Key Takeaways
- The exposure window – the time between a vulnerability becoming exploitable and its remediation – is the decisive metric for breach risk, not just the volume of discovered flaws.
- Attackers now operate on minute‑scale timelines (average eCrime breakout time ≈ 29 minutes), while most enterprises still follow day‑ or week‑scale remediation processes, creating a ~1,000‑to‑1 gap.
- Mythos (Anthropic’s AI‑driven discovery tool) did not create the exposure window; it amplified an existing bottleneck in the mobilization stage of vulnerability management.
- Mobilization – the handoff from security teams that identify a flaw to the operations/IT teams that patch or mitigate it – remains slow due to fragmented ownership, change‑window constraints, legacy systems, and lack of clear responsibility for non‑patchable findings (e.g., excessive privileges).
- Proactive security functions must adopt the speed‑based metrics traditionally used by SOC teams (dwell time, mean‑time‑to‑respond) because AI‑driven discovery puts both reactive and proactive on‑watch.
- Shrinking the blast radius – the set of critical assets reachable from an exploitable flaw provides a practical way to prioritize remediation when total closure of the window is impossible.
- Attack‑path analysis makes the blast radius visible, turning remediation speed into a direct business‑risk metric and helping organizations close the exposure window where it matters most.
Understanding the Exposure Window as the Core Risk Metric
The exposure window defines the period during which a vulnerability can be actively exploited before an organization applies a fix. In 2025, attackers can move from discovery to weaponization in minutes, with the average eCrime breakout time falling to 29 minutes. Yet many compliance frameworks, such as PCI DSS, still allow up to 30 days to remediate a critical vulnerability. This mismatch creates a roughly 1,000‑to‑1 disparity between attacker speed and expected defender response, leaving the exposure window wide open for potential breaches.
Mythos Did Not Create the Exposure Window; It Widened It
Before Anthropic’s Mythos reveal on April 7, vulnerability management programs were already strained. In 2025, 48,185 CVEs were disclosed—a 22 % increase over 2024—and projections point to 66,000 new CVEs in 2026. Most security teams were drowning in remediation backlogs, forced to process findings through manual approvals, fragmented ownership, and enterprise‑scale change windows that move at the pace of IT, not at attacker speed. Mythos, by dramatically accelerating AI‑driven discovery, added volume to an already clogged pipeline, thereby stretching the exposure window further rather than creating the problem anew.
Why Mobilization Is the Breaking Point of CTEM Programs
Mobilization—the step where a identified vulnerability is handed off to the team that must actually apply the fix—is where most programs falter. Security analysts may correctly prioritize a flaw, but the remediation action often resides with a separate IT or operations group that operates under its own priorities, change‑control windows, and approval chains. This handoff creates a soft underbelly: high‑ and critical‑application vulnerabilities take an average of 55 days to patch, and nearly half of enterprise vulnerabilities remain unpatched after a full year. Legacy systems, OT environments, and production infrastructure often delay fixes due to business‑impact concerns, while findings such as excessive privileges or cached credentials lack a straightforward patch and languish in queues without clear ownership.
Proactive Teams Now Operate on Reactive Timelines
Historically, security organizations split into two modes: reactive SOC teams tracking dwell time, mean‑time‑to‑respond, and containment speed; and proactive VM, cloud, and network teams measuring patch coverage or time‑to‑fix misconfigurations. AI‑driven discovery collapses this division. When vulnerabilities move from disclosure to weaponization in hours and breakout times are measured in minutes, a quarterly patch rate of 90 % is meaningless if critical assets remain exploitable for weeks while patches sit in a queue. Consequently, proactive teams must adopt the same speed‑centric metrics that SOC teams have long used—mean‑time‑to‑detect, mean‑time‑to‑remediate, and mean‑time‑to‑contain—to stay aligned with attacker timelines.
Accepting That the Exposure Window Will Never Fully Close
Given the inherent delays in mobilization, security leaders should shift from the unrealistic goal of eliminating every exposure to a pragmatic question: how far can we shrink the window, and when an attacker does slip through, how many critical assets can they reach? This mindset acknowledges that some exposure will persist but focuses effort on reducing the window to a size where the potential damage is manageable.
Shrinking the Blast Radius to Convert Speed into Risk Reduction
The blast radius—the set of critical assets reachable from an exploitable exposure—determines actual business impact. Not every vulnerability leads to a high‑value target; many are dead‑ends. Attack‑path analysis reveals which exposures open routes to crown‑jewel assets and which do not, allowing organizations to prioritize remediation on the finite set of paths that truly matter. By tracking how long critical assets remain reachable, remediation speed becomes a direct business‑risk metric. Mobilization then shifts from holding the exposure window open to actively closing it where it counts most.
Mythos Is Not the Culprit; Mobilization Is
Mythos did not break existing security programs; it merely exposed a pre‑existing weakness in the mobilization phase of vulnerability management. If organizations continue to let ownership gaps, change‑window bottlenecks, and legacy‑system constraints keep the exposure window wide, the volume of AI‑discovered findings will translate into real‑world breaches. Conversely, by recognizing mobilization as the key lever, adopting speed‑based metrics, and focusing attack‑path analysis on the blast radius, security teams can turn the tide—closing the exposure window enough to keep attackers from reaching the assets that matter most