Cybersecurity is operating on the wrong clock
Wed, 23rd Sep 2026 (Today)
Every Cyber Security Awareness Month, organisations are told to patch their systems, train their people, use strong authentication and stay alert to suspicious activity. It's good advice - but it's no longer enough.
This year, the message carries extra weight: the Australian Signals Directorate's inaugural Cyber Action Year 2026 calls on organisations to move from awareness to action - less annual reminder, more year-round discipline.
Cybersecurity is operating on the wrong clock. Attackers think in minutes, IT teams work in patch cycles, and boards review risk quarterly. For years the answer has been patch faster, hire more, work the backlog. But the backlog is now a continuously evolving exposure window, weaponised faster than most teams can respond.
At some point, working harder stops being a viable strategy.
The exposure window has changed
Research conducted by our Qualys Threat Research Unit (TRU) shows how wide the gap has become. Across more than one billion CISA Known Exploited Vulnerability remediation records, the volume of closed vulnerability events grew 6.5 times in four years, from around 73 million in 2022 to 473 million in 2025. At the same time, average Time-to-Exploit has collapsed to negative one day, meaning adversaries are routinely weaponising vulnerabilities before they are publicly disclosed.
Security teams aren't asleep at the wheel - many are closing more vulnerabilities than ever. The work has simply outgrown the operating model and they are simply outnumbered.
When exploitation can happen before disclosure, mean time to remediate no longer reflects true exposure - it tells you how long a fix took, not how long attackers had a usable opportunity.
That is why Qualys TRU introduced a new metric - Average Window of Exposure (AWE) – that measures the time from exploitation to remediation. Attackers control the Window of Weaponisation. Defenders control the Window of Exposure.
From zero-day vulnerabilities to zero-day remediation
Not all patching is equal, especially as frontier AI speeds up how fast attackers find and exploit weaknesses. The job is to shrink the exposure window for the risks that matter most: vulnerabilities on assets critical to revenue, operations, customer trust and regulatory obligations.
This is why the conversation needs to shift from zero-day vulnerabilities to zero-day remediation. Organisations need the ability to identify, prioritise and safely act on critical exposures before they become business incidents.
Many organisations still treat vulnerability management as a volume problem - how many vulnerabilities did we find, how many tickets did we close. Those are activity metrics. They don't prove risk reduction.
A low-severity issue on a mission-critical system may matter more than a high-severity vulnerability on an isolated asset. Without business context, teams can do a lot of work without reducing the risk that keeps the board awake.
You cannot hire your way out of machine-speed risk
The natural response to growing workload is to ask for more people. Extra capability sometimes helps, but headcount alone won't solve a machine-speed problem.
As our CEO put it: when boards ask CISOs how they'll respond to autonomous AI exploits, the answer cannot be, "I'm going to hire 100 more people." You can't outpace autonomous offence with manual defence.
Resourcing pressures are real - but the answer is using the budget already committed more effectively by consolidating fragmented visibility, prioritising the exposures that create real business risk, and automating remediation where it's safe to do so.
Security leaders need to show value, not just activity. A cybersecurity leader I spoke to recently described cutting mean time to detect from 26 hours to a couple of hours. That is not just a technical improvement – it is a board-level proof point that investment is changing the organisation's risk position.
Speed and context are non-negotiable
Many organisations have plenty of tools - too many. The issue isn't a lack of data. It's that data is fragmented across platforms, teams and reporting lines, so high-severity alerts rarely reach the remediation team with business context attached.
The recent Mathspace breach shows why. Public reporting indicates attackers accessed an internal reporting system while a security patch sat uninstalled, affecting more than one million people across Australia and New Zealand. The lesson isn't to patch everything instantly - that's unrealistic, and often reckless. It's that critical advisories need to be detected, contextualised, escalated and remediated fast enough to stop an exposure window becoming a business incident.
This is why organisations need to move from fragmented visibility to integrated risk operations. A Risk Operations Centre brings together asset intelligence, vulnerability data, threat intelligence, business context and remediation workflows, so teams can focus on what matters most and use autonomous remediation to act faster. It's not about replacing human expertise - it's using people where they add the most value, while machines correlate signals, recommend action, automate trusted workflows and verify whether risk has actually been reduced.
This Cyber Security Awareness Month, the message for Australian organisations should be simple: don't just manage vulnerabilities - manage exposure. Don't just measure effort - measure risk reduction.
The old model asked: how many vulnerabilities did we close? The new model should ask: how much business risk did we remove, and how quickly?
Attackers aren't waiting for the next patch cycle, board meeting or budget approval. Organisations need to find and reduce the risks that matter before attackers get there first.