Photo Gallery
|
|
Onit Security
Additional Info
| Company | Onit Security |
| Company size | 10-39 employees |
| World Region | North America |
| Website | https://onit.security/ |
NOMINATION HIGHLIGHTS
Gartner’s CTEM framework gave the industry the right operating model: Scoping, Discovery, Prioritization, Validation, Mobilization. But nearly every CTEM program stalls in the same place – the final stage. Organizations scope, discover, prioritize, and validate, and then Mobilization collapses back into tickets, spreadsheets, and ownership debates. The program produces a better-understood backlog instead of a smaller one.
Onit Security built the execution layer CTEM was missing, and named its operating model Decision-Based Exposure Management. It is the layer that turns a CTEM program’s prioritized, validated findings into completed, verified fixes.
How Onit runs the CTEM loop:
Discovery and consolidation: API connections to 100+ tools (scanners, cloud, CMDB, ticketing, collaboration) feed one continuously updated knowledge graph. Findings are normalized, deduplicated, and filtered.
- Prioritization with context: exposures are ranked by real-world business impact, drawn from asset criticality, ownership, and blast radius, not by raw CVSS.
- Validation in the live environment: reachability and exploitability agents prove whether each exposure is actually attackable before it reaches a human, with evidence attached. Theoretical criticals on unreachable assets are deprioritized accordingly.
- Mobilization, finally solved: this is Onit’s core innovation. Exposures that resolve together are grouped into a single decision. A human approves it once; AI agents then find the true owner, deliver the fix guidance, chase the work to verified closure, and apply the same decision automatically to every future matching exposure. One decision resolves thousands of exposures. Decide once. Resolve forever.
The mobilization numbers CTEM programs struggle with are exactly the ones Onit attacks: roughly 50% of remediation tickets bounce back from the wrong owner, another 30% stall for lack of context, and the industry’s remediation half-life stands at 243 days (Veracode 2026) while exploitation now begins within days – sometimes hours – of disclosure.
In production, Onit works with Fortune 500 companies including Honeywell and Marvell. Its largest deployment runs continuous exposure management across 50+ million active exposures and roughly 700,000 assets in a hybrid cloud and on-premises environment, with resolution reduced from months to hours.
CTEM told the industry what a mature exposure program looks like. Onit makes the last, hardest stage of it actually happen – continuously, at enterprise scale, with humans defining judgment and agents executing.
Help This Nominee Win a
Community Choice Award
Vote by sharing this page:
Cast your vote by sharing this nominee’s profile on LinkedIn, Facebook, or X, using the buttons above. Each completed social share adds one Community Choice vote.
Votes recorded by July 18, 2026 will determine the Community Choice winners. Winners will be announced before Black Hat USA.
What is the Community Choice Award? →
Community Choice is a separate award track from the jury-selected Cybersecurity Excellence Awards. Jury winners are chosen by expert judges, while Community Choice winners are determined by public voting. A nominee may be honored by the jury, the community, or both.



