Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
  • AI
  • Tech
  • Cybersecurity
  • Finance
  • DeFi & Blockchain
  • Startups
  • Gaming
Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

Building a permanent VulnOps function to survive the AI vulnerability storm

byEditorial Team
July 24, 2026
in Industry
Home Industry
Share on FacebookShare on TwitterShare on LinkedInShare on WhatsAppShare on e-mail
Google Preferred Source

VulnOps is quickly becoming a core security function. Its purpose is straightforward: continuously identify, prioritize, fix, and verify software vulnerabilities before they turn into exploitable risk.

Like DevOps and Site Reliability Engineering before it, VulnOps brings a flow-based operating model to a process that has often been slow, ticket-driven, and reactive. That shift is especially important after Mythos, because AI-driven vulnerability discovery now moves faster than traditional patch cycles can support.

Following the Cloud Security Alliance’s April 2026 briefing, the message is clear: organizations can no longer manage vulnerabilities as a periodic backlog. They need a permanent VulnOps capability with owners, workflows, automation, and metrics.

Stay Ahead of the Curve!

Don't miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.

Building a permanent VulnOps function to survive the AI vulnerability stormThe baseline imperative for VulnOps

The old model is simple: scan, ticket, rank by CVSS, and patch on a monthly or quarterly schedule. The problem is that this process assumes the queue stays relatively stable (and it doesn’t). But VulnOps assumes a continuous stream of AI-discovered vulnerabilities requiring permanent triage.

The numbers show why the old process is breaking. Last year alone, more than 48,000 new CVEs were published. This volume forces a move away from periodic sprint mentalities toward building permanent prioritization and remediation capacity. Yet, any continuous remediation effort requires a clear understanding of the environment first.

Building a permanent VulnOps function to survive the AI vulnerability storm“Both security and IT share the same foundational goal: knowing what normal looks like. Security is anomaly detection. IT is troubleshooting. Neither works without an established baseline,” Jason Kikta, Automox CTO, said.

You simply can’t secure systems you don’t fully understand.

The human cost and staffing reality

Maintaining a continuous patching flow carries immediate staffing implications. Security teams are absorbing exponential workload increases, often without corresponding investments in automation or tooling. The recent CSA briefing treats team resilience as a strategic priority. It explicitly recommends that organizations increase headcount alongside automation initiatives to prevent widespread burnout.

The manual burden is a documented reality. According to the 2026 State of Endpoint Management Report, 43% of teams spend 10 or more hours per week on manual endpoint tasks. Despite this drain on resources, 27% of organizations still allocate less than 10% of their IT budget to endpoint management. More concerning, only 6% of organizations report being fully automated.

Building a permanent VulnOps function to survive the AI vulnerability stormRelying on manual intervention to process a machine-speed vulnerability feed guarantees that teams will eventually fail to keep pace. This exposes organizations to unnecessary risk while exhausting their specialized personnel.

Building the operational foundation with autonomous endpoint management

A VulnOps agenda relies heavily on endpoint management to succeed. A complete and accurate endpoint inventory acts as the mandatory precondition for this operational model. You can’t patch, segment, or measure service-level agreements for assets you don’t know exist. Transitioning from manual oversight to an automated framework is necessary to establish this baseline.

To implement this, tools like Automox provide autonomous endpoint management mechanisms. Automox’s Turnkey Results operates as a personalized blueprint built from 1.4 billion policy runs, providing an implementation design specific to each environment. This moves organizations from relying on ad-hoc scripting to governed execution at frontier pace.

The financial and operational return on building this foundation is measurable. Recent 2025 data demonstrates a 362% return on investment with a four-month payback period for automated patch and endpoint management. Structured automation directly offsets the rising costs of continuous remediation.

Rethinking remediation metrics

VulnOps changes how security teams instrument their programs. Rather than relying on severity ranking alone, a mature VulnOps function measures lead time from disclosure to verified remediation, change-failure rates on patches, and pipeline saturation.

Depending exclusively on CVSS scores is dangerous. Following the National Vulnerability Database’s recent triage policy shift, the majority of new CVEs will arrive without full enrichment.

To adapt, VulnOps programs are transitioning to composite signals. They combine the CISA Known Exploited Vulnerabilities (KEV) catalog and the Exploit Prediction Scoring System (EPSS) to determine what actually requires immediate automated remediation. This data-driven approach ensures teams allocate their automated patching cycles to active threats. It reduces noise and focuses execution on defects that present immediate, provable risk.

Turning continuous remediation into practice

The CSA briefing turns this shift into a concrete roadmap. Organizations should begin immediately by checking that known vulnerabilities are patched and baseline configurations are in place. The focus should move to automating routine remediation and finishing asset inventories within 45 days.

The longer-term target is clear. VulnOps should operate as a dedicated function with staffing and ownership as well as metrics within 12 months. Achieving operational readiness means acknowledging that vulnerabilities won’t ever stop flowing. Building a continuous, automated response is the only sustainable strategy moving forward.


Featured image credit

Tags: trends

Related Posts

Why exchange rate data misleads most businesses and how to read it properly

Why exchange rate data misleads most businesses and how to read it properly

July 24, 2026
How software learned to make blurry photos clear

How software learned to make blurry photos clear

July 24, 2026
Apple Maps powers navigation in Ford’s new EVs

Apple Maps powers navigation in Ford’s new EVs

July 24, 2026
EU approves  billion acquisition of Electronic Arts by Saudi fund

EU approves $55 billion acquisition of Electronic Arts by Saudi fund

July 24, 2026
Patreon lays off 20% of staff amid AI-focused restructuring

Patreon lays off 20% of staff amid AI-focused restructuring

July 24, 2026
The quiet sector JP Conte thinks Wall Street is sleeping on

The quiet sector JP Conte thinks Wall Street is sleeping on

July 23, 2026

LATEST NEWS

Xbox tests free ad-supported cloud gaming

OpenAI launches ChatGPT Health to all US users

Runway introduces AI model router via Dev platform

AMD unveils Helios AI rack to challenge Nvidia

Amazon brings Luna games into Prime Video

Anthropic upgrades Claude voice mode with Sonnet

BEST AI MODELS LEADERBOARD

See the best AI models, ranked by intelligence, benchmark results, speed and token price. Find the most suitable LLMs, Text-to-Image, Image Editing, Text-to-Speech, Text-to-Video and Image-to-Video  artificial intelligence model for your tasks and business.

LATEST TOOLS

Amanda AI

InterviewBot

VernAI

MyLoans

Essay Grader AI

Cover Letter AI

Animate Old Photos

Resume.io

MonAI

AIEngine Plugin

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy

Follow Us

  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI tools
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
No Result
View All Result
Subscribe

This website uses cookies to improve your experience. You can choose to accept or reject them. Visit our Privacy Policy.