The exposure signal

What is an exposure signal?

Definition version 1.0.0 · Published 2026 · Status: Stable
Source: Exposure Signals: A Practical Definition and Reference Model for Vulnerability and Exposure Management, v1.0.0

An exposure signal is a deterministic, time-aware, evidence-backed assessment of an exposure class's exploitation state, derived from globally observable evidence.

Exposure Signals: A Practical Definition and Reference Model for Vulnerability and Exposure Management, v1.0.0


The defining property

An exposure signal describes an exposure class, not your organization's assets.

A class-level assessment of a security condition that exists independently of any asset, with local asset context left to the consumer. The term is used inconsistently across the industry; some apply "exposure signal" to an asset-level combination of conditions on one system. ESIP means something different, and more reusable: a class-level assessment that means the same thing for everyone.


What travels with the definition

Every clause is load-bearing
Deterministic
The same evidence under the same rules always produces the same assessment. Reproducible and replayable, not a number that wanders.
Time-aware
The assessment knows when it last moved and ages as its evidence ages. This is the clause that carries change.
Evidence-backed
Every verdict traces to its source. Strip the evidence and what is left is an opinion.
Exposure class
The stable unit a signal describes (a CVE is the archetype), not your asset.
Globally observable evidence
Public sources, not your environment: exploitation catalogs, exploit repositories, prediction scores, patch status.

Exploitation state means the current observable state of an exposure class, as determined by exploitation capability, exploitation activity, predicted exploitation likelihood, attack relevance, and remediation availability. Read it everywhere as defined here, not as attacker activity alone; a patch becoming available is a real change in that state.


Safe to cite

The canonical definition is intended to remain stable over time. Clarifications may be added through revision, but changes to the meaning of the term are expected to be rare.


What it is, and is not
It is
  • class-level
  • time-aware
  • evidence-backed
  • deterministic
It is not
  • a CVSS score
  • a risk score
  • an asset-specific scenario
  • just another alert

The "is not" column names the asset-level usage explicitly: an exposure signal is class-level, the same for everyone, not a combination of risks on one of your assets.


Signal, score, finding, alert, indicator

Five words that get blurred.

TermWhat it answersRelationship to a signal
Score How severe, or how likely, in the abstract. An input to a signal.
Finding Do I have this, and where? Establishes presence; the signal establishes urgency.
Signal How is the exposure class's exploitation state moving? The interpretation of change, with its evidence preserved.
Alert Notify me now. A delivery mechanism when a signal changes.
Indicator What adversary artifact was observed? A different domain; not exposure state.

Why this name

Threat signal pulls toward threat intelligence, with its actors and intent, which this model sets aside. Risk signal borrows from risk scoring, which folds in business impact the model does not carry. Exposure event names the raw change, not the published assessment. Exposure signal is the fit: exposure, because it describes the exposure class, and signal, because it is the interpreted, evidence-backed assessment of change.


Cite this
Reference
Exposure Signals: A Practical Definition and Reference Model for Vulnerability and Exposure Management
Author
Jonathan Risto
Publisher
ZenzizenSec Inc.
Version
1.0.0 (2026)
ISBN
978-1-0677048-1-0
License
Reference-friendly: free to use, cite, and reference, with no implied endorsement.

Cite as: Exposure Signals: A Practical Definition and Reference Model for Vulnerability and Exposure Management, v1.0.0, ZenzizenSec Inc., 2026. ISBN 978-1-0677048-1-0.

Read the full reference →

See it on a real CVE.

Try ESIP How ESIP builds one → Where it fits →