Better Together: Brinqa + PlexTrac and the Next Era of Exposure Management
by Brad Hibbert, COO & CSO//17 min read/

The security industry has spent two decades getting very good at finding problems. Scanners find vulnerabilities. Pen testers find exploitable paths. Cloud tools find misconfigurations. What the industry has been far less good at is turning that mountain of findings into confident decisions, and then turning those decisions into fixes that someone has actually verified.
That gap is why the market is consolidating around exposure management, and it is why Brinqa acquired PlexTrac. This post lays out how we see the market evolving, why the two companies fit so naturally, and what the combined platform will look like for both of our customer communities.
The market is evolving: from data, to decisions, to action
Exposure management did not arrive all at once. The discipline has developed in three stages over the past several years, with each stage building on the one before it. Walking through them helps explain where the industry is headed next and why Brinqa and PlexTrac belong together.
The first stage was about data. Every security program runs dozens of detection tools: vulnerability scanners, cloud security posture tools, application testing, pen tests, and more. Each one produces findings in its own format, on its own schedule, with its own idea of what counts as severe. The first real job of exposure management was simply to pull all of that into one trusted place, normalized, deduplicated, and tied back to the assets and the people who own them. This stage was data orchestration. It was necessary work, but on its own it is not enough. A unified pile of findings is still a pile.
The second stage, and the one most of the market lives in today, is about decisions. Once the data is in one place, the platform can start to form an opinion: which exposures actually matter, in what order, and why. Business context, threat intelligence, exploitability, and validation evidence all come together to answer the question every CISO is really asking: what do we fix first? This is decision orchestration, and it is where both Brinqa and PlexTrac built their reputations.
The third stage is about action. Decisions flow into remediation workflows, tickets, and owners automatically. Fixes get made. Then validation confirms that each fix actually worked, so the loop finally closes. That is action orchestration, and just beyond it, the earliest form of the next era is already visible: autonomous remediation, where AI agents prioritize, validate, and remediate exposures with progressively less human involvement. It is early, but the direction is clear.
This is not just our read on the market. The Gartner® inaugural Magic Quadrant™ for Exposure Assessment Platforms was published two quarters ago. We believe they created this new Magic Quadrant to signal that a new durable category has arrived. Gartner’s research on this topic reflects the importance of exposure assessment as well. Recent research has noted that organizations that prioritize their security investments through a continuous threat exposure management (CTEM) program are three times less likely to suffer a breach. Gartner also projects that by 2027, organizations that integrate exposure assessment data into IT and business workflows will see thirty percent less unplanned downtime from exploited vulnerabilities than those relying on isolated vulnerability management tools. At the 2026 Gartner Security & Risk Summit, analysts went a step further and described exposure assessment and validation converging into a single unified platform category.

The evolution of exposure management, and where Brinqa and PlexTrac each sit above their tool ecosystems.
Two companies, similar approaches
Brinqa and PlexTrac took similar approaches to the same problem. Both recognized that everything starts with the data, and both recognized that data alone does not help an organization act. The tools generate findings. What organizations need is consistency across those findings and insight on top of them before anyone can decide what to do. So rather than compete with the tools, both companies chose to sit above them and supply what the tools cannot.
Brinqa sits above the scanners. With 260+ connectors feeding the CyberRisk Graph™, Brinqa takes the output of the entire detection stack, from vulnerability scanners to cloud and application security tools to asset and identity sources, and turns a noisy, inconsistent stream of findings into one coherent picture. On top of that consistency, it layers insight: a proven risk-scoring engine that turns raw findings into prioritized, business-contextualized decisions at enterprise scale.
PlexTrac does the same job for the offensive side of the house. It is the system of record for the entire engagement lifecycle, from scoping and testing through reporting, delivery, remediation, and retest, sitting above the pen testing tools, red team tooling, and adversary emulation platforms that practitioners use every day. And like Brinqa, PlexTrac does far more than aggregate. Validated, exploited, human-confirmed findings carry a level of signal that no scanner output can match, and retest evidence proves whether a fix actually held.
