Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Vulnerability exploitation is outpacing remediation. What now?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 13011
Topic starter  

TL;DR: The 2026 Verizon DBIR says vulnerability exploitation has become the most common known initial access vector, rising to 31%, while only 26% of detected KEVs were fully remediated and median resolution stretched to 43 days, according to Verizon. The operational problem is no longer discovery but verified closure at the pace attackers are exploiting exposures.

NHIMG editorial — based on content published by Cogent: The 2026 Verizon DBIR Shows Vulnerability Management Has Become a Remediation Problem

By the numbers:

Questions worth separating out

Q: What breaks when vulnerability management stops at scanning and ticketing?

A: Teams create a false sense of progress.

Q: Why do critical vulnerabilities remain open for so long in modern appsec programmes?

A: They stay open because remediation is harder than detection in modular environments.

Q: How do security teams know whether Teams remediation is working?

A: They should measure dwell time, removal latency, and the percentage of malicious messages removed before any user interaction.

Practitioner guidance

  • Build a verified-remediation workflow Require every critical vulnerability to move through assignment, safe-fix approval, closure validation, and post-fix verification before it can be marked resolved.
  • Prioritise by exploitability and reachability Score vulnerabilities using active exploit signals, internet exposure, business criticality, and whether compensating controls already exist.
  • Tie remediation to named operational owners Assign each high-risk weakness to a team that can both change the asset and verify the result.

What's in the full article

Cogent's full article covers the operational detail this post intentionally leaves for the source:

  • The article's AI-agent remediation workflow, including how the system confirms reachability before recommending a fix.
  • The step-by-step process for assigning the right owner and routing remediation through existing security and IT systems.
  • The verification stage that checks whether an exposure is actually closed after the fix is applied.
  • Cogent's framing of how its AI agents reduce open, exploitable paths rather than adding more findings.

👉 Read Cogent's analysis of why vulnerability management is becoming a remediation problem →

Vulnerability exploitation is outpacing remediation. What now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12595
 

Exposure debt is now a governance problem, not a scanning problem. The DBIR's numbers show that discovering weaknesses faster does not help if verified closure slows down. When remediation lags behind exploitation, organisations accumulate exposure debt: a backlog of known weaknesses that are already operationally usable by attackers. The control issue is not simply detection, but whether the right owner can close the right exposure before it is reused. Practitioners should treat remediation throughput as a board-level governance metric.

A question worth separating out:

Q: Who is accountable when critical vulnerability deadlines are missed?

A: Accountability usually spans security operations, infrastructure owners, and risk leadership because missed deadlines are often caused by governance gaps rather than one failed team. Frameworks such as the NIST Cybersecurity Framework and NIST SP 800-53 expect defined responsibility for asset management, response, and access control, so remediation ownership must be explicit.

👉 Read our full editorial: Vulnerability management is becoming a remediation problem



   
ReplyQuote
Share: