supplied at signing with the executed order and signed variations. Two offers with the same service name can cover different systems, operating hours or responsibilities.
Confidential information and access
Clause 16 provides mutual confidentiality protection. It covers information marked confidential, information identified orally and confirmed in writing within 30 days, and information that should reasonably be understood to be confidential. Customer Data, Customer Records and Customer Software are included; blueAPACHE’s agreement and fees are also confidential. Permitted disclosures include appropriately bound personnel on a need-to-know basis and specified professional advisers, with other exceptions in the clause. Identify who may receive operational reports, configuration details and commercial information. Access to information to deliver the service is not a general permission to circulate it.
Evidence available during the engagement
The General Terms provide standard monthly performance reports within five Business Days of month end and a formal service review every six months. Performance Records must be kept through the term and for seven years afterwards. The customer audit provisions allow access to relevant Records, premises for audit purposes and personnel interviews, with five Business Days’ notice normally or one Business Day where a regulator requires the audit. This records obligation is not a seven-year backup-retention promise for customer workloads. Agree additional report formats and audit-cost arrangements before depending on them; the general audit clause does not clearly allocate every audit cost.
Escalating a contractual dispute
A support escalation and a formal contractual dispute are different processes. Clause 26 begins with a Dispute Notice giving adequate particulars. Representatives meet within three Business Days; unresolved matters then move through the clause’s senior-representative referral and meeting stages before court proceedings. Urgent equitable relief and disputes over whether the agreement was validly terminated are exceptions. Keep incident records, service measurements, approvals and correspondence together so the disputed obligation and requested outcome can be identified. Raising a ticket does not necessarily satisfy a formal notice requirement; use the agreement’s notice process for contractual disputes.
How liability differs from service performance
Clause 19 separates performance obligations from financial liability. The general cap per claim is the greater of the fees paid in the preceding three months or $25,000, with exclusions and specific categories governed separately. Confidentiality, information security, privacy and the IP indemnity have a $1 million per-event and $2 million aggregate cap. Data-loss liability depends on whether blueAPACHE had, and breached, a contracted backup or disaster recovery obligation; the relevant measure is restoration cost to the applicable recovery point, not the value of every business consequence. Read these provisions alongside the negotiated Service Order and Schedule; an availability statement does not describe the liability regime.
Sources and scope
The contractual detail above summarises the published General Terms and Conditions v3.6, using the KB documents on service agreement formation and document precedence; confidentiality; reporting review and audit rights; dispute resolution; liability and indemnity. The customer’s Service Order, Schedules and agreed variations determine the specific engagement. See the terms and conditions guide and Service Agreement.
Frequently asked questions
Is Exposure Management the same as vulnerability scanning?
No. Scanning produces findings; exposure management adds asset context, misconfiguration and identity surface, and prioritises by likely business impact. The distinction matters because a scanner alone tends to produce a backlog rather than a plan.
Does it cover cloud environments?
Yes — cloud services are one of the five named coverage areas, alongside vulnerabilities, misconfigurations, identities and attack surface.
Who fixes what it finds?
Not stated in blueAPACHE's published material. Confirm whether remediation is performed under your managed services agreement or handed back to your team as recommendations.
What platform does it run on?
Not named. blueAPACHE lists Rapid7 among its security vendor partners, but does not state what underpins this service specifically.
How often does it assess?
Not published. It is described as continuous rather than point-in-time; confirm the actual cadence.
Is it included with MDR?
Unclear. Vulnerability Management is listed alongside MDR without inclusion status, which suggests an add-on. Get it in writing.
Does it help with Essential Eight?
It provides the evidence base for several of the eight strategies — particularly application and operating system patching, and administrative privilege restriction. blueAPACHE states Maturity Level 3 operation.
Does it include penetration testing?
Not described as part of this service. Ask separately if you need it.
What is the contract term?
The standard 36-month Minimum Service Period, unless your Service Description states otherwise.
What happens if we do not give notice before the term ends?
The service automatically extends three months at full list price with Service Levels switched off, the same holdover regime that applies across emPOWER.
Can we cancel early?
Only on the termination grounds in the general terms, and early exit before the Minimum Service Period ends triggers an Early Termination Payment under the relevant Schedule.
What happens to our findings register when we leave?
blueAPACHE deletes exposure and scan data from its environment at no cost on exit. Take a current export of your findings register and remediation history before the Service Period ends — no post-termination retrieval window is published.
Does this service handle our data, and where does it sit?
Yes — asset, vulnerability and identity data is processed to generate findings. blueAPACHE states customer data is stored and processed within Australian-based data centres under Australian legal jurisdiction, with role-based access and audit logging.
What support window applies?
Not stated specifically for this service. It is described as continuous monitoring rather than a ticket-driven support desk; confirm escalation handling for high-severity findings in your Service Description.
Related
Security · emPOWER Security · Managed Detection and Response · Human Risk Management · Governance, Risk and Compliance · Managed Services · Glossary · Contact
Source
Drawn from blueAPACHE's emPOWER Security page, the emPOWER Managed Detection and Response brochure, the emPOWER platform overview and the vendor partner listing. Platform, cadence, coverage depth and remediation responsibility for this service are not stated in blueAPACHE's published material and are not inferred here. Also drawn from the General Terms and Conditions v3.6 (service term, renewal and minimum service period; transition in and disengagement services; consequences of termination; data protection and privacy) and blueAPACHE's data sovereignty and residency statement.
Knowledge Base
What is blueAPACHE's Exposure Management service?
Exposure Management is a service from blueAPACHE that provides continuous visibility of assets, vulnerabilities and security exposure so teams can prioritise remediation around the risks most likely to affect the organisation.
What does the Exposure Management service help organisations do?
It helps organisations identify and prioritise cyber exposure, improving visibility across assets, vulnerabilities and remediation priorities.
Who provides the Exposure Management service?
The Exposure Management service is provided by blueAPACHE.
What category and service type does blueAPACHE's Exposure Management fall under?
Exposure Management is categorised under Security, with a service type described as Integrated security and response.
In which area is blueAPACHE's Exposure Management service offered?
The Exposure Management service is offered in Australia.
What kind of visibility does Exposure Management provide?
It provides continuous visibility across assets, vulnerabilities and overall security exposure within an organisation.
How does Exposure Management help with remediation efforts?
It allows teams to prioritise remediation efforts around the risks most likely to affect the organisation, rather than treating all vulnerabilities equally.
Images on This Page
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a6ffec7d87be5a881637bba_31b5a84971e1d1ce71dc99ca059bfbde_blueAPACHE.svg
blueAPACHE logo on a dark blue background
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a713402a5a7f7ebf553f0bf_Background-Top.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fbfad31fa678fefd51a_6a704f395a0a01b8e482853a_support-monitor.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4563e_6a704f3a400fc8e661400519_support-user.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45639_6a704f3a91ffd7d0dbc40847_support-phone.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4562f_6a704f3747d60bd3f65b7a31_support-globe.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45636_6a704f38eb60992797acf5d9_support-mail.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45633_6a704f3a07b7741bf54f2122_support-speech-bubble.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a707520ca872d1b5a69a518_Sensiba.avif
Sensiba ISO/IEC 27001 Certified badge with a diamond-shaped logo below the text.