New at Horizon3
Pentest Wednesday banner featuring NodeZero and the Find-Fix-Verify security testing rhythm

Patch Tuesday to Pentest Wednesday: How an Equipment Rental Company Is Turning Continuous Testing Into Continuous Exposure Management

Stephen Gates
September 9, 2026

A Pentest Wednesday® Story

Introduction

For a large equipment rental and services company with distributed operations supporting customers across a wide range of industries, technology is deeply embedded in how the business operates. Its environment spans corporate systems, customer-facing applications, digital services, and the technology supporting a complex rental and fleet operation. Across that footprint, cyber exposure is constantly changing.

That made point-in-time security testing increasingly difficult to rely on. A traditional penetration test could provide useful insight into the environment on the day it was performed, but it could not show what became exploitable the next day, the next week, or months before the next assessment.

The security team needed a way to continuously identify where exposure existed, validate what attackers could actually exploit, and use that evidence to drive remediation as the environment changed.

That shift is helping the organization move toward continuous exposure management. CTEM provides a framework for getting there, but the goal is not simply to execute its stages. It is to continuously reduce the exposures attackers can use. The NodeZero® Proactive Security Platform provides the continuous validation needed to help put that approach into practice.

As the company’s Chief Security Architect explained:

“We are leveraging the Horizon3 APIs to pull telemetry into Splunk for our CTEM attack surface management pipeline.”

For the team, that pipeline is ultimately about making exposure management continuous: identifying changes in the environment, validating what creates real risk, acting on the evidence, and measuring whether those actions actually reduce exposure.

Outcomes at a Glance

  • More findings in 12 hours than a third-party engagement found in roughly 30 days, giving the team faster evidence of where real exposure existed.
  • An SSH key exposure caused by a recent change was discovered in about eight hours, rather than potentially remaining unnoticed until the next annual pentest.
  • A suspected Cisco vulnerability was validated as exploitable, helping the team move from assumption to evidence and then remediate the affected systems.
  • Password testing exposed systemic Active Directory weaknesses, driving broader password and identity security changes.
  • NodeZero telemetry now feeds the organization’s CTEM attack surface management pipeline in Splunk, helping operationalize continuous exposure management.

Impact

The value of continuous exposure management became tangible when NodeZero began producing evidence faster and more consistently than the company’s traditional testing model.

In one comparison, NodeZero uncovered more findings in hours than a third-party assumed-breach and external penetration testing engagement found over several weeks.

As the company’s Chief Security Architect put it:

“You’ve uncovered and saved our bacon in multiple areas… You found more findings in 12 hours than they found in 30 days.”

The value was not simply speed. It was the ability to test repeatedly as the environment changed, validate which weaknesses were actually exploitable, and surface exposures that might otherwise remain hidden between scheduled assessments.

Background

The company’s move toward continuous exposure management was driven by a simple reality: its environment changes too quickly for annual or periodic testing to provide a current picture of exposure.

That became clear when an employee stood up a PHP web server for testing in the root directory. In doing so, SSH RSA key pairs were exposed, creating an opportunity for lateral movement.

NodeZero surfaced the issue roughly eight hours after the change was introduced.

As the company’s Chief Security Architect explained:

“That individual did that… theoretically, in most organizations, it would have been another pentest a year down the road where they would have found it, if they would have found it at all.”

That gap between when exposure is created and when it is discovered is exactly what continuous exposure management is designed to reduce. The goal is to identify changes that introduce risk and validate whether they create real attack paths.

The PHP server incident was not the only example. In another test, NodeZero discovered weak or default SSH credentials. Exposure can emerge from vulnerabilities, credentials, configurations, or everyday changes, and it does not wait for the next scheduled assessment.

Image 1: In another test, NodeZero discovered weak or default SSH credentials, showing how exploitable exposure can surface between scheduled assessments.

Mitigation

Continuous validation also helped the team move from knowing it had a password-policy problem to seeing the full extent of the exposure.

The company already planned to strengthen its Active Directory password requirements, including increasing minimum password length from eight to 12 characters. But NodeZero revealed that the issue went deeper. Testing showed widespread cracked and similar passwords, while the team also identified gaps around banned-password enforcement and service-desk password practices.

As the company’s CISO described it:

“We enumerated 15,000 passwords and of those 15,000, 300 are identical or similar and all compromised… It was ridiculous. It was insane. Think about that.”

That evidence helped turn a known weakness into an organizational priority. The company implemented a banned-password list, increased password length requirements, changed how the service desk handled passwords, and began rolling out self-service password reset.

Image 2: NodeZero AD Password Audit gave the security team measurable evidence of cracked and similar passwords across the environment, helping drive broader password and identity security changes.

The team then retested to see whether those changes were reducing the exposure. In a later audit, users with similar passwords had dropped from 880 to 209.

Image 3: Subsequent testing showed users with similar passwords drop from 880 to 209, providing measurable evidence that remediation was reducing identity exposure.

For the security team, that created something more valuable than evidence of the original problem: a way to measure improvement over time and show that changes to policy and process were reducing identity exposure.

That is the continuous exposure management outcome in practice: identify a systemic weakness, act on the evidence, retest, and measure whether the exposure has been reduced.

Remediation

The company’s Cisco infrastructure showed how continuous validation could turn suspected exposure into evidence that drove remediation.

The security team already suspected that some Cisco infrastructure might be vulnerable, but suspicion alone was not enough to prioritize action with confidence. NodeZero validated exploitation of CVE-2023-20198 in Cisco IOS XE and demonstrated downstream impact, including host and critical infrastructure compromise.

Image 4: NodeZero validated exploitation of CVE-2023-20198 in Cisco IOS XE infrastructure, demonstrating a path to host and critical infrastructure compromise.

Image 5: After NodeZero validated exploitation of CVE-2023-20198, the affected Cisco IOS XE instances were remediated and marked as mitigated or fixed.

That closed-loop process is central to continuous exposure management: prove which exposures matter, remediate them, and measure whether the exposure has been reduced.

Conclusion

For this company, continuous exposure management is becoming less about periodic snapshots and more about maintaining a current, evidence-based understanding of exposure.

NodeZero is helping the team continuously test the environment, validate what attackers can actually exploit, and turn that evidence into concrete remediation. It is also giving the organization a way to measure whether those changes are reducing exposure over time.

The company’s Chief Security Architect summed up the value this way:

“The value add is being able to continuously test for real vulnerabilities that can lead to findings, as well as some more advanced [things] such as purple team type of activities… we’re not even scratching the surface of the capabilities.”

That is the shift from point-in-time pentesting to continuous exposure management: not simply finding more issues, but continuously producing the evidence needed to understand exposure, act on what matters, and measure whether that exposure is being reduced.


What this shows about CTEM

CTEM is a framework for achieving continuous exposure management. Validation moves security teams from assumption to evidence. That evidence improves prioritization and drives action, while repeated testing helps measure whether exposure is actually going down.

How can NodeZero help you?
Let our experts walk you through a demonstration of NodeZero®, so you can see how to put it to work for your organization.
Get a Demo
Share: