TL;DR: Most application security programs fail not at detection but at the resolution gap, where scanners generate large backlogs and remediation never catches up, according to Pixee. The article maps four maturity levels and shows that regulated enterprises usually stall between triage-heavy detection and sovereignty-constrained automation.
NHIMG editorial — based on content published by Pixee: The AppSec Maturity Model: Where Does Your Organization Fit?
By the numbers:
- Automated fix attempts often see less than 20% merge rates, so remediation bottlenecks persist even when code changes are generated.
- Fortune 50 financial institutions reported 76% developer merge rates and MTTR reduction from 252 days to under 30 days with sovereign remediation.
Questions worth separating out
Q: What breaks when AppSec programs focus on findings instead of fixes?
A: Findings-only programs create the illusion of control while exploitable issues remain unresolved.
Q: Why does reachability analysis help, but not solve remediation?
A: Reachability analysis improves prioritisation by filtering out theoretical vulnerabilities that an attacker cannot actually trigger.
Q: How do you know if AppSec automation is actually working?
A: Look for fewer human-review hours spent per confirmed issue, higher merge rates for fixes, and a falling share of findings that end up dismissed after manual inspection.
Practitioner guidance
- Rebase AppSec metrics on closure outcomes Replace scanner-volume KPIs with time-to-fix, merge rate, reopen rate, and backlog age so the programme is measured on risk reduction rather than alert production.
- Adopt reachability as a triage gate Use reachability analysis to separate exploitable issues from theoretical ones before assigning developer work, and record why each item was prioritised.
- Design remediation inside the governance boundary If code, metadata, or analysis context cannot leave the environment, require on-premises or otherwise sovereign remediation workflows before approving AI-assisted fix generation.
What's in the full article
Pixee's full article covers the operational detail this post intentionally leaves for the source:
- How the four AppSec maturity levels are defined and how to assess where your programme sits
- The rationale behind the 80% false-positive figure and why scanner noise still dominates triage
- Examples of sovereign remediation architecture and how it preserves data control while generating fixes
- The assessment model used to identify blockers between detection, context, automation, and closure
👉 Read Pixee's analysis of the AppSec maturity model and remediation gap →
AppSec remediation is stalling. Where does your program get stuck?
Explore further
The resolution gap is now the central AppSec governance problem. Most programmes still reward detection volume, yet risk falls only when issues are fixed, deployed, and verified. That mismatch creates a false sense of progress and a growing backlog of unresolved exposure. For security leaders, the real question is whether the operating model can convert signal into closure.
A question worth separating out:
Q: Should organisations prioritise sovereign remediation over cloud AI fix generation?
A: If code, findings, or metadata cannot leave the environment under policy, sovereign remediation has to come first. Cloud AI fix generation may improve speed, but it is unusable when governance rules, regulatory constraints, or data residency requirements make external analysis unacceptable.
👉 Read our full editorial: The AppSec resolution gap is what stalls remediation at scale