**The Hidden Scale of Enterprise Cyber Risk: Why Asset Visibility Must Come First**
Most organizations operate under a dangerous illusion: they believe their asset inventories are sufficiently accurate to guide critical security decisions. However, a revealing case study from Lumen Technologies, combined with data from the 2026 Axonius Actionability Report, shatters this assumption and exposes a foundational flaw in how enterprises manage cyber risk. The data indicates a severe disconnect between perceived and actual asset scope, creating a dangerous foundation for security programs.
The report highlights a startling reality: only 45% of organizations successfully consolidate their asset and exposure data into a single, unified view. This consolidation gap means the vast majority of security teams are making decisions based on fragmented and potentially inaccurate data. The downstream impact is significant, as every security initiative—from vulnerability management to compliance reporting—inherits whatever inaccuracies exist in the foundational inventory.
A powerful example of this problem comes from Lumen Technologies, a company with nearly a century of operational history. Faced with a sprawling and complex environment, Lumen’s Director of Product and Platform Security, Geoff Krahn, and his team utilized an asset intelligence platform to reconcile data from over 40 disconnected IT and security tools. The results were not just an incremental improvement but a complete recalibration of their security posture.
**The Chasm Between Perception and Reality**
Lumen’s environment exemplified the chaos that can occur when multiple systems operate in silos. Different tools tracked different asset slices with varying levels of maturity, leading to contradictory data on device counts, ownership, and coverage status. Leadership questions about critical security metrics, such as the percentage of servers with Endpoint Detection and Response (EDR) installed, were met with the frustrating reality of conflicting data sources.
“We were constantly in incident response calls with no idea who owned what,” Krahn described.
To resolve this, the team implemented a platform capable of reconciling these disparate sources into a single, trusted model. The scope of the task was far larger than anyone had anticipated:
* **Starting point:** Approximately 17,000 known cyber assets across existing inventories.
* **After initial reconciliation:** 500,000 devices were identified and categorized.
* **Current scope:** A staggering approximate total of 1.1 million devices.
“It has really been an eye-opener for the organization as a whole,” Krahn stated. “Being able to quantify it and highlight gaps in controls has allowed us to gain the leadership support and funding we need.”
**From Blind Spots to Strategic Action**
This newfound visibility was not just an administrative exercise; it became the bedrock for a more effective and strategic security program. Reliable asset data enabled capabilities that are impossible without a clear picture of the environment.
* **Zero-Day Response:** When a critical vulnerability is disclosed, the speed of response is paramount. With a unified asset view, Lumen’s team can now identify affected systems, confirm if they are externally exposed, and determine ownership within minutes, pushing alerts directly to engineers. This capability transforms the response to zero-day threats from a frantic hunt into a coordinated, timely operation.
* **Application Posture Visibility:** Security extends beyond servers and endpoints to the applications they host. Lumen runs thousands of internal applications, and understanding their risk requires more than just a patch status. By correlating Configuration Management Database (CMDB) relationships with control coverage and vulnerability data, Lumen built an Application Posture Dashboard. This tool evaluates risk at the application level, linking security posture directly to business criticality and even potential revenue impact.
**Replacing “Scan and Spam” with Intelligent Risk Management**
A key insight from Lumen’s journey is that poor asset data inevitably leads to poor risk management practices. Without reliable context, security teams often default to a “scan and spam” methodology—prioritizing solely by Common Vulnerability Scoring System (CVSS) scores and remediating in numerical order. This approach ignores crucial factors like exploitability, blast radius, and business impact.
Critical issues can be buried under thousands of medium-severity findings that pose little actual risk to the specific environment. Armed with trusted asset data, Lumen adopted a risk-based approach. By combining technical findings with asset context and business criticality, tools like Axonius Exposures allow the team to surface the remediations that deliver the greatest risk reduction.
“Exposure management will allow us to evolve vulnerability management beyond scan and spam to intelligent risk-based requests driven by remediation actions that will deliver the most risk reduction,” Krahn concluded.
**A Wake-Up Call for Every Organization**
The transformation at Lumen—from a fragmented environment with 17,000 known assets to a unified view of over 1.1 million devices—demonstrates the profound gap that can exist in cyber asset management. If a dedicated security organization with over 40 inventory systems discovered its asset picture was off by a factor of 60, it serves as a stark warning for others.
Every exposure management program is only as strong as its underlying asset data. If that foundation is untested, the prioritization, ownership mapping, and remediation workflows built upon it are operating on assumptions, not evidence. Lumen’s story is a powerful reminder that true security begins not with fixing vulnerabilities, but with first achieving true visibility into the assets that need protection.
***
**Original Source:**
This article is based on the case study and insights presented in the **2026 Axonius Actionability Report**, as detailed in the article *”Million”* by Axonius. The post details Lumen Technologies’ journey to reconcile its asset inventory and the subsequent improvements in its security posture. You can find the original content on the Axonius blog [here](https://www.axonius.com/platform/exposures?utm_medium=cpc&utm_source=TheHackerNews&utm_campaign=LumenCaseStudy&utm_content=text_link&utm_term=LumenCaseStudy).



