82% of security leaders fear AI will amplify challenges around toxic combinations 

New research from Panaseer, a leader in security posture management powered by Continuous Controls Monitoring (CCM), shows 82% of security leaders fear AI will amplify challenges around toxic combinations of control failures. Moreover, 92% believe growing IT complexity is increasing the threat of toxic combinations, putting high-value assets at greater risk. 

Toxic combinations of control failures refer to the interconnected risks spanning multiple inventories and asset relationships, that compound to create a pathway for attackers to compromise a business. Now attackers have AI at their disposal, security leaders are increasingly concerned that attackers will exploit these combinations as Marc Möesse, Chief Product Officer from Panaseer explains:  

Panaseer warns that because toxic combinations span multiple security domains, they don’t always take the same form and are very hard to detect and prioritize. Security teams often lack the time and tools needed to see how different combinations of risk overlap within their environments, and are therefore ill-equipped to address areas of vulnerability or prioritize remediation effectively.  

To tackle this challenge and help shine a light on toxic combinations, Panaseer has launched a new Compound Risk Metrics (CRMs) feature. These CRMs deliver actionable insights into the specific assets and relationships driving toxic combinations. This helps eliminate manual effort while ensuring consistent, reliable access to validated and verified data from across the business – far more than just a number or single line of data. Designed to address toxic combinations of risks across security domains, CRMs enable organizations to create complex, threat-driven risk profiles by identifying previously hidden or unknown vulnerabilities, prioritizing response and mitigating risk.

This is a unique solution available today that integrates data from multiple sources, including vulnerability, endpoint, Configuration Management Database (CMDB), user awareness, and Privileged Access Management (PAM) tooling, to spotlight hidden attack paths and devices at risk. Panaseer’s CRMs are uniquely automated and ready to deploy within hours, making it easy for users to start creating dashboards and getting insights from their data. 

You can read more in Panaseer’s new blog: https://panaseer.com/resources/blog/why-toxic-combinations-are-a-cause-for-real-concern-in-2025 

To download the ‘ControlWatch and the Continuous Controls Battle: Panaseer 2025 Security Leaders Peer Report’, please visit the Panaseer website: https://panaseer.com/resources/reports/2025-security-leaders-peer-report 

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading