The Challenge of Exposure Windows in Security
Following the unveiling of Mythos by Anthropic on April 7, the security sector quickly shifted its focus to understanding the volume of new vulnerabilities. Questions arose about the potential surge in CVEs, the ability of teams to manage the influx, and the speed at which adversaries might exploit these vulnerabilities. Despite these concerns, the critical issue remains the exposure window—the period between vulnerability discovery and its remediation.
The exposure window represents the timeframe during which attackers can exploit vulnerabilities before they are patched. In 2025, the average time for an eCrime breakout was reduced to just 29 minutes, highlighting the disparity between attacker speed and the industry’s response. The challenge is amplified by organizational hurdles in mobilization, which hinder the swift resolution of vulnerabilities.
Mythos and the Widening Exposure Window
Even before Mythos, the vulnerability management landscape was strained. In 2025 alone, 48,185 CVEs were disclosed, marking a 22% increase from the previous year. Projections for 2026 suggest a further rise to 66,000 CVEs. Such numbers overwhelm existing remediation processes, which often involve cumbersome manual approvals and slow adaptation to enterprise IT procedures.
Gartner’s CTEM framework outlines five stages: scoping, discovery, prioritization, validation, and mobilization. While the initial stages have been accelerated by technology, the final step—mobilization—lags due to organizational inertia. New policies, such as CISA’s BOD 26-04, attempt to prioritize vulnerabilities based on exploitability, but do not address the speed of mobilization, leaving the exposure window vulnerable.
Mobilization: The Critical Bottleneck
The gap between identifying and fixing vulnerabilities is primarily a mobilization issue. Security teams may pinpoint vulnerabilities, but the responsibility for remediation often falls on different teams with their own priorities and processes. This disconnect results in delays, with high and critical vulnerabilities taking an average of 55 days to address, and many remaining unpatched for over a year.
Legacy systems and complex infrastructure further complicate the issue, as taking them offline for patches can have significant business impacts. Additionally, identity exposures like excessive privileges lack straightforward fixes, often falling into a backlog with no clear path to resolution.
Aligning Proactive and Reactive Security Efforts
Traditionally, security operations have been divided between proactive and reactive measures. While SOC teams focus on minimizing damage from existing threats, other teams work to preemptively close vulnerabilities. However, the rapid pace of AI-driven discovery means that both must now operate on similar timelines.
When vulnerabilities can be exploited within hours and breakout times are measured in minutes, traditional patching strategies become insufficient. Proactive teams must adopt speed-based metrics to keep pace with the threat landscape, as a delayed response leaves critical assets exposed.
Reducing the Impact of Vulnerabilities
The true risk to businesses is determined by the blast radius—the critical assets that are vulnerable to exploitation. As closing every exposure instantly is unfeasible, organizations must focus on securing pathways leading to critical assets. Attack path analysis can reveal which exposures pose genuine risks, enabling more focused remediation efforts.
By narrowing the scope of necessary actions, organizations can shift from an unmanageable backlog to a targeted strategy that prioritizes business risk. Ultimately, addressing the exposure window effectively requires minimizing the time vulnerabilities remain exploitable, thereby reducing the potential impact on critical infrastructure.
Mythos hasn’t dismantled security programs, but the persistent issue of exposure windows might, unless organizations enhance their mobilization efforts.
Note: This article was contributed by Ryan Blanchard, Director of Product Marketing at XM Cyber.
