The industry spent the initial months after Anthropic's April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI-driven discovery overwhelm triage capabilities? How long would it take adversaries to weaponize Mythos findings at scale? Those questions were and remain valid. Yet they all stop short of addressing the single metric that determines whether any of those vulnerabilities actually lead to a breach: the exposure window.
The exposure window - the gap between the moment a vulnerability becomes exploitable and the moment your team fixes it - is the time an attacker has to do actual damage. That window is currently open far too wide. In 2025, the average eCrime breakout time dropped to 29 minutes. Even PCI DSS - the strictest compliance framework in the industry - allows 30 days to remediate a critical vulnerability. That's a 1,000-to-1 gap between how fast attackers move and how fast organizations are expected to respond. And the stick propping this exposure window open? Mobilization - the ownership, remediation, and organizational complexity that lowers response times and raises risk.
In this article, I'll walk through why the exposure window is now the metric that matters most, what keeps it open, and how AI-driven discovery is forcing proactive security teams to adopt the speed-based metrics that SOC teams have used for years.
Mythos Didn't Create the Exposure Window. It Widened It.
The vulnerability management model was already showing cracks before Mythos came on the scene. 48,185 CVEs were disclosed in 2025 - a 22% jump over 2024. Most security teams were already drowning in their remediation backlog. And current projections are that 66,000 new CVEs will be listed in 2026. Often, every one of those CVEs ends up in the same remediation pipeline - subject to manual approvals, fragmented ownership, and change windows that move at the pace of enterprise IT - not at the pace of attackers.
Gartner's CTEM framework defines five stages: scoping, discovery, prioritization, validation, and mobilization. The first three stages now run at machine speed. Validation - confirming that your controls actually stop real threats - has improved as platforms have automated attack path testing. Yet mobilization still runs at organizational speed.
Recent policy moves acknowledge the disparity. Notably, CISA's BOD 26-04 shifts federal agencies from CVSS-first patching toward exploitability and asset context (which is what CTEM has called for all along). But this directive still addresses only which vulnerabilities to fix first. It does not address how fast organizations can mobilize to execute the fix. Meaning, it still leaves the exposure window wide open.
Why Mobilization Is Where Programs Break
The gap between knowing which vulnerability to fix and actually fixing it is a mobilization problem. The security team identifies the exposure, and a different team - one with its own priorities, its own change windows, its own approval chains - has to remediate it. That handoff is the soft underbelly of most CTEM programs. Enterprise remediation processes were built for a pipeline that moves at human speed, but every stage upstream of mobilization no longer does.
According to recent research, high and critical application vulnerabilities take an average of 55 days to remediate, and nearly half of enterprise vulnerabilities remain unpatched after a full year. Most organizations still do not prioritize remediation based on exploitability and business impact, in any case. And legacy systems, OT environments, and production infrastructure can have a serious business impact when they go offline - so fixes tend to wait. Further, identity exposures like excessive privileges and cached credentials don't even have a patch to apply. Many findings simply land in the queue with no single team responsible for resolving them.
The point is that the exposure window stays open because the organizational machinery between "fix this" and "fixed" takes weeks or months to turn, while attackers need just minutes. Which begs the question: how long can proactive security teams keep measuring success on a different clock than attackers?
Proactive Teams Now Operate on Reactive Timelines
Security organizations have traditionally split into two operational modes. SOC teams - the reactive side - track dwell time, mean time to respond, and containment speed. Their job is to limit damage from threats already inside the environment. VM teams, cloud security teams, and network security teams - the proactive side - track patch coverage by severity level or time to fix misconfigurations. Their job is to reduce exposure before an attacker arrives.
The thing is, AI-driven discovery essentially puts both teams on the same stopwatch.
When vulnerabilities move from disclosure to weaponization in hours and breakout time is measured in minutes, a quarterly patch rate of 90% means nothing if critical assets sat exploitable for weeks while those patches waited in the queue. Proactive teams now need the same speed-based metrics the SOC has always used - because no remediation process can outrun a 29-minute breakout time on its own.
Teams need to accept that the exposure window will never fully close. Rather, we need to ask ourselves how far we can close it, and when an attacker moves through the gap, how many critical assets can they reach?
Shrinking the Blast Radius
That reachable set of assets - the blast radius - is what determines actual business risk. Since no organization can close every exposure at the speed attackers move, priority needs to shift to the paths that connect exploitable exposures to critical assets. The 2026 Verizon DBIR makes this case for attack path analysis - with the goal of making the blast radius visible.
Not every exposure leads somewhere dangerous. Attack path analysis shows which exposures open routes to critical assets and which ones are simply dead-ends. This narrows the scope of mobilization - from an unfinishable backlog to a finite set of paths. And once teams start tracking how long critical assets stay reachable, remediation speed becomes a business risk metric. Mobilization stops holding the exposure window open and starts closing it.
Mythos didn't break your security program. Your exposure window might - if you let mobilization keep propping it open.
Note: This article was thoughtfully written and contributed for our audience by Ryan Blanchard, Director of Product Marketing, XM Cyber.
Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
0 Comments
Log in to join the conversation.No comments yet. Be the first to share your thoughts.