back to blog
BLOG
The Control Gap Reality: How Exposure Operations Secures the Perimeter
Nagomi Security

![]()
By Nagomi Security
The FortiGate incidents from the past few years highlight a bothersome challenge in perimeter security, namely, that edge infrastructure serves as both the first line of defense and the most attractive attack target for initial access.
In the case of the recent FortiBleed issues, a memory disclosure vulnerability in FortiOS SSL-VPN appliances allowed unauthenticated attackers to read portions of process memory directly from exposed devices. Session tokens, usernames, passwords, and other sensitive data could potentially be stolen without an attacker ever needing to authenticate to the appliance itself. For organizations that depended on FortiGate devices to protect remote access, the firewall effectively became an attack surface.
One of the most concerning issues about this incident is that the technical problem extended well beyond the vulnerability itself. The stolen VPN credentials create another downstream issue: What else do those credentials offer access to?
For many organizations, the answer depends less on the appliance and more on the surrounding control ecosystem. If conditional access policies restrict logins to managed devices, the credentials may have limited value. For example, if endpoint telemetry exists across critical systems, suspicious activity may trigger rapid detection. If service accounts follow least-privilege principles and segmentation controls limit east-west movement, the attack path narrows considerably.
Unfortunately, perimeter compromises rarely occur in isolation.
An exposed VPN appliance combined with permissive outbound access rules, incomplete endpoint coverage, disabled tamper protection, or overprivileged accounts creates conditions that adversaries actively seek. None of those issues independently represents a catastrophic failure. Together, however, they create an efficient path from internet exposure to internal compromise.
Traditional vulnerability management programs struggle to distinguish between those two very different scenarios.
Beyond CVSS: The Control Gap Reality
CVSS, the foundation upon which many vulnerability programs are built, correctly scores the FortiGate vulnerability as severe. What it doesn’t do is analyze if an attacker can move beyond the firewall after exploitation. That’s the really dangerous part — how the attack could progress in an enterprise’s environment. Without that critical information, a FortiGate appliance protected by strong identity controls and comprehensive endpoint visibility receives the same severity rating as an identical appliance operating behind significant control gaps. This means that SecOps analysts face large remediation queues without a reliable way to determine which exposures represent actual business risk.
The Anatomy of Toxic Combinations
Adversaries do not look for isolated infiltration points; they curate chains of multiple weaknesses that intersect across enterprises’ security domains. These junctures represent toxic combinations. In the context of an edge compromise like FortiBleed, a toxic combination merges disparate control failures into a single operational pathway.
Consider how an attack might progress when systemic vulnerabilities overlap:
- Edge exposure: an unpatched process-memory flaw on a public gateway
- Network permissiveness: a loose outbound firewall rule that permits unrestricted traffic
- Control blindspots: an absent EDR sensor on a critical internal segment
- Identity sprawl: an overprivileged service account that lacks multi-factor authentication
Individually, a single misconfiguration might only cause a minor operational headache. Together, they form an express lane for lateral movement.
For security teams, the challenge is not simply identifying exposed systems but preemptively understanding what an attacker can do after initial access occurs. In the case of FortiBleed, that means the team must determine if harvested credentials offer access to critical assets, if configuration drift has exposed administrative interfaces, and whether identity, endpoint, and network controls could contain the intrusion or allow it to expand.

Mapping those attack paths before an adversary attempts exploitation provides a far more accurate picture of risk than vulnerability severity alone. Control effectiveness and continuous validation are the ultimate determining factors of whether an exposed asset becomes an incident. They’re also the basis of effective Exposure Ops.
How Exposure Ops Eradicates Boundary Risks
Exposure operations shifts security from a reactive compliance function to a proactive asset validation process. Rather than relying on a manually aggregated spreadsheet of disconnected alerts gathered from various vulnerability scanners, an exposure ops framework autonomously maps how vulnerabilities, identities, and defensive configurations interact. To neutralize campaigns like FortiBleed, an effective strategy replaces static scans with a continuous operational rhythm.
This approach restructures defense across several execution phases, using AI to eliminate exposures:

- Attack surface discovery: automation continuously inspects the external perimeter to identify exposed management ports
- Control posture analysis: systems evaluate the configuration integrity of edge devices to flag legacy password hash formats
- Reachability validation: platforms simulate lateral movement vectors to determine if a compromised credential can access Active Directory infrastructure
- Prescriptive remediation: engineers receive direct, control-specific steps to harden systems and isolate compromised segments rather than generic patch instructions
Through this continuous cycle, defenders gain clarity into which edge exposures present a path to the corporate core. If an attacker acquires a valid administrative credential, software patch status becomes completely irrelevant. The only defense that matters is the immediate restriction of control reachability.
Systemic Defense. Autonomous Control Validation
The vulnerability at the heart of FortiBleed serves as a reminder the boundary is no longer a definitive control zone (nor is any single layer). When an unauthenticated attacker can extract active session tokens and passwords directly from firewall memory, the device itself becomes the initial point of exposure. But it’s not the end of the exploit. Defenders must consider not just how to prevent the memory leak, but how to stop downstream lateral movement and subsequent damage.
Autonomous control validation across the security stack is the answer. Rather than rely on manual audits or isolated tests, exposure operations continuously and automatically checks the defenses that surround the vulnerable gateway. It verifies that a stolen FortiBleed session token can bypass conditional access policies on a managed device, and validates when an attempt to use harvested credentials triggers endpoint alerts or is blocked by network segmentation.
This systemic check across identity, network, and endpoint layers exposes the true reachability of an attack before an incident occurs.
Given the threat landscape, boundary compromises like FortiBleed are inevitable. However, a compromised firewall doesn’t have to result in a game-stopping network intrusion. When enterprises prioritize autonomous, full-stack control validation over the endless race to patch every edge device, they strip stolen credentials of their utility.
The organizations that fare most effectively in the face of future FortiBleed-style incidents will not necessarily be the ones that patch fastest. Instead, they will be the ones that understand which exposures remain reachable, which controls compensate for risk, and where defensive cracks create opportunities for adversaries.
See Nagomi in action at nagomisecurity.com


