XM Cyber Enhances Identity Security Across Hybrid Systems with New Exposure Management Capabilities
XM Cyber, a leading provider of Continuous Exposure Management, has announced a significant round of platform enhancements designed to help organizations reduce identity risk in the era of AI-enabled attackers. The updates introduce deeper visibility into how permissions are actually used across enterprise environments — spanning Active Directory, cloud platforms, and hybrid infrastructure.
As organizations accelerate cloud adoption and expand hybrid architectures, the management of identities and access permissions has grown exponentially complex. Excessive permissions have emerged as one of the most exploited vectors in modern breaches, serving as a consistent pathway for lateral movement across hybrid-cloud environments. XM Cyber's latest release tackles this challenge head-on.
According to Gartner, by 2028, 70% of CISOs will deploy identity visibility and intelligence capabilities to shrink the IAM attack surface and reduce the risks of credential compromise. XM Cyber's new capabilities directly address this trajectory, putting organizations ahead of the curve.
"Least privilege access is a well-established principle for maintaining an effective security posture, but many organizations still struggle to achieve it due to the complexity of managing identities and access at enterprise scale."
— Boaz Gorodissky, CTO & Co-Founder, XM Cyber
The Identity Risk Challenge in Hybrid Environments
Modern enterprise environments present a formidable challenge: identities, roles, and entitlements are continuously changing across on-premises Active Directory, cloud platforms, and everything in between. Security and identity teams must constantly determine which exposures to prioritize and whether privileges can be safely revoked — all without disrupting business operations.
XM Cyber's platform already delivered actionable intelligence on Active Directory and cloud configurations. The new enhancements add a critical missing layer: granular visibility into how permissions are actually being used, enabling teams to distinguish genuinely necessary elevated access from dormant privileges that silently expand the attack surface.
What's New: Two Capability Pillars
The platform update introduces two distinct but complementary capabilities, each targeting a critical segment of the hybrid identity landscape:
Active Directory Excessive Permissions Analysis
Active Directory entities are continuously assessed to determine how frequently they make use of their assigned permissions. This makes it significantly easier for identity security practitioners to evaluate whether a specific permission level is genuinely required, and provides the necessary evidence to provision a fix — speeding time-to-remediation and closing attack paths that exploit over-permissioned accounts.
Cloud Infrastructure Entitlement Management (CIEM)
Entitlements for cloud entities are evaluated to provide a comprehensive view of usage patterns across large multi-cloud environments. Cloud security and DevSecOps teams gain the data needed to make informed decisions when cleaning up overly-permissive roles, boosting overall security posture and identity hygiene across AWS, Azure, GCP, and beyond.
"We're adding granular visibility into access permissions and their actual usage so teams can quickly see whether elevated permissions across Active Directory, Entra and cloud platforms are actually being used. If they aren't, that's a clear opportunity to remove permissions to reduce the attack surface and improve risk posture without disrupting operations."
— Boaz Gorodissky, CTO, XM Cyber
Connecting Identity Risk to Full Attack Paths
What makes XM Cyber's approach distinctive is how these new identity capabilities are woven into the broader Continuous Exposure Management framework. Rather than treating identity security as a silo, the platform connects identity risk to the full range of exposures it already discovers and prioritizes — giving organizations a clearer picture of how identity-related issues contribute to real, exploitable attack paths across hybrid environments.
Security and identity teams can surface excessive permissions that are validated as part of an active attack path. Unused permissions can be revoked outright to shrink the attack surface, or flagged for continuous monitoring as part of an ongoing identity security hygiene process. The result: faster, frictionless remediation workflows that bridge the gap between IT, DevOps, and Security teams.
Existing Platform Coverage
The new capabilities build on XM Cyber's already comprehensive Continuous Exposure Management foundation, which provides actionable intelligence across a broad range of identity exposure vectors:
Roles with Excessive Permissions
Continuous identification and prioritization of roles carrying more access than their function requires, enabling proactive right-sizing in line with least-privilege principles.
At-Risk Cached, Leaked & Reused Credentials
Detection of credentials that have been cached, exposed, or reused across systems — a frequent source of lateral movement and privilege escalation in hybrid environments.
Exposed Local & Domain Accounts
Visibility into local and domain accounts that are vulnerable to exploitation, mapped against attack paths to reveal which exposures pose the greatest risk to critical assets.
Third-Party Identity Security Tool Posture
Assessment of the security posture of third-party identity tools integrated into the enterprise stack, ensuring that external providers do not introduce blind spots into the overall security framework.
The release underscores a broader shift in how security leaders are approaching the identity problem. As AI-enabled attackers grow more sophisticated in exploiting credential and permission gaps, the static snapshots delivered by periodic pen tests and compliance audits are no longer sufficient. Continuous, context-aware visibility — the kind that maps permissions usage to live attack graphs — is rapidly becoming the baseline expectation for mature security programs.
XM Cyber's timing is deliberate. The company will be showcasing these new capabilities at the Gartner Security & Risk Management Summit, where the intersection of identity security, AI risk, and hybrid infrastructure is expected to dominate the conversation. For organizations navigating the complexity of enforcing least privilege at enterprise scale, the message is clear: understanding what access exists is only half the battle — understanding what access is actually being used is where the real security gains lie.
To learn more about XM Cyber's Continuous Exposure Management platform and its latest identity security enhancements, visit xmcyber.com.
