MSSP, Exposure management, AI/ML, Identity, Data Security

Tenable Extends Exposure Management to the AI Attack Surface

Risk reduction

With AI now embedded across applications, cloud services, APIs, and automated agents, security teams are finding that AI risk does not sit only inside tools. It cuts across identities, data, infrastructure, and user behavior. Tenable’s expansion of Tenable One to include AI Exposure reflects this shift, treating AI as part of the attack surface rather than a separate category to manage later.

Liat Hayun, SVP of Product Management at Tenable, puts it plainly to MSSP Alert: “AI risk is an extension of the attack surface. It does not live in a single asset. It emerges across applications, infrastructure, identities, and data, and only becomes visible when those connections are understood together.” For many organizations, those connections are exactly what has been missing.

Bringing AI into the exposure management workflow

Most security teams already track vulnerabilities and attack surface risk. The challenge with AI has been fitting it into those existing workflows. AI tools are often adopted quickly, sometimes outside formal IT processes, which makes them difficult to govern and even harder to prioritize.

“With Tenable One, organizations can see, protect and manage AI risk alongside all other areas of risk for a more precise risk reduction strategy,” Hayun said. “We’re empowering security teams to address AI risk leveraging the platform they already use to manage all other forms of security risk.” The so-what here is efficiency: teams do not need a separate AI security program to start managing AI exposure in a meaningful way.

From isolated signals to real context

A recurring problem in security operations is noise. Isolated alerts rarely explain how risk actually materializes. Tenable’s approach focuses on context by mapping how AI interacts with data, identities, and systems.

“Tenable One provides a complete, risk-aware view of where AI operates, how it’s connected, where exposure is created, what data or processes it touches, who has access, and how users interact with it,” Hayun explained. “In short, Tenable One enables organizations to see, protect and govern AI usage across the enterprise.” This helps teams move from knowing that AI exists to understanding why a specific AI-related exposure matters.

Tenable’s AI approach is different

As more exposure management vendors talk about AI risk, differentiation comes down to depth and integration. Some tools add AI-related data into existing vulnerability or posture views, but stop there.

“Unlike point solutions that cover only one piece of the AI security puzzle, Tenable offers a comprehensive AI security solution that delivers on AI discovery, proaction, and governance,” Hayun said. Tenable One correlates issues such as misconfigurations, unsafe integrations, prompt injections, misbehaving agents, and shadow AI, helping teams focus on the AI exposures most likely to drive impact across environments.

Why this matters for MSSPs

For MSSPs, AI exposure management has to work at scale and across tenants. Managing multiple customers means strong separation, clear access controls, and repeatable outcomes.

“Tenable One AI Exposure is available in Tenable One, and is offered within the Tenable One workspace,” Hayun said. “This means that MSSPs can manage each of their clients from their MSSP multi-tenant portal without worry of data bleed between instances, as well as robust RBAC controls at both the MSSP and Client tenant level.” That structure supports managed services without adding operational complexity.

Just as important is showing value to customers. “Tenable One AI Exposure helps clients provide measurable risk reductions by not only alerting them to potential exposure of valuable data or misuse of AI models, but also provides controls to block their models from responding to requests that may lead to those issues,” Hayun said. For service providers, that turns AI security into something they can measure and report, not just explain.

AI is now woven into how businesses operate, which means it also reshapes the attack surface. Treating AI risk as a first-class exposure, rather than an add-on, reflects where security programs are headed. Tenable’s move signals that the question is no longer whether AI should be governed, but how quickly organizations can bring AI into the same risk conversations they already have for everything else.

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.
Suparna Chawla Bhasin

Suparna is the Senior Managing Editor for CyberRisk Alliance’s Channel Brands, including MSSP Alert and ChannelE2E. She manages content development, sharpens editorial workflows, and ensures storytelling is tightly aligned with audience needs. With a background in technology, media, and education, she combines strategic insight with creative execution.

You can skip this ad in 5 seconds