Most security programs measure attack surface and track vulnerabilities, but few measure exposure time: how long an asset is actually reachable. Yet exposure time is a real variable in risk, and unlike the others it is often the easiest to reduce.
This article offers a practical method to measure exposure time across an estate, identify assets that do not need round-the-clock connectivity, and turn the result into a concrete reduction plan.
01Key takeaways
- 01
Exposure time is the duration an asset is reachable and therefore available to be attacked; it is measurable and reducible.
- 02
A simple model frames the problem: Risk = Attack Surface x Vulnerability x Exposure Time.
- 03
Many assets are always-on by default, not by requirement; the gap between the two is the opportunity.
- 04
Measuring online hours per asset turns a vague sense of overexposure into a number you can act on.
- 05
Reducing the Time variable complements, rather than replaces, patching, segmentation and monitoring.
02The risk model: where time fits
A useful way to frame exposure is a simple product: Risk = Attack Surface x Vulnerability x Exposure Time. Security programs invest heavily in shrinking attack surface and remediating vulnerabilities, but the time term is frequently left at its maximum, because most assets are reachable continuously.
Treating time as a variable changes the conversation. If an asset only needs to be reachable for a few hours a week, then leaving it online the rest of the time is pure, unmanaged exposure that no patch can remove.
You cannot patch a system out of being reachable. If it does not need to be online, the strongest control is to reduce the time it is.
03Why always-on is the default
Continuous connectivity is rarely a deliberate decision. It is the path of least resistance: systems are installed connected, monitoring assumes they are reachable, and nobody owns the question of when they actually need to be online.
The result is a large set of assets that are reachable 168 hours a week but used for a fraction of that. Backup repositories, management interfaces, maintenance endpoints and certain OT devices are common examples.
04Step 1: build an asset connectivity inventory
You cannot measure exposure time without first knowing which assets exist and what each one is for. Start from existing inventories and enrich them with a single new question: when does this asset genuinely need to be reachable?
- List assets with their function, owner and the systems they communicate with.
- For each asset, record its current connectivity: always-on, scheduled, or on-demand.
- Capture the business reason for connectivity, not just the technical fact of it.
- Flag assets whose only inbound need is occasional: backups, updates, maintenance, periodic transfers.
- Note dependencies so a disconnection plan does not break a legitimate workflow.
05Step 2: calculate online hours per asset
Turn connectivity into a number. For each asset, estimate required online hours per week versus actual online hours, which for always-on systems is 168.
- Required online hours
- The hours per week the asset genuinely needs to be reachable for its function, including a margin for operational reality.
- Actual online hours
- The hours per week it is currently reachable. For always-on assets this is 168.
- Exposure gap
- Actual minus required. This is the reducible exposure time, expressed in hours per week, that no other control addresses.
Summing the exposure gap across the estate produces a single, defensible figure: the total reducible exposure time. It is far more persuasive to leadership than a general sense that the network is too reachable.
06Step 3: identify assets that do not need 24/7 reachability
Rank assets by exposure gap and consequence. The best candidates for reduction have a large gap and high impact if compromised.
- Backup repositories that only receive data during defined backup windows.
- Out-of-band management interfaces used occasionally for maintenance.
- Engineering or update endpoints touched on a schedule, not continuously.
- OT devices that report or receive data periodically rather than in real time.
- Vendor or support paths that should exist only during approved sessions.
07Step 4: reduce the time variable
Once you know the gap, reduction is an engineering choice. Options range from process-based disconnection to hardware-enforced, scheduled or on-demand connectivity.
For assets with a large exposure gap, a hardware-enforced approach such as an AIRGAPNET controlled connectivity model can keep the asset physically disconnected by default and reconnect it only for approved windows, turning the measured gap into an actual reduction.
Reducing exposure time does not replace patching, segmentation or monitoring. It removes the hours during which those controls have to hold against an attacker who cannot reach the asset at all.
08Closing thought
Exposure time is the risk variable hiding in plain sight. It is measurable, it is usually far larger than it needs to be, and it responds directly to a control that has nothing to do with perfect configuration or perfect detection.
Measure it once and the conversation changes. Instead of arguing about whether the network is too exposed, you can point to a number and a plan to bring it down.
FAQFrequently asked questions
What is network exposure time?
Network exposure time is the duration an asset is reachable and therefore available to be attacked. It is a measurable risk variable, distinct from attack surface and vulnerability, and it is often the easiest of the three to reduce.
How do you measure exposure time?
Inventory assets and their connectivity, then for each asset compare required online hours per week against actual online hours. The difference is the exposure gap, and summing it across the estate gives total reducible exposure time.
Why does exposure time matter if systems are patched?
Patching reduces vulnerability but does not change how long a system is reachable. If an asset does not need to be online continuously, the hours it remains reachable are exposure that no patch removes.
Which assets usually have the most reducible exposure time?
Backup repositories, out-of-band management interfaces, maintenance and update endpoints, and OT devices that only report periodically tend to be reachable far longer than they are used.
Does reducing exposure time replace other security controls?
No. It complements patching, segmentation and monitoring by removing the hours during which those controls must hold. An attacker cannot exploit an asset that is not reachable in the first place.
SRCSources of record
Measure it, then bring it down
Turn exposure time from a feeling into a number.
Once you know the exposure gap for your highest-consequence assets, hardware-enforced scheduled disconnection can turn that measured gap into a real reduction.