Avatar

Something shifted in the vulnerability landscape, and most of the industry is still operating as if it didn’t happen.

For years, the discipline of vulnerability management rested on a comfortable assumption: that defenders and attackers moved at roughly human speed. A flaw was disclosed. Teams triaged. Patches were tested, scheduled, and rolled out over days or weeks. The window between disclosure and exploitation was uncomfortable, but it was survivable. It was a race between people.

That assumption is now obsolete.

With the arrival of frontier AI models capable of discovering — and weaponizing — software flaws at machine scale, the clock has been rewritten. What once took a skilled adversary weeks now takes an automated system hours. The race is no longer between people. It’s between machines that find flaws and humans who still fix them by hand.

The defining question is no longer “Are we patched?” It’s “Can we survive the gap between disclosure and defense?” And in that framing, every hour of human-speed response is an open door.

The gap didn’t just narrow. It inverted.

If you want a single picture of why this matters, look at the trajectory of time-to-exploitation (TTE) — the gap between a CVE going public and its first confirmed exploitation in the wild.

*Based on 3,500+ confirmed-exploited CVEs (CISA KEV + VulnCheck KEV). Source: zerodayclock.com*

Read that last figure again. In 2026, the mean TTE went negative. Attackers are now, on average, exploiting flaws before they’re publicly disclosed. The defensive window hasn’t just shrunk — it has closed and gone into deficit. Meanwhile, the volume of weaponized exploits has climbed year over year, peaking in 2024 and holding high.

This is the whole argument in one curve. A remediation process measured in weeks was tenable when TTE was measured in years. It is untenable when TTE is measured in hours — and unthinkable when it’s negative.

The uncomfortable arithmetic

The math is brutal in its simplicity:

  • Hours to weaponize a newly disclosed flaw.
  • Weeks to patch it through manual remediation.

Sit with that gap for a moment, because everything else follows from it. Manual remediation is structurally outpaced. Generic scanning generates more noise than signal. Periodic testing guarantees blind spots between cycles. And zero-days are no longer occasional events — they’re a continuous condition.

The conclusion writes itself: machine-speed threats demand machine-speed defense. Not as a slogan, but as an operating principle. The organizations that thrive in this era won’t be the ones with the most scanners. They’ll be the ones who have collapsed the gap between knowing and acting.

The layer everyone forgot

Here’s where the thinking gets interesting for anyone who operates infrastructure.

Almost every enterprise vulnerability program is built around endpoints and servers. That’s where the tooling matured, where the budgets went, and where the attention stays. Meanwhile, the network infrastructure layer — routers, switches, firewalls, wireless controllers, load balancers, SD-WAN edge, OT gateways — has been quietly left under-assessed.

This is not a minor oversight. That layer sits astride some of the highest-impact attack paths in the entire environment. It is precisely the terrain a machine-speed adversary would want. And it is the terrain most enterprise programs are least equipped to watch continuously.

There’s a strategic asymmetry here that the managed services community is uniquely placed to exploit: the layer the market forgot is the layer MSPs already operate. You run the NOC. You touch these assets daily. The relationship, the access, and the operational discipline already exist. What hasn’t been monetized — yet — is the security posture of infrastructure you’re already responsible for.

From network operations to vulnerability operations

The response to a machine-speed world is a discipline that’s beginning to take shape under the name VulnOps — Vulnerability Operations.

VulnOps is the shift from point-in-time patching to a continuous defensive pipeline: automated detection, triage, and remediation woven directly into daily operations. It’s the recognition that vulnerability management can no longer be a quarterly event. It has to become a living process — always on, always current.

Applied to a NOC, the principles translate cleanly:

  • A complete, always-current inventory of every element in production and lab.
  • Continuous identification of OS and firmware vulnerabilities across the estate.
  • OEM validation to separate real guidance from generic advisories.
  • Honest assessment of real-world impact — not theoretical severity.
  • Structured remediation planning and execution.
  • And ultimately, continuous, automated tracking and remediation that operates at the speed of the threat.

The philosophy underneath it is balance: strengthen the fundamentals, eliminate structural risk, automate at machine speed, and progressively harness AI for defense rather than leaving it solely in the hands of the attacker.

Signal, not noise

There’s a trap worth naming, because it’s where most well-intentioned programs go wrong. Raw CVSS scoring treats every vulnerability in isolation. The output is thousands of “criticals” and no way to tell which ones matter. That’s not intelligence — it’s a spreadsheet, and spreadsheets don’t defend anything.

The mature move is to rank findings by two questions that actually change outcomes: Is this exploitable in this specific environment? (using signals like EPSS and KEV) and How much does the affected asset actually matter? (business criticality). Answer those, and the impossible backlog of theoretical criticals collapses into the handful of issues that can genuinely cause harm. That’s the difference between busywork and defense.

Why this is an MSP story, not just a security story

The most durable business opportunities tend to sit where a genuine market gap overlaps with something you already do well. VulnOps for the network layer is exactly that overlap.

It’s adjacent revenue on an existing footprint — no new customer relationship required, just deeper value in the ones you own. It’s recurring and low-capex, a subscription model that scales with the estate you already manage. It offers a natural land-and-expand path, from scan-and-report to fully managed remediation as trust deepens. And it’s sticky by design: once you become the system of record for network risk — with continuous assessment and audit-ready evidence — you’re very hard to displace.

Perhaps most importantly, the entry bar is a maturity ramp, not a gate. If you run a disciplined NOC — solid asset tracking, mature ticketing and change management, active element management, working familiarity with CVE/KEV — you already meet the threshold to begin. The advanced capabilities are how you climb into higher-margin tiers, not prerequisites to start.

The bottom line

The post-Mythos era didn’t just accelerate the threat. It exposed a structural gap — a critical layer of infrastructure that most programs don’t watch, defended at a speed the adversary has already left behind. When time-to-exploitation goes negative, “we’ll patch it next cycle” isn’t a strategy. It’s a countdown.

Closing that gap is going to be one of the defining managed-services opportunities of this cycle. And the operators best positioned to seize it aren’t the ones building something new. They’re the ones who already run the network — and are ready to run its security posture, too.

Bring the NOC discipline. The framework, the tooling, and the model are ready.

Authors

Russ Atkin

Global Service Creation Lead, AI & Olly

Global Partner Sales