Puntos Clave
- El rápido aumento de las vulnerabilidades y la detección basada en la IA están reduciendo el tiempo que transcurre entre la divulgación de una vulnerabilidad y su explotación activa.
- Los ciclos de aplicación de parches regulares y disciplinados ayudan a reducir la vulnerabilidad general y a prepararse para nuevas vulnerabilidades (CVE).
- La recuperación es clave para la resiliencia, pero tiene que ir acompañada de la aplicación oportuna de parches para solucionar las vulnerabilidades.
- Las organizaciones deberían usar la IA para acelerar la detección y la corrección de vulnerabilidades, en lugar de dejar que los problemas se acumulen en las listas de tareas pendientes.
- Los proveedores que desempeñan un papel fundamental ofrecen a los clientes información rápida y transparente sobre las vulnerabilidades, así como instrucciones claras para solucionarlas.
El año pasado,los informes del sectorsituaban el volumen anual de CVE en decenas de miles, y el NIST señaló posteriormente un crecimiento récord de los CVE y unaumento del 263 % en el número de notificaciones between 2020 and 2025.
I hear what that does to a security team in real time, because I am on the calls when it happens. The old questions – what is our exposure, and how fast can we close it? – used to have room to breathe. Now they arrive faster than most teams can staff for them.
Most organizations have vulnerability response processes. Fewer have processes designed for this speed.
For years, the industry organized its response around individual vulnerabilities. A CVE would publish, severity scores would follow, enrichment would catch up, and teams would triage with some margin for judgment. That rhythm assumed a human pace of discovery, but that assumption no longer holds.
That volume is already outrunning the infrastructure built to track it. NIST has said the National Vulnerability Database is moving to a risk-based enrichment model because CVE submissions have grown faster than the program can fully process them.
AI is likely compounding pressure by helping threat actors exploit vulnerabilities, and defenders identify and validate vulnerabilities faster than legacy cataloging workflows can absorb. The window between when a vulnerability is discovered and when it is exploited is closing, and working exploit code can appear before a patch is widely deployed.
That breaks the old model. Structured vulnerability management still matters, but many programs are calibrated for a slower era: gather signal, rank risk, assign owners, then remediate. When discovery accelerates this sharply, even disciplined teams fall behind because the operating model cannot absorb the volume fast enough.
So, the unit of work must change. It no longer matters whether you patched a specific vulnerability but whether your organization can apply, verify, and recover at the speed the threat environment now demands.
Parche en un reloj
Empieza por la cadencia. Las operaciones más resilientes que conozco han dejado de ver las correcciones como una interrupción y han empezado a tratarlas como mantenimiento rutinario: programadas semanalmente, con una responsabilidad clara y evaluadas como cualquier otro compromiso operativo. Una cadencia predecible ayuda a reducir el periodo de exposición en todo el entorno informático y a eliminar el «sobrecoste por pánico» que supone cualquier divulgación concreta. Cuando las actualizaciones se hacen cada semana, las organizaciones están preparadas para las vulnerabilidades (CVE).
La cadencia no significa tratar todo por igual. Una vulnerabilidad que se está explotando activamente, de esas que acaban enCISA’s Known Exploited Vulnerabilities Catalog, sigue mereciendo una respuesta inmediata y fuera de la rutina. El calendario semanal gestiona el aluvión de incidencias como algo rutinario, para que las verdaderas emergencias reciban la atención que merecen en lugar de tener que competir con el ruido de fondo.
Soluciona la vulnerabilidad, no solo el problema
Esta es la parte que Recovery no puede solucionar por sí sola. Si una vulnerabilidad pone en riesgo un activo, restaurar ese activo sin cerrar la vulnerabilidad solo reinicia el reloj. La vulnerabilidad sigue ahí, a la espera del siguiente intento. Recovery es importante, pero no sustituye a cerrar el agujero por el que entró el actor malintencionado.
Esto significa que el verdadero trabajo debe realizarse antes, en el momento en que se detectan y corrigen las vulnerabilidades. La IA está cambiando esa ecuación en ambos frentes. Los mismos modelos que ayudan a un actor malintencionado a detectar una explotación pueden ayudar a un proveedor a encontrarla primero. El equipo de ingeniería de Commvault utiliza la IA en nuestro propio código para detectar vulnerabilidades antes de que se lancen, y aplicamos la IA para ayudar a resolver lo que encontramos, en lugar de dejarlo en la lista de tareas pendientes. Una vulnerabilidad que se queda en la cola durante semanas porque a un equipo se le acabó la capacidad sigue siendo una vulnerabilidad. La rapidez en la detección no sirve de nada sin rapidez en la resolución.
Pide más a tus proveedores
When the window between discovery and exploit is measured in hours, customers cannot afford to learn about a vulnerability in their vendor’s product from a third party.
They need to hear it from the vendor, early, in plain language, with a direct answer to “Am I affected?” and “What do I do first?” Ask every critical vendor how quickly they disclose, how they notify affected customers, what evidence they provide for remediation, and how customers can validate that the exposure is closed. Vulnerability transparency is part of resilience.
The frontier AI era will not be won by whoever ships the fewest vulnerabilities. Every serious software company will disclose more. The advantage goes to whoever treats patching as a standing discipline and treats recovery as the discipline that makes a missed window survivable.
Preguntas frecuentes
Q: Why is the window between vulnerability discovery and exploitation getting shorter?
A: AI is likely compounding pressure by helping threat actors exploit vulnerabilities, and defenders identify and validate vulnerabilities faster than legacy cataloging workflows can absorb. As a result, exploit code can become available before many organizations have had time to deploy patches.
Q: Why are weekly patching cycles becoming more important?
A: A consistent weekly patching schedule helps reduce the organization’s exposure to known vulnerabilities. It also allows security teams to focus immediate attention on actively exploited threats and prepare new CVEs.
Q: Is disaster recovery enough to protect against cyberattacks?
A: No. Recovery helps organizations restore operations after an incident, but restoring systems without addressing the underlying vulnerability leaves them exposed to future attacks. Effective resilience requires both rapid remediation and reliable recovery.
Q: How can AI help improve vulnerability management?
A: AI can help identify vulnerabilities earlier, prioritize remediation efforts, and accelerate the resolution process. This helps security and engineering teams respond more quickly instead of allowing vulnerabilities to remain unresolved in lengthy backlogs.
Q: What should organizations ask their software vendors about vulnerability management?
A: Organizations should ask how quickly vendors disclose vulnerabilities, how affected customers are notified, what remediation guidance is provided, and how customers can verify that the issue has been fully addressed. Transparent communication is an important part of cyber resilience.
Rajiv Kottomtharayil is Chief Products Officer at Commvault.
