
Vulnerability management has been a staple of security programs since the dawn of the cybersecurity discipline. The symbiotic relationship between vulnerability and patch management teams has also existed for that time and has gone through waves of contention and thankfulness. While this relationship required thoughtful care and feeding from both sides, both sides were aiming to work toward a common goal of identifying vulnerabilities and confirming the risk was removed from the environment.
In come Frontier AI models such as Anthropic's Mythos to radically change the vulnerability management space. These models can identify zero-day flaws, chain complex exploits, and adapt in real time. They have forced vulnerability management programs to take an introspective look at themselves and ask, “Is my vulnerability program ready for this revolution?” For many organizations, the answer is no. Many vulnerability management programs were hanging by a thread already, with very distant plans of migrating to a CTEM-style program yet with a backlog of vulnerabilities that stretched for miles.
Do not let Frontier AI’s impact on security go to waste. Vulnerability programs need to be systematically revolutionized to meet the changing threat and risk landscape, and the time is now to mature your program to meet the ever-increasing concerns Frontier AI models introduce to organizations.
With so many moving parts of a vulnerability program that need to be managed on the ground, where do you start building up your program's maturity? As opposed to how vulnerability and patch management programs operated in a siloed fashion in the past, this is now the opportunity to work together as a team to tackle the new cybersecurity concerns being introduced. Both vulnerability and patch management programs now require a major upgrade.
Going Beyond CVSS, EPSS, and KEV
From a vulnerability management perspective, just looking at CVSS scores alone is not going to be enough to see through the noise of vulnerabilities and to provide a risk-based view into what your organization should prioritize. Additionally, vulnerabilities prioritized by EPSS (Exploit Prediction Scoring System) and by CISA's KEV (Known Exploited Vulnerabilities) list have now become table stakes for vulnerability management programs to prioritize and govern removal from the organization. However, how do we answer the question of how to prioritize vulnerabilities that are rapidly being turned into exploits by Frontier AI models at machine speed? We need to go beyond the CVSS, EPSS and KEV prioritization and understand exactly what vulnerabilities are a priority to your organization.
Building up an exposure management function within your vulnerability management program is a key way to tackle this. The function augments traditional vulnerability management by assessing the true risk across an organization's attack surface, which results in helping to prioritize remediation based on exploitability and business impact. It assists with drilling down into the vulnerabilities that need action as soon as possible and makes the largest impact to risk reduction in the organization. While this thought process is not new, it has jumped in its necessity as a staple in a VM program as a response to how quickly vulnerabilities are not only discovered but also turned into exploitable vulnerabilities based on Frontier AI models. Your vulnerability program needs to be able to articulate more clearly than ever what vulnerabilities need to be prioritized.
Additionally, exposure management broadens the landscape of a traditional vulnerability management program by looking not only at open vulnerabilities, but also other risk factors such as misconfigurations, reachability, and other sources of threat intelligence. This helps build a stronger prioritized risk picture for your organization. Exposure management broadens the toolsets needed to support the larger vulnerability management program using continuous monitoring, breach attack simulations, and automated pen testing to validate exposures. Now that your program is not using legacy vulnerability management risk indicators anymore, vulnerabilities are prioritized at an organizational level, helping to provide a strong response to the frontier AI threat.
Patch Management's Revolution
Patch management teams will be experiencing a revolution as well. Instead of just waiting for Patch Tuesday to work through testing and deployment of patches and having a process to deal with zero-day vulnerabilities, the velocity of patching and remediation will need to accelerate to match the machine speed at which vulnerabilities and exploits are identified. Patch management will need to shift to an automated patch identification, testing and deployment strategy utilizing a ring-based methodology to push patching to the next ring after the prior ring has been validated for stability. Introduction of automation at each step of the patching lifecycle will help reduce the time a vulnerability would be sitting unmitigated in an environment.
Importantly, patching teams have historically been required to rigorously reduce availability disruptions and maintain uptime requirements set by the business while deploying patches. Increasing patching velocity may disrupt this equilibrium and will force patching teams, in conjunction with security teams, to have hard conversations with key stakeholders in an organization on what uptime requirements look like in the age of machine speed identified vulnerabilities and exploits and increased patching frequency.
Do downtime requirements change? Does more investment go into resiliency efforts? How do integrations with BC/DR teams change and mature? While these conversations may be uncomfortable at first, they are necessary given the changing threat landscape. They should be done proactively, before the alternative arrives in the form of an increased velocity of cybersecurity incidents.
Bringing Your Vulnerability Program to the Next Level
In LDR516, we will be talking about and covering how your vulnerability program today may look very different to the vulnerability program of tomorrow. The time is now to bring your program to the next level across many different domains and key stakeholders, and we will equip you with all of the necessary actions to take once you return to your organization the following week.
I’m teaching two upcoming LDR516 course runs at SANS DC Metro September 2026 (Sept. 28-Oct. 2) and SANS Dallas 2026 (Dec. 7-11). I’ll see you there!
Register for SANS DC Metro September 2026 here.
Register for SANS Dallas 2026 here.
Note: This article has been expertly written and contributed By Kevin Garvey, SANS Certified Instructor.