TL;DR: AI has shortened the gap between vulnerability disclosure and weaponization, while many teams still run scan, score, ticket, chase workflows that assume defenders have time, according to Tonic. The real control problem is not finding more issues, but contextualizing business impact, ownership, and exploitability quickly enough to reduce exposure before attackers do.
NHIMG editorial — based on content published by Tonic: LLMjacking: How Attackers Hijack AI Using Compromised NHIs
Questions worth separating out
Q: How should security teams prioritise patches when CVSS no longer drives the schedule?
A: Start with exploitability, exposure, and business impact.
Q: Why does backlog become an attack path in modern vulnerability management?
A: Backlog becomes an attack path when discovery is faster than remediation and the queue becomes the place where risk waits.
Q: What signals show that exposure management is working?
A: Look for shorter time to ownership, shorter time to prioritisation, fewer findings waiting in unresolved queues, and faster verified closure after remediation starts.
Practitioner guidance
- Implement contextual prioritisation rules Classify vulnerabilities by exploitability, reachability, business criticality, and compensating controls before assigning remediation priority.
- Connect findings to accountable owners Map each exposure to a clear service owner, system owner, or control owner at intake.
- Automate remediation verification Require a post-fix validation step that confirms the exposure is actually reduced, not just marked closed.
What's in the full article
Tonic's full article covers the operational detail this post intentionally leaves for the source:
- Framework-level discussion of collect, contextualize, prioritize, act workflows for exposure management.
- The article's reasoning on why ticket creation is not the same as risk reduction.
- Operational examples of how security teams can measure exposure reduction velocity in practice.
- The source's view of how identity platforms, CMDBs, and ITSM systems feed remediation decisions.
👉 Read Tonic's analysis of exposure reduction velocity and modern vulnerability management →
Exposure reduction velocity: what vulnerability teams need to change?
Explore further
Legacy vulnerability management is now an execution risk, not just a visibility gap. The article is right to frame backlog as part of the attack path. When exploit development moves at machine speed, a programme that can only discover and ticket weaknesses is structurally outpaced. That is not a scanner problem. It is a governance failure in how organisations translate findings into action. Practitioners should treat remediation latency as a control weakness, not an operational inconvenience.
A question worth separating out:
Q: Who is accountable when a contained vulnerability still leads to operational disruption?
A: Accountability usually sits across infrastructure, identity, and security governance, because disruption occurs when access paths, privilege, and segmentation are not managed as one control system. NIST CSF and NIST SP 800-53 both reinforce that containment, access control, and monitoring are shared responsibilities, not separate technical chores.
👉 Read our full editorial: Exposure reduction velocity is replacing legacy vulnerability management