Thursdays With Erik: Educating Myself On Proactive Security Platforms
As a research director, I manage a team of analysts who cover a range of technologies outside my primary area of expertise (identity and access management). I’ve had to educate myself on these areas so I can oversee the quality of the analysts’ respective research and direct their research agendas.
One area of personal interest and rapid change has been Erik Nost’s coverage. When I hired Erik in late spring 2022, his main coverage was vulnerability risk management (VRM). Since joining, Erik has led our VRM coverage through significant market evolution, including the merger of external and internal attack surface management disciplines and the emergence of breach and attack simulation and exposure validation as critical complements to traditional VRM prioritization. All of these use cases have coalesced under “proactive security” — a solution category now offered by major security platforms which led to his publication of the first Forrester Wave™ evaluation on proactive security platforms last week.
As Erik’s coverage has evolved, I have pestered him with questions from clients, vendors, and my own research. Erik’s responses have helped me expand my own knowledge about the proactive security platform market. In these conversations, a consistent theme has emerged: Proactive security is a use case that borrows from a variety of market categories and emphasizes visibility, asset context, prioritization, validation and, increasingly, autonomous action. Below is a summary of the key themes and emerging trends from our discussions this year.
The Future Of Proactive Security: From Visibility To Preemptive Action
Over the past year, discussions across the cybersecurity industry have focused on moving beyond reactive security. But what does “proactive security” really mean, and where is the market headed next?
Erik’s conversations highlight how both vendors and security leaders are rethinking traditional approaches to vulnerability management, attack surface management, and exposure reduction, resulting in a broader vision of proactive security that extends far beyond simply finding vulnerabilities.
Why Visibility Is No Longer Enough
For years, security programs concentrated on discovering assets, identifying vulnerabilities, and prioritizing remediation efforts. While these capabilities remain critical, organizations now recognize that visibility alone does not improve security outcomes or keep up with the concerns that organizations have regarding AI-enabled threat landscapes.
This shift was one of the primary drivers behind Forrester’s move from evaluating attack surface management solutions to defining the broader category of proactive security platforms. The change reflects the reality that customers need platforms capable of discovery, prioritization, validation, and remediation rather than standalone visibility tools.
As the market (and threats) continue to evolve, security teams need solutions that help them understand which exposures truly matter and how to reduce risk most effectively rather than simply generating more findings.
The Rise Of Exposure Prioritization And Validation
A recurring theme has been the importance of moving beyond “whack-a-mole” security operations. Traditional approaches often focus on fixing individual vulnerabilities one at a time, creating a cycle of endless remediation without addressing underlying security weaknesses.
Since Anthropic announced its Mythos models’ cyber capabilities earlier this year, organizations have accelerated their interest in understanding attack paths, identifying choke points, validating exploitable exposures, and implementing structural improvements that reduce risk at scale. This evolution has fueled growing interest in exposure validation, attack path analysis, and risk-based prioritization capabilities.
The goal is not to fix more vulnerabilities. It is to eliminate the conditions that create recurring security problems in the first place.
Agentic AI Is Reshaping Proactive Security
AI is one of the most important catalysts for change in proactive security. A question we explored earlier this year was whether agentic security would disrupt reactive or proactive security programs and markets. Through our conversations, we concluded that agentic capabilities are not a replacement for proactive or reactive security. Rather, they are an enabler of it. AI agents can support and improve both reactive and proactive workflows depending on how they are applied.
AI also allows organizations to rapidly collect various contexts about an environment to make quicker, more strategic underlaying changes to security posture based on new conditions and threats. In this model, organizations use AI-driven analysis to identify risk conditions and automatically implement mitigations before an attack occurs. When risk thresholds are exceeded, platforms can trigger compensating controls, segmentation changes, policy adjustments, or remediation actions without waiting for human intervention. This represents a significant departure from traditional vulnerability management processes and will ultimately redefine what enterprises expect from security platforms.
Market Taxonomy Matters More Than Ever
The security market continues to struggle with overlapping terminology, including exposure management, continuous threat exposure management, vulnerability management, attack surface management, exposure validation, and now proactive security. Conversations with vendors and clients suggest that confusion remains widespread.
As a result, establishing clear market definitions is essential. A use-case-oriented framework based on proactive security provides greater stability than relying on rapidly changing vendor categories, AI-powered solutions, or marketing terminology. Even as technology categories continue to converge, organizations will still need capabilities focused on visibility, prioritization, validation, and remediation.
Looking Ahead
The next generation of proactive security will be defined by three major trends:
- Increased use of AI for prioritization and remediation
- Greater adoption of exposure validation and attack-path analysis
- Movement toward proactive security actions that automatically reduce risk before threats materialize
The industry has spent years improving visibility. The challenge now is turning insight into action. Organizations that successfully connect discovery, prioritization, validation, and automated remediation will be better positioned to reduce risk in an environment where threats, assets, and AI-driven attacks continue to accelerate, and proactive security prevents exposures from becoming incidents in the first place.
Forrester clients interested in discussing proactive security and the platforms providing this capability should schedule an inquiry or guidance session with Erik Nost.