Where it fits

Where ESIP fits

ESIP is a layer, not a replacement. It does not scan your assets, manage your remediation, or replace your threat feed. It sits between the public evidence and the tools you already run, and answers one question none of them answer on their own: of everything you already know about, what changed, and does it matter more today than yesterday?


Your stack already answers a lot of questions

A scanner tells you what you have. A severity score tells you how bad it could be. A threat feed tells you who is active. A platform tracks the fixing. Each answers a real question, and ESIP replaces none of them. It answers the one a queue actually turns on: of everything already on your list, what just changed?

Organizations rarely suffer from too little security data. They suffer from not knowing what changed since yesterday.


What each layer answers, and what ESIP adds

Every layer in a modern security program answers a different question. ESIP adds one more.

LayerThe question it answersWhat ESIP adds
Scannerwhat do I have?which of those just changed
Severity score (CVSS)how bad could it be?severity is set once; the change is the signal
EPSShow likely is exploitation?reads it as one input; a probability moving is a signal
CISA KEVis it confirmed exploited?watches it as one signal source among several
Threat intelligencewho is attacking, and how?describes the exposure, not the adversary
VM platformwhat is my remediation status?feeds it what changed and why it matters
CTEM programhow do I run continuous exposure management?the intelligence input to the prioritization step
Asset inventory and ASMwhat do I own and expose?a class-level signal you apply to your own assets

What ESIP is not

To be precise about the boundary: ESIP is not a scanner, a vulnerability management platform, a CTEM platform, an asset inventory, or a SIEM. It is not a threat-intelligence platform, and it does not produce a risk score. It is the intelligence layer those systems consume: the part that says what changed and how much it matters, so each of them does its own job better.


One distinction worth making: class, not asset

An exposure signal describes an exposure class, not your organization's assets. The term is used inconsistently across the industry; some use "exposure signal" for an asset-level combination of conditions on one of your systems. ESIP means something different, and more reusable: a class-level assessment that means the same thing for everyone, which you then apply against your own environment. That is what lets one signal be produced once and used by every team running the affected technology.

The full definition →

Where it fits
Your tools: scanner · VM platform · CTEM · SOAR
consume the signal
ESIP: the exposure signal layer
reads the evidence, fires on change
Public evidence: KEV · EPSS · exploit repositories · patch status

A layer, not a replacement.


Get a free key and see where it fits in your stack.

Get a free key