How many vulnerabilities you have and how many attacks target you isn’t the whole story. A new TrendAI research study shows that the real damage from cyber incidents is determined by something else – a combination of two factors that have rarely been studied together until now.
What TrendAI found
TrendAI Research analyzed telemetry from 2,014 enterprises worldwide that continuously used the Trend Vision One Cyber Risk Exposure Management (CREM) and XDR platforms throughout 2025. The goal was to understand why organizations with similar Cyber Risk Index (CRI) scores often experience very different outcomes – some weather an incident with minimal fallout, while others suffer significant damage.
The answer: damage isn’t determined by the number of vulnerabilities or the volume of attacks alone. It comes down to the combination of two variables:
- Attack Pressure – the intensity and frequency of attacks an organization actually faces
Exposure – the scope and nature of the vulnerable points an organization leaves open
It’s the interaction between these two factors – not their sum, and not either one alone – that best explains why two companies with the same CRI can end up with completely different levels of damage.
The Cyber Risk Positioning Map
The study also introduces a new visualization tool – the Cyber Risk Positioning Map. Rather than tracking a single overall risk score, the map shows how Attack Pressure, Exposure, and the degree of damage containment interact across different types of organizations. This makes it possible to place your own organization in context more precisely and identify which of the two factors is the real driver of risk in your case.
Building on earlier research
The study builds on two earlier TrendAI Research publications:
- From Vulnerable to Resilient (December 2024) – showed that continuously reducing exposure through Cyber Risk Exposure Management has a direct impact on lowering ransomware risk.
- Proactive Security (July 2025) – using data from 190 enterprises, demonstrated that high exposure significantly increases the likelihood of damage, and that the best outcomes come from combining exposure management with detection and response (MDR/XDR).
The new analysis takes these findings further – showing that understanding risk accurately requires tracking not just one variable, but how the two interact.
What this means for your organization
For security leaders and CISOs, the takeaway is clear: a risk score alone isn’t enough to understand where you actually stand. It’s worth tracking both factors separately – how much you’re under attack, and how exposed you are at the same time – and investing accordingly, whether that means reducing exposure, strengthening detection and response capability, or both.