TL;DR: AI-assisted attackers are compressing discovery, exploitation, and weaponisation faster than most remediation cycles can absorb, while Verizon’s 2025 DBIR puts median remediation for edge device vulnerabilities at 32 days and Mandiant’s M-Trends 2026 estimates mean time to exploit at negative seven days. The control problem is no longer prioritisation alone, but whether findings are continuously validated, deduplicated, owned, and revalidated before closure.
NHIMG editorial — based on content published by Pentera: Exposure management used to look a lot like baggage claim
By the numbers:
- Verizon’s 2025 DBIR puts median time to remediate edge device vulnerabilities at 32 days.
Questions worth separating out
Q: How should security teams contain a breach when attackers can move faster than patch cycles?
A: Security teams should assume the first compromise will happen before every weakness is fixed and design limits around that assumption.
Q: Why do false clearances create so much risk in remediation programmes?
A: Because they create confidence without proof.
Q: What do security teams get wrong about deduplicating exposure findings?
A: They often treat duplicate findings as separate work items instead of symptoms of one root cause.
Practitioner guidance
- Collapse duplicate findings into one exposure record Deduplicate issues that map to the same underlying flaw, assign one owner, and track one path to resolution so the real exposure does not remain hidden behind multiple tickets.
- Require proof of elimination before closure Do not close remediation work after a patch or workaround alone; revalidate the original exposure and confirm that no alternate path remains exploitable.
- Tie remediation ownership to engineering workflows Move findings directly into the systems teams already use, such as ServiceNow or Jira, so accountability is assigned at handoff rather than rediscovered later.
What's in the full article
Pentera's full article covers the operational detail this post intentionally leaves for the source:
- How Pentera Resolve deduplicates multiple findings into one underlying exposure record.
- How the workflow integrates with systems such as ServiceNow, Jira, and Slack for ownership assignment.
- How revalidation is triggered after remediation to confirm the exposure is actually closed.
- How SLA tracking and escalation paths are used to measure remediation progress and proof of closure.
👉 Read Pentera's analysis of AI-assisted exposure management and continuous validation →
Exposure management in attacker time: are your controls keeping up?
Explore further
Continuous validation is now the control boundary, not prioritisation. Ranking exposures still has value, but it no longer answers the central question: is the path closed in time? AI-assisted attacker behaviour compresses the window between discovery and exploitation, which means remediation programmes must verify live risk continuously rather than assume a ticketed fix is effective. For IAM and NHI teams, this is the same shift from owning credentials to proving they are no longer exploitable. The practitioner conclusion is straightforward: if the closure cannot be revalidated, it is not closure.
A question worth separating out:
Q: What should teams measure instead of counting closed tickets?
A: They should measure eliminated exposures, revalidation success, and the time between discovery and verified closure. Closed-ticket counts can rise even when risk remains if fixes are partial or bypassable. Outcome-based metrics reveal whether the remediation process is actually reducing attack paths, not just moving work through a queue.
👉 Read our full editorial: AI-assisted exposure management needs continuous validation, not sorting