Punti di forza
- La rapida crescita delle vulnerabilità e l’individuazione basata sull’intelligenza artificiale stanno riducendo il tempo che intercorre tra la divulgazione di una vulnerabilità e il suo sfruttamento attivo.
- Cicli di applicazione delle patch regolari e disciplinati contribuiscono a ridurre l’esposizione complessiva e a prepararsi alle nuove vulnerabilità (CVE).
- Il ripristino è fondamentale per la resilienza, ma deve essere accompagnato dall’applicazione tempestiva delle patch per correggere le vulnerabilità.
- Le organizzazioni dovrebbero avvalersi dell’intelligenza artificiale per accelerare l’individuazione e la risoluzione delle vulnerabilità, anziché lasciare che i problemi si accumulino nei backlog.
- I fornitori che svolgono un ruolo fondamentale garantiscono ai clienti una comunicazione rapida e trasparente delle vulnerabilità e indicazioni chiare su come risolverle.
L’anno scorso,secondo i dati di settore, il volume annuale dei CVE si attestava a decine di migliaia; in seguito, il NIST ha segnalato una crescita record dei CVE e unaumento del 263% delle segnalazioni between 2020 and 2025.
I hear what that does to a security team in real time, because I am on the calls when it happens. The old questions – what is our exposure, and how fast can we close it? – used to have room to breathe. Now they arrive faster than most teams can staff for them.
Most organizations have vulnerability response processes. Fewer have processes designed for this speed.
For years, the industry organized its response around individual vulnerabilities. A CVE would publish, severity scores would follow, enrichment would catch up, and teams would triage with some margin for judgment. That rhythm assumed a human pace of discovery, but that assumption no longer holds.
That volume is already outrunning the infrastructure built to track it. NIST has said the National Vulnerability Database is moving to a risk-based enrichment model because CVE submissions have grown faster than the program can fully process them.
AI is likely compounding pressure by helping threat actors exploit vulnerabilities, and defenders identify and validate vulnerabilities faster than legacy cataloging workflows can absorb. The window between when a vulnerability is discovered and when it is exploited is closing, and working exploit code can appear before a patch is widely deployed.
That breaks the old model. Structured vulnerability management still matters, but many programs are calibrated for a slower era: gather signal, rank risk, assign owners, then remediate. When discovery accelerates this sharply, even disciplined teams fall behind because the operating model cannot absorb the volume fast enough.
So, the unit of work must change. It no longer matters whether you patched a specific vulnerability but whether your organization can apply, verify, and recover at the speed the threat environment now demands.
Toppe su un orologio
Iniziate dalla cadenza. Le operazioni più resilienti che ho osservato hanno smesso di considerare l’applicazione delle patch come un’interruzione e hanno iniziato a trattarla come una manutenzione di routine: programmata settimanalmente, con responsabilità ben definite e misurata come qualsiasi altro impegno operativo. Una cadenza regolare contribuisce a ridurre il periodo di esposizione in tutto il parco sistemi e ad eliminare il “premio di panico” associato a ogni singola segnalazione. Quando gli aggiornamenti vengono effettuati ogni settimana, le organizzazioni sono preparate ad affrontare le vulnerabilità (CVE).
La cadenza non significa trattare tutto allo stesso modo. Una vulnerabilità oggetto di sfruttamento attivo, del tipo che viene inserita nelCISA’s Known Exploited Vulnerabilities Catalog, richiede comunque una risposta immediata e fuori programma. Il programma settimanale gestisce il flusso di segnalazioni come routine, in modo che le vere emergenze ricevano la giusta attenzione senza dover competere con il rumore di fondo.
Colmare la vulnerabilità, non solo il divario
Ecco la parte che Recovery da solo non può risolvere. Se una vulnerabilità mette a rischio una risorsa, ripristinare quella risorsa senza risolvere la vulnerabilità equivale solo a azzerare il conto alla rovescia. La vulnerabilità è ancora lì, in attesa del prossimo tentativo. Recovery è importante, ma non sostituisce la chiusura della falla che ha permesso all’autore della minaccia di entrare.
Ciò significa che il vero lavoro deve avvenire prima, nel momento in cui le vulnerabilità vengono individuate e risolte. L’intelligenza artificiale sta cambiando questa equazione su entrambi i fronti. Gli stessi modelli che aiutano un autore di minacce a individuare uno sfruttamento possono aiutare un fornitore a individuarlo per primo. Il reparto di ingegneria di Commvault utilizza l’intelligenza artificiale sul nostro codice sorgente per individuare le vulnerabilità prima del rilascio, e applichiamo l’intelligenza artificiale per risolvere i problemi rilevati, anziché inserirli in un elenco di attività in sospeso. Una vulnerabilità che rimane in coda per settimane perché un team ha esaurito le risorse disponibili rimane comunque una vulnerabilità. La rapidità di rilevamento non ha alcun significato senza la rapidità di risoluzione.
Chiedete di più ai vostri fornitori
When the window between discovery and exploit is measured in hours, customers cannot afford to learn about a vulnerability in their vendor’s product from a third party.
They need to hear it from the vendor, early, in plain language, with a direct answer to “Am I affected?” and “What do I do first?” Ask every critical vendor how quickly they disclose, how they notify affected customers, what evidence they provide for remediation, and how customers can validate that the exposure is closed. Vulnerability transparency is part of resilience.
The frontier AI era will not be won by whoever ships the fewest vulnerabilities. Every serious software company will disclose more. The advantage goes to whoever treats patching as a standing discipline and treats recovery as the discipline that makes a missed window survivable.
Domande frequenti
Q: Why is the window between vulnerability discovery and exploitation getting shorter?
A: AI is likely compounding pressure by helping threat actors exploit vulnerabilities, and defenders identify and validate vulnerabilities faster than legacy cataloging workflows can absorb. As a result, exploit code can become available before many organizations have had time to deploy patches.
Q: Why are weekly patching cycles becoming more important?
A: A consistent weekly patching schedule helps reduce the organization’s exposure to known vulnerabilities. It also allows security teams to focus immediate attention on actively exploited threats and prepare new CVEs.
Q: Is disaster recovery enough to protect against cyberattacks?
A: No. Recovery helps organizations restore operations after an incident, but restoring systems without addressing the underlying vulnerability leaves them exposed to future attacks. Effective resilience requires both rapid remediation and reliable recovery.
Q: How can AI help improve vulnerability management?
A: AI can help identify vulnerabilities earlier, prioritize remediation efforts, and accelerate the resolution process. This helps security and engineering teams respond more quickly instead of allowing vulnerabilities to remain unresolved in lengthy backlogs.
Q: What should organizations ask their software vendors about vulnerability management?
A: Organizations should ask how quickly vendors disclose vulnerabilities, how affected customers are notified, what remediation guidance is provided, and how customers can verify that the issue has been fully addressed. Transparent communication is an important part of cyber resilience.
Rajiv Kottomtharayil is Chief Products Officer at Commvault.
