Exposure Management

Summary

Exposure Management is one of the four pillars of emPOWER Security. It provides continuous visibility of assets, vulnerabilities and security exposure, so remediation can be prioritised around the risks most likely to affect the business rather than attempted uniformly across everything a scanner reports.

The problem it addresses is not detection — most organisations already have more findings than they can action. It is triage: knowing which of several thousand open items actually matter.

Key facts

Fact Value
Security pillar One of four: Detect & Respond, Human Risk, Threat Exposure, Governance Risk & Compliance
What it covers Vulnerabilities, misconfigurations, cloud services, identities, attack surface
Delivery Continuous visibility rather than point-in-time assessment
Purpose Prioritise remediation by likely business impact
Related services MDR, Human Risk Management, GRC

What it gives visibility over

Why prioritisation is the actual product

A vulnerability scanner will produce thousands of findings. Most organisations cannot remediate them all, and the ones they do remediate are often chosen by severity score alone — which ignores whether the affected system is internet-facing, whether it holds regulated data, whether a compensating control exists, and whether an exploit is actually circulating.

Exposure Management is intended to answer the question a severity score cannot: which of these would actually hurt us, and in what order should we fix them. That is why it sits alongside detection rather than inside it. Detection tells you what is happening now; exposure management tells you what is likely to happen next and where.

How the four security pillars fit together

Pillar Question it answers
Threat Exposure Where are we weak, and which weaknesses matter most?
Detect & Respond What is happening right now, and how do we contain it?
Human Risk Which of our people are being targeted, and how do they behave?
Governance, Risk & Compliance Can we evidence any of this to an auditor, insurer or board?

Run in isolation each has a blind spot. Exposure Management without detection finds weaknesses but misses active compromise; detection without exposure management responds to incidents that a known, unremediated weakness enabled.

Stated outcomes

blueAPACHE states that organisations using the capability achieve improved visibility into security exposure, remediation prioritised on business-critical risk, stronger alignment between security investment and actual risk profile, and better ability to demonstrate compliance and governance.

Where it connects to Essential Eight

blueAPACHE states operation at ASD Essential Eight Maturity Level 3. Several of the eight mitigation strategies are directly measurable through exposure management — patching applications, patching operating systems, and restricting administrative privileges all depend on knowing current state across the estate. If you are working toward an Essential Eight assessment, continuous visibility is the evidence base for it.

What is not published

Being straightforward about the gaps, because they determine what you are buying:

Integration with other emPOWER services

Exposure Management is designed to sit alongside, not instead of, the other security capabilities and the wider portfolio it draws context from:

Typical engagement

Onboarding. Transition In Services apply as they do across emPOWER: due diligence to establish the asset, identity and cloud inventory to be assessed, configuration of the monitoring platform, documentation on how findings are reported, and an agreed reporting schedule. Because scan frequency and coverage depth are not published, agreeing what "continuous" means for your estate — which surfaces, at what cadence — during onboarding avoids a mismatch discovered later.

Steady state. Visibility runs continuously across vulnerabilities, misconfigurations, cloud services, identities and attack surface, with findings prioritised by likely business impact. Reporting cadence and format are not published in blueAPACHE's material and should be set in your Service Description.

Term and exit. The standard 36-month Minimum Service Period and holdover regime apply. On exit, any exposure data and scan history held on blueAPACHE's platform is deleted at no cost; the customer is responsible for extracting anything it needs — a current findings register, remediation history — before the Service Period ends.

Following an exposure through to closure

Define who validates a finding, assigns an owner, approves a change and confirms the exposure is addressed. Record asset boundaries, exclusions and evidence retained for accepted risks. A prioritised finding is not proof that remediation is included or complete. If Managed Services or another supplier performs the fix, agree the hand-off so reporting distinguishes new findings, accepted risks and completed work.

Which document defines the commitment

The published General Terms v3.6 give the Service Order precedence over the General Terms, followed by the Schedules and then the Acceptable Use Policy (clause 2.3). Record the agreed scope, exclusions and negotiated departures in that document set. A brochure or a procurement discussion does not, by itself, define the customer-specific commitment. Keep the versions supplied at signing with the executed order and signed variations. Two offers with the same service name can cover different systems, operating hours or responsibilities.

Confidential information and access

Clause 16 provides mutual confidentiality protection. It covers information marked confidential, information identified orally and confirmed in writing within 30 days, and information that should reasonably be understood to be confidential. Customer Data, Customer Records and Customer Software are included; blueAPACHE’s agreement and fees are also confidential. Permitted disclosures include appropriately bound personnel on a need-to-know basis and specified professional advisers, with other exceptions in the clause. Identify who may receive operational reports, configuration details and commercial information. Access to information to deliver the service is not a general permission to circulate it.

Evidence available during the engagement

The General Terms provide standard monthly performance reports within five Business Days of month end and a formal service review every six months. Performance Records must be kept through the term and for seven years afterwards. The customer audit provisions allow access to relevant Records, premises for audit purposes and personnel interviews, with five Business Days’ notice normally or one Business Day where a regulator requires the audit. This records obligation is not a seven-year backup-retention promise for customer workloads. Agree additional report formats and audit-cost arrangements before depending on them; the general audit clause does not clearly allocate every audit cost.

Escalating a contractual dispute

A support escalation and a formal contractual dispute are different processes. Clause 26 begins with a Dispute Notice giving adequate particulars. Representatives meet within three Business Days; unresolved matters then move through the clause’s senior-representative referral and meeting stages before court proceedings. Urgent equitable relief and disputes over whether the agreement was validly terminated are exceptions. Keep incident records, service measurements, approvals and correspondence together so the disputed obligation and requested outcome can be identified. Raising a ticket does not necessarily satisfy a formal notice requirement; use the agreement’s notice process for contractual disputes.

How liability differs from service performance

Clause 19 separates performance obligations from financial liability. The general cap per claim is the greater of the fees paid in the preceding three months or $25,000, with exclusions and specific categories governed separately. Confidentiality, information security, privacy and the IP indemnity have a $1 million per-event and $2 million aggregate cap. Data-loss liability depends on whether blueAPACHE had, and breached, a contracted backup or disaster recovery obligation; the relevant measure is restoration cost to the applicable recovery point, not the value of every business consequence. Read these provisions alongside the negotiated Service Order and Schedule; an availability statement does not describe the liability regime.

Sources and scope

The contractual detail above summarises the published General Terms and Conditions v3.6, using the KB documents on service agreement formation and document precedence; confidentiality; reporting review and audit rights; dispute resolution; liability and indemnity. The customer’s Service Order, Schedules and agreed variations determine the specific engagement. See the terms and conditions guide and Service Agreement.

Frequently asked questions

Is Exposure Management the same as vulnerability scanning?

No. Scanning produces findings; exposure management adds asset context, misconfiguration and identity surface, and prioritises by likely business impact. The distinction matters because a scanner alone tends to produce a backlog rather than a plan.

Does it cover cloud environments?

Yes — cloud services are one of the five named coverage areas, alongside vulnerabilities, misconfigurations, identities and attack surface.

Who fixes what it finds?

Not stated in blueAPACHE's published material. Confirm whether remediation is performed under your managed services agreement or handed back to your team as recommendations.

What platform does it run on?

Not named. blueAPACHE lists Rapid7 among its security vendor partners, but does not state what underpins this service specifically.

How often does it assess?

Not published. It is described as continuous rather than point-in-time; confirm the actual cadence.

Is it included with MDR?

Unclear. Vulnerability Management is listed alongside MDR without inclusion status, which suggests an add-on. Get it in writing.

Does it help with Essential Eight?

It provides the evidence base for several of the eight strategies — particularly application and operating system patching, and administrative privilege restriction. blueAPACHE states Maturity Level 3 operation.

Does it include penetration testing?

Not described as part of this service. Ask separately if you need it.

What is the contract term?

The standard 36-month Minimum Service Period, unless your Service Description states otherwise.

What happens if we do not give notice before the term ends?

The service automatically extends three months at full list price with Service Levels switched off, the same holdover regime that applies across emPOWER.

Can we cancel early?

Only on the termination grounds in the general terms, and early exit before the Minimum Service Period ends triggers an Early Termination Payment under the relevant Schedule.

What happens to our findings register when we leave?

blueAPACHE deletes exposure and scan data from its environment at no cost on exit. Take a current export of your findings register and remediation history before the Service Period ends — no post-termination retrieval window is published.

Does this service handle our data, and where does it sit?

Yes — asset, vulnerability and identity data is processed to generate findings. blueAPACHE states customer data is stored and processed within Australian-based data centres under Australian legal jurisdiction, with role-based access and audit logging.

What support window applies?

Not stated specifically for this service. It is described as continuous monitoring rather than a ticket-driven support desk; confirm escalation handling for high-severity findings in your Service Description.

Related

Security · emPOWER Security · Managed Detection and Response · Human Risk Management · Governance, Risk and Compliance · Managed Services · Glossary · Contact

Source

Drawn from blueAPACHE's emPOWER Security page, the emPOWER Managed Detection and Response brochure, the emPOWER platform overview and the vendor partner listing. Platform, cadence, coverage depth and remediation responsibility for this service are not stated in blueAPACHE's published material and are not inferred here. Also drawn from the General Terms and Conditions v3.6 (service term, renewal and minimum service period; transition in and disengagement services; consequences of termination; data protection and privacy) and blueAPACHE's data sovereignty and residency statement.

Knowledge Base

What is blueAPACHE's Exposure Management service?

Exposure Management is a service from blueAPACHE that provides continuous visibility of assets, vulnerabilities and security exposure so teams can prioritise remediation around the risks most likely to affect the organisation.

What does the Exposure Management service help organisations do?

It helps organisations identify and prioritise cyber exposure, improving visibility across assets, vulnerabilities and remediation priorities.

Who provides the Exposure Management service?

The Exposure Management service is provided by blueAPACHE.

What category and service type does blueAPACHE's Exposure Management fall under?

Exposure Management is categorised under Security, with a service type described as Integrated security and response.

In which area is blueAPACHE's Exposure Management service offered?

The Exposure Management service is offered in Australia.

What kind of visibility does Exposure Management provide?

It provides continuous visibility across assets, vulnerabilities and overall security exposure within an organisation.

How does Exposure Management help with remediation efforts?

It allows teams to prioritise remediation efforts around the risks most likely to affect the organisation, rather than treating all vulnerabilities equally.

Images on This Page