That insight comes from several places. Some of it comes from automation: normalizing, deduplicating, and routing findings the same way every time so teams are not reinventing triage with every report. Some of it comes from computation: risk scoring, attack path analysis, and prioritization models running across the whole graph of assets and exposures. Increasingly, some of it comes from purpose-built AI, agents designed for specific exposure management jobs rather than general-purpose chat. And in the cases where it matters most, insight comes from human judgment: a tester who has actually exploited the exposure and can say with confidence that this one is real, this path works, and this fix holds. The platforms that win will be the ones that blend all four, using automation where automation is enough and saving human expertise for the exposures that deserve it.
Brinqa tells you what matters across everything you have detected. PlexTrac proves what is genuinely exploitable and confirms what is genuinely fixed. Together they answer the two questions that define a mature program: what do we fix first, and does it work?
AI is accelerating findings, which makes judgment and verification the bottleneck
One more development is making all of this more urgent. AI is dramatically accelerating the rate at which exposures are discovered. AI-assisted scanning, autonomous pen testing, and agentic discovery tools are surfacing findings faster and in greater volume than any human-scaled triage process can absorb. Attackers are riding the same acceleration, and the window between disclosure and exploitation keeps shrinking. Researchers have already shown AI systems going from a newly published CVE to a working exploit in minutes, and it is safe to assume adversaries are not far behind. The result is a widening gap between how fast exposures are found and how fast organizations can decide and act.
You cannot out-scale that gap with more analysts or bigger spreadsheets. It forces two structural changes to how programs prioritize and remediate.
The first change is that prioritization has to be elevated to exploitability, and ideally to validated exploitability. When finding volume explodes, severity scores alone collapse as a triage mechanism. Everything is critical, so nothing is. The signal that cuts through is exploitability: is this exposure actually reachable and usable by an attacker in this environment? The strongest form of that signal is validated exploitability, meaning an exposure that a tester or a validation agent has actually exploited, with evidence. A validated finding is not a probability. It is a demonstrated attack path. Programs that put validated exploitability at the top of the queue fix what attackers would actually use instead of drowning in what scanners merely flag. This is precisely where the combination shines, with Brinqa's prioritization engine consuming PlexTrac's exploited, evidence-backed findings as a first-class signal in the risk model.
The second change is that remediation itself is changing shape, which makes fix verification essential. As the exposure backlog outpaces patch cycles, leading organizations are moving to a more targeted, two-step approach to remediation. The first step is to disrupt the attack path right away, using shielding or mitigating controls such as a WAF rule, a firewall change, network segmentation, disabling a service, or tightening an identity permission, so the exploitable path is broken without waiting on a maintenance window. The second step is to patch when you can, applying the durable fix on the normal change cycle once testing, dependencies, and downtime allow.
Two-step remediation is faster and far less disruptive than emergency-patching everything, but it only works if you can prove each step worked. Did the mitigating control actually break the attack path, or just appear to? Is the exposure still shielded three weeks later, after configurations have drifted? And once the patch lands, does it truly close the exposure so the compensating control can be retired? Every one of those is a fix verification question. Retest and validation stop being a nice-to-have audit step and become the control plane of remediation itself. That is exactly the muscle PlexTrac brings, from human-led retest evidence today to validation agents going forward, feeding verified status back into Brinqa's risk graph so the priority queue always reflects what is actually still exploitable.
AI is accelerating the front of the funnel. The winners will be the platforms that accelerate the back of it: validated prioritization in, verified fixes out.
The combined platform: three layers, built to be shared
So what are we building? The combined entity is organized around three layers that both customer communities share.
At the base sits the data foundation, the CyberRisk Graph, with 260+ connectors unifying every scanner, every pen test, and every security tool into a single trusted source of exposure truth. PlexTrac's validated findings and retest evidence flow into the same foundation, giving the graph human-confirmed proof of exploitability and proof of fix, something it never had before.
On top of the data foundation sits the AI layer: purpose built models for every stage of the lifecycle, covering data completeness, deduplication, prioritization, validation, and remediation. These models are the building blocks of the action orchestration era described above, and eventually of autonomous remediation. Just as important, the AI layer is open rather than a walled garden. Through MCP support and a Bring Your Own AI approach, customers can feed validated exposure data into the AI tools they already run.
At the top sits the insights and action layer, where orchestration happens: risk-based prioritization, validation, reporting, and remediation workflows where data becomes decisions and decisions become verified action. Brinqa's prioritization engine and PlexTrac's validation and reporting engine work from the same data and close the same loop. Tying it together is SmartFlows, a no-code automation and workflow canvas that empowers users and AI alike to build powerful automation, with the access, audit, and governance controls organizations demand.

One platform in three layers, serving both customer communities with modular flexibility.
Built for both customer communities, with flexibility and choice
A better together story only works if both sets of customers actually come out ahead. Here is what each community gets.
For Brinqa's enterprise exposure management customers, PlexTrac adds the proof they have been asking for. Prioritization gets sharper when validated, exploited findings are weighted in the model, and remediation reporting becomes far more credible when it includes evidence that a fix actually worked rather than evidence that a ticket was closed. The offensive security data that used to live in a separate silo now enriches the risk picture the board sees.
For PlexTrac's offensive security teams and service providers that rely on Plextrac today, nothing changes. The pentest workflow automation, the reporting engine, and the engagement lifecycle all continue exactly as they are, with more investment behind the roadmap. With deeper integrations into the Brinqa EAP platform, findings and tester insights go straight into a system that prioritizes them by business impact and tracks them through to a fix. For the 150+ service providers who deliver through PlexTrac, that is a deeper, stickier offering for every one of their end clients.
The platform is also modular by design. One EAP platform serves every market segment, with modules that customers, partners, and teams can mix and match to fit their needs: PlexTrac for validation and reporting, AI agents for every stage, and a shared data foundation. Adopt the full platform, or adopt the pieces that solve today's problem and grow from there. Flexibility and choice, not forced migration.
Where this leaves us
The exposure management market is moving from orchestrating data, to orchestrating decisions, to orchestrating action, with autonomous remediation on the horizon. AI is accelerating the discovery of exposures faster than any team can triage by hand, which puts a premium on exactly two things: prioritization elevated by validated exploitability on the way in, and fix verification on the way out, especially as organizations adopt two-step remediation, disrupting the attack path with mitigating controls first and patching when they can. Winning that market requires a broad, trusted data foundation, real insight layered on top of it, and a closed loop that proves every fix, mitigation and patch alike, actually worked.
Brinqa built the first two above the detection stack. PlexTrac built them above the offensive stack. Together, with a shared data foundation, an open AI layer, and a unified insights and action layer, we cover the full lifecycle and give every customer, from a single pen testing team to a Global 2000 exposure program, the flexibility to adopt it their way.
It starts with data. We add insight. And now, together, we prove the fix.
Talk to a Brinqa Expert about what the PlexTrac acquisition means for your team.
FAQs
No. For PlexTrac's existing offensive security teams and service providers, the pentest workflow automation, reporting engine, and engagement lifecycle continue exactly as they are with more investment behind the roadmap.
First, disrupt the attack path immediately with a mitigating control (a WAF rule, firewall change, segmentation, or a tightened permission) without waiting on a maintenance window. Second, apply the durable patch on the normal change cycle once testing and dependencies allow. It only works if you can verify each step actually held, which is where retest and validation become the control plane rather than an afterthought.
The platform is modular by design: PlexTrac for validation and reporting, AI agents for specific stages, a shared data foundation. Adopt the whole thing, or adopt the pieces that solve today's problem and grow from there.
CTEM programs already prioritize based on business context and threat intelligence; that's decision orchestration. But the loop has stayed open on the last step: decisions flow into remediation with no reliable confirmation that a fix actually held. PlexTrac closes that gap. Validated, evidence-backed findings feed Brinqa's risk model as a first-class signal, and retest evidence confirms whether each fix or mitigating control actually worked, so validation becomes a standing part of the CTEM cycle instead of a periodic audit step bolted on afterward.
Sources:
Gartner, Magic Quadrant for Exposure Assessment Platforms, Mitchell Schneider, Dhivya Poole, Jonathan Nunez, 10 November 2025.
Gartner CTEM research and 2026 Gartner Security & Risk Summit.
Black Hat USA 2026 briefings and industry coverage.
Gartner does not endorse any vendor, product or service depicted in its research publications. GARTNER and MAGIC QUADRANT are registered trademarks of Gartner, Inc. and/or its affiliates and are used herein with permission.
- The market is evolving: from data, to decisions, to action
- Two companies, similar approaches
- AI is accelerating findings, which makes judgment and verification the bottleneck
- The combined platform: three layers, built to be shared
- Built for both customer communities, with flexibility and choice
- Where this leaves us
- FAQs


