ASM Has a Silent C, and It Stands for Change Management
If you run a security team, a large part of the job is responding to change. Something in the environment moves, and you have to work out whether risk moved with it, and how quickly you need to act. Those changes arrive from two different directions, external and internal. Of course, we’re all familiar with the external ones. A new CVE drops, a proof of concept goes public, a ransomware group starts naming your sector. The internal ones start inside your own organization.