Key Takeaways

  • A newly announced integration connects cyber risk intelligence with continuous exposure validation in a shared workflow.
  • Customers can test controls against relevant adversaries, campaigns, TTPs, IoCs, and CVEs, then return the evidence to Bitsight.
  • The planned integration supports CTEM by helping security teams distinguish theoretical exposure from demonstrated control gaps.

Cymulate has announced plans for an integration with Bitsight that will connect threat intelligence to continuous exposure validation, creating a feedback loop between identifying relevant threats and testing whether security controls can stop them.

The planned workflow begins with Bitsight, which provides asset discovery, business context, and intelligence about adversaries, campaigns, tactics, techniques and procedures, indicators of compromise, targeting trends, and related vulnerabilities. The validation platform uses that context to run scenarios against the threats considered relevant to a customer. Test results then flow back into Bitsight, adding evidence about which techniques were prevented or detected and which exposed a control gap.

That distinction matters. Security teams routinely receive vulnerability findings, threat reports, risk scores, and alerts from multiple systems. Each data source can be useful, but an extensive list of possible problems does not establish whether an attacker can exploit a specific weakness or evade the controls protecting a particular environment.

The two companies position validation evidence as a mechanism to prioritize remediation. Joint customers can test prevention and detection coverage against ransomware groups, advanced persistent threats, malware families, and active campaigns. Where testing demonstrates a gap, customers can apply remediation guidance or automated mitigation and then retest the control to confirm whether the change improved performance.

“Threat intelligence tells security teams what they should care about, but validation proves whether defenses can stop it,” noted the validation platform's co-founder and CTO. Connecting threat intelligence with exposure validation lets customers tailor testing to their specific threats and measure how controls perform against them.

Threat intelligence and security validation have historically operated as adjacent disciplines. Intelligence teams identify actors and techniques, while security engineering teams test products and detections. Connecting those activities shortens the route from learning about a campaign to checking whether endpoint, network, email, or other controls recognize its associated behavior.

The approach fits the broader shift toward continuous threat exposure management (CTEM). Gartner estimated in 2023 that organizations prioritizing CTEM practices will experience 3x fewer breaches of exposed assets by 2026 than organizations that do not. CTEM emphasizes recurring discovery, prioritization, validation, and remediation rather than relying mainly on periodic assessments.

Ongoing assessment reflects guidance from NIST, whose Cybersecurity Framework and SP 800-53 Rev. 5 treat control assessment, monitoring, and validation as core elements of risk management. Furthermore, ENISA reported in 2023 that organizations combining continuous control validation with risk-based prioritization reduce critical exposures by more than 50% compared with point-in-time assessments. These findings help explain the market interest in joining external intelligence to attack simulation.

The integration also supports threat hunting. Validation scenarios check whether expected detections fire when relevant attack behaviors or indicators are introduced. Hunters can use the resulting evidence to investigate potential compromises, identify telemetry gaps, and refine detection logic. While not a substitute for incident investigation, it provides analysts with a focused starting point.

The VP of product at Bitsight indicated that security teams require evidence showing which exposures enable specific attack paths, rather than just another list of potential vulnerabilities. The partnership advances Bitsight’s threat-informed risk prioritization by allowing customers to validate the severity and exploitability of findings across their attack surface.

Competition is already active in this sector. AttackIQ and SafeBreach provide breach and attack simulation and exposure validation capabilities, while SecurityScorecard competes with Bitsight in external cyber risk intelligence. MITRE ATT&CK mappings remain central to how customers organize adversary techniques and interpret validation results, although the vendors have not disclosed detailed technical architecture, availability dates, packaging, or pricing.

For prospective customers, those implementation details will shape the practical value. Data mapping, asset identity, retest automation, and the clarity of returned evidence will dictate whether the integration streamlines operations or merely adds another dashboard. Still, the strategic direction is clear: Cymulate and Bitsight want risk decisions to rest on observed control performance, not exposure data alone.