Vectra AI found attacker-relevant exposure conditions in 98% of enterprise environments, underscoring how AI agents, unmanaged devices, and rapidly changing infrastructure are making traditional security visibility less reliable.
The findings, detailed in the company’s 2026 State of Threat Exposure Management Report, suggest that exposure management now requires more than tracking known vulnerabilities. Security teams must also understand how assets, identities, automation, and communication patterns combine to create exploitable attack paths.
Dynamic enterprise environments undermine static inventories
Vectra AI found that enterprise environments are constantly evolving, making static asset inventories increasingly unreliable.
During a 14-day observation period, every environment analyzed saw new devices appear, while 90% introduced new device roles and 83% added new device types.
According to the report, that constant change creates uncertainty around ownership, management status, endpoint protection, segmentation, and communication behavior.
Unmanaged devices create gaps in endpoint visibility
The company also found that endpoint detection and response (EDR) tools leave significant blind spots.
On average, more than 30% of devices across observed environments were unmanaged because endpoint agents could not be installed on them.
Those devices included IoT and operational technology systems, network infrastructure, printers, legacy equipment, contractor-owned assets, and specialized workloads.
AI agents expand non-human identity risks
The report also points to the growing role of non-human identities in enterprise environments.
Across organizations with AI agent activity, Vectra AI observed roughly 1.17 AI agents per device on average over 90 days. In extreme cases, environments had up to 96 AI agents assigned to a single device, while 35% of environments contained more AI agents than devices.
According to the report, AI agents, service accounts, APIs, and automation workflows continuously authenticate, move data, and trigger downstream actions, creating new communication paths that security teams must monitor alongside traditional users and endpoints.
Legacy technologies remain widely exposed
Vectra AI found that 98% of analyzed environments contained at least one attacker-relevant exposure condition during a 30-day observation period, while 63% showed multiple categories of risk, including weak cryptography, exposed credentials, legacy protocols, and remote access services.
Among the most common issues were:
- deprecated TLS clients (96%)
- expired certificates (91%)
- NetBIOS (86%)
- plaintext passwords (85%)
- FTP (73%)
Rather than simply identifying vulnerabilities, the report argues that organizations need operational context to determine which exposure conditions are actually exploitable based on asset sensitivity, identities, segmentation, and communication behavior.
Vectra AI continues push toward proactive exposure management
The findings align with Vectra AI’s broader strategy announced earlier this year to emphasize preemptive security by reducing exposure before attackers gain access.
In January, the company launched the next generation of its cybersecurity platform with a focus on unified visibility across hybrid and AI-driven environments. That followed a December platform update centered on continuous exposure management throughout the attack lifecycle.
The latest report also builds on Vectra AI’s February State of Threat Detection and Response Report, which found that despite growing AI adoption, fragmented visibility and alert overload continued to limit cyber resilience.
Exposure management moves beyond vulnerability scanning
The findings point to a broader shift away from periodic vulnerability scans and static asset inventories toward continuous exposure management across hybrid environments.
For MSPs, MSSPs, and security partners, that shift creates a need to expand beyond endpoint coverage alone. Providers may need stronger asset discovery, identity monitoring, network telemetry, and risk-prioritization capabilities to help customers identify attack paths involving unmanaged devices, AI agents, cloud services, and legacy infrastructure.
As enterprise environments become more dynamic, the value of exposure management will increasingly depend on whether security teams and their partners can distinguish the risks that are merely present from those that attackers can actually exploit.





