Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Vulnerability management at machine speed: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 12518
Topic starter  

TL;DR: Annual CVE volume has reached record levels, with NIST noting a 263% increase in submissions between 2020 and 2025 as exploit windows shrink and AI accelerates both discovery and abuse, according to Commvault and NIST. The operating model has to shift from slow triage to routine patching, faster validation, and recovery that actually closes the underlying exposure.

NHIMG editorial — based on content published by Commvault: vulnerability management, patching speed, and recovery in the AI era

Questions worth separating out

Q: What breaks when vulnerability management still relies on slow triage?

A: Slow triage breaks the assumption that teams have time to enrich, prioritise, and schedule remediation before exploitation starts.

Q: When should organisations prioritise patch speed over perfect risk ranking?

A: Prioritise patch speed whenever the vulnerability is actively exploited, exposed to the internet, or tied to a high-value access path such as authentication, secrets handling, or remote code execution.

Q: How do you know if recovery is actually reducing cyber risk?

A: Recovery is working only if restored systems return without the original weakness, with validation proving the flaw is closed and the exposure path is gone.

Practitioner guidance

  • Implement a fixed patch cadence Run vulnerability remediation on a weekly schedule for standard issues, with a separate emergency path for actively exploited CVEs so routine work does not crowd out urgent exposure.
  • Tie recovery to verified closure Require post-restoration checks that confirm the original vulnerability has been removed, the configuration is corrected, and the affected asset is not reintroduced with the same exposure.
  • Measure exposure window as a control Track time from disclosure to patch, from detection to validation, and from validation to safe return to service so leaders can see whether the programme is keeping pace with threat velocity.

What's in the full article

Commvault's full article covers the operational detail this post intentionally leaves for the source:

  • Practical guidance on how the vendor frames weekly patching and exception handling for actively exploited CVEs
  • Detailed examples of how AI is being used to accelerate both vulnerability discovery and remediation workflows
  • The vendor's recommendations for what customers should demand from disclosure notices and remediation guidance
  • The article's recovery discussion, including why restoration alone does not close an exposure

👉 Read Commvault's analysis of vulnerability speed, patching, and recovery →

Vulnerability management at machine speed: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12102
 

Exposure window management is becoming the primary vulnerability control. The article reflects a broader shift in which the critical question is no longer whether a vulnerability exists, but how long it remains exploitable before remediation lands. That is a governance problem, not just an operations problem, because exposure windows are now shorter than many change-management cycles. Practitioners should measure time-to-remediate as a security control, not a cleanup metric.

A question worth separating out:

Q: Who is accountable when compromised access infrastructure keeps working after patching?

A: Accountability sits across platform owners, IAM teams, and security operations because patching alone does not remove persistence or confirm that access state has been cleaned up. Frameworks that matter here include least-privilege and configuration management controls, plus the operational responsibility to verify that no unauthorized access path survives remediation.

👉 Read our full editorial: Vulnerability management is shifting from triage to speed and recovery



   
ReplyQuote
Share: