Description
TrendAI Vision One Cyber Risk Exposure Management (CREM) - Essentials
CREM finds what you own, works out which parts an attacker can reach, and scores the risk so you fix the right things first. It covers identities, devices, applications, cloud assets, network devices, APIs and internet-facing assets. This is the mid tier.
The problem it solves: most businesses cannot list their own internet-facing assets accurately. You cannot secure what you do not know exists, and a vulnerability scanner only looks at what you point it at.
What it consolidates
TrendAI positions CREM as replacing several point tools rather than adding another one.
| Discipline | What it covers |
|---|---|
| External attack surface management (EASM) | Internet-facing assets an attacker can see |
| Cyber asset attack surface management (CAASM) | Everything you own, including assets nobody registered |
| Cloud security posture management (CSPM) | Cloud misconfiguration against best practice and frameworks |
| Vulnerability risk management (VRM) | Which vulnerabilities actually matter in your environment |
| Compliance reporting | Audit-ready reports for standards including NIST, FedRAMP and GDPR |
| Risk quantification | A risk score you can put in front of a board |
How it scores risk
Scoring uses more than ten risk factors rather than raw CVE severity, drawing on TrendAI Cybertron and the TrendAI Zero Day Initiative. The output is an organisational risk score plus a prioritised list of what to fix, with AI-guided remediation playbooks.
Why the score matters more than the list
Any tool can produce a list of vulnerabilities. The hard part is knowing which ones matter in your environment. A critical CVE on an isolated test machine matters less than a medium one on an internet-facing server holding customer data. Context-driven scoring is what makes the list actionable rather than overwhelming.
Frequently asked questions
What is Cyber Risk Exposure Management?
CREM gives continuous visibility of identities, devices, applications, cloud assets, network devices, APIs and internet-facing assets, then scores and prioritises the risk. It consolidates external attack surface management, cyber asset attack surface management, cloud posture, vulnerability management and compliance into one product.
How is this different from a vulnerability scanner?
A scanner lists vulnerabilities by severity. CREM scores them in context, using more than ten risk factors including how exposed the asset is and what it is worth to the business. A medium-severity issue on an internet-facing server can outrank a critical one on an isolated machine.
What is the Zero Day Initiative advantage?
TrendAI runs the Zero Day Initiative, a vulnerability disclosure programme. TrendAI states that customers receive protection for vulnerabilities disclosed exclusively through ZDI 90 to 120 days before public patches are available, citing Omdia.
Does this replace tools I already run?
That is the intent. CREM consolidates EASM, CAASM, CSPM and vulnerability risk management into one product, so several point tools can be retired. Tell us what you run today and we will map it.
How does it fit with XDR and MDR?
CREM is the proactive side: finding and reducing exposure before an attack. XDR and MDR are the reactive side: detecting and responding once something happens. They run on the same Vision One platform and share the same asset picture.
Get this quoted by Nuformat
Nuformat sells and supports both TrendAI and Sophos. Tell us your asset count and which tiers you are considering, and we will price it and say plainly whether CREM replaces anything you already pay for.
Request a quoteTrendAI Vision One range · TrendAI XDR · Cyber risk exposure management
Capabilities as published by TrendAI in the Cyber Risk Exposure Management solution brief and datasheet. Pricing and availability confirmed by Nuformat at the time of quotation.

