Historically, when a vulnerability was disclosed, defenders had a window. Sometimes that window was weeks, sometimes days, occasionally hours. It wasn’t that attackers were unaware of the flaw, it was that there was still real work to do before it became dangerous.
Someone had to understand the flaw, work out whether it was genuinely exploitable, build a proof of concept and then adapt it to a real-world target. That took time. Acknowledged or not, time has always been one of the most valuable assets defenders had. The race began the moment a vulnerability went public, but for the most part attackers and defenders competed on similar terms.
I’m increasingly convinced that won’t be true for much longer.
The Gap Is Shrinking
Figure 1: The disclosure-to-exploit window, 2020 versus 2026.
Most discussions about AI and cyber security focus on a single question: will AI help us find more vulnerabilities? I think that’s the distraction. AI is certainly getting better at analysing code and uncovering weaknesses, and it’s reasonable to expect vulnerability research to become more productive over time.
But that isn’t the shift security teams should be watching. The bigger change is what happens after a vulnerability becomes public. Disclosure was always just the beginning, because understanding the issue, assessing exploitability and building a working exploit all took time, effort and specialist skill.
AI is rapidly reducing that effort. The concern isn’t that AI creates entirely new threats, it’s that it compresses the timelines we’ve quietly relied on for years.
For defenders, the most significant change may not be vulnerability discovery itself, but the shrinking gap between vulnerability disclosure and exploitation.
Every Stage After Disclosure Is Getting Faster
Figure 2: AI is compressing every stage that follows disclosure.
Think about what happens after a new CVE is announced. Researchers analyse the technical detail, attackers assess whether it’s exploitable, proof-of-concept code starts to appear and exploits are gradually adapted to real environments. Each of those steps has traditionally been a natural delay between disclosure and widespread exploitation.
Large language models are getting better at helping people navigate technical documentation, understand complex code and speed up development tasks. That doesn’t mean AI is replacing skilled researchers, but it does mean a skilled individual can now move considerably faster than before.
If understanding a vulnerability takes less time, and building a proof of concept takes less time, the gap between disclosure and exploitation inevitably narrows. The real impact won’t be in the number of vulnerabilities that exist, it will be in the speed at which they become actionable.
As AI tools become more capable, the effort required to analyse vulnerabilities, understand exploit paths and develop proof-of-concept code continues to decrease.
Vulnerability Management Becomes a Speed Problem
Figure 3: From reducing vulnerabilities to responding at speed.
For years, vulnerability management has largely been a prioritisation exercise: find vulnerabilities, assess risk, schedule remediation, report compliance and repeat. Those activities still matter, but if the gap between disclosure and weaponisation keeps shrinking, speed starts to matter far more than it does today.
The key question changes. Instead of asking “how do we reduce vulnerabilities?”, we increasingly need to ask “how quickly can we safely get a fix into production?”. Many organisations still run patching cycles measured in weeks, and some in months. That may have been acceptable when exploit development was slow and attackers faced the same technical barriers as everyone else.
The organisations that perform best won’t be the ones with the fewest vulnerabilities. They’ll be the ones that can respond safely at speed, which puts far greater emphasis on automation, mature testing and deployment pipelines that move quickly without introducing unnecessary operational risk. The challenge isn’t simply finding vulnerabilities anymore, it’s responding before attackers do.
Defence In Depth Gets More Valuable
Figure 4: Defence in depth buys defenders time.
The other implication doesn’t get discussed often enough. For years we’ve talked about Zero Trust, conditional access, EDR, segmentation and privileged access controls. Some organisations embraced those principles early, others have improved gradually, but either way their value is about to become much more obvious.
None of these controls prevent a vulnerability from existing, and none of them remove the need to patch. What they provide is friction. They slow attackers down, restrict movement, increase the likelihood of detection and reduce blast radius. In short, they buy defenders time.
If time becomes the scarce resource we’re all competing for, those layers suddenly matter far more. We’ve traditionally seen defence in depth as a way of improving security posture. We may soon need to see it as a way of extending reaction time, because every additional layer gives security teams one more chance to detect, contain or disrupt an attack before it reaches its objective.
Security strategies such as Zero Trust, network segmentation, endpoint detection and response (EDR) and privileged access management become increasingly valuable because they help organisations detect, contain and respond to attacks more quickly.
Looking Ahead
Cyber security has always been a race. What’s changing is the pace. I don’t think the biggest story over the next few years will be AI discovering endless numbers of unknown vulnerabilities. The bigger story will be how AI affects every stage that follows disclosure, from understanding the flaw to adapting an attack for a specific target.
All of those activities are getting faster, and if that trend continues, many of the assumptions we’ve built vulnerability management programmes around will need to evolve. The organisations that succeed won’t be the ones that predict every vulnerability before it appears. They’ll be the ones that can adapt, respond and recover most quickly once it does.
The organisations best positioned for the future will not necessarily be those with the fewest vulnerabilities. They will be those that can identify, prioritise, patch and respond faster than the threat landscape evolves.
We’ve spent years trying to reduce risk. We may need to get much better at reducing reaction time.
FAQs
What is the vulnerability disclosure-to-exploit window?
The vulnerability disclosure-to-exploit window is the period between a security vulnerability becoming publicly known and attackers developing or deploying a working exploit. Historically, this window has given defenders time to assess risk and apply patches before exploitation becomes widespread.
How is AI changing cyber security?
AI is helping security professionals analyse code, understand vulnerabilities and automate technical tasks more efficiently. At the same time, it may reduce the time required for attackers to analyse vulnerabilities and develop exploits after disclosure.
What is a CVE?
A CVE (Common Vulnerabilities and Exposures) is a publicly disclosed cyber security vulnerability that has been assigned a unique identifier to help organisations track, assess and remediate security risks.
Why is vulnerability management becoming more time-sensitive?
As AI accelerates activities such as vulnerability analysis and exploit development, organisations may have less time to test, prioritise and deploy fixes before vulnerabilities are actively exploited.
What is defence in depth?
Defence in depth is a cyber security strategy that uses multiple layers of security controls, such as Zero Trust, endpoint protection, network segmentation and privileged access management, to reduce risk and limit the impact of a successful attack.
Why is speed becoming more important in cyber security?
If the gap between vulnerability disclosure and exploitation continues to shrink, organisations will need to identify, prioritise and remediate vulnerabilities more quickly. Speed of detection, response and recovery may become as important as prevention.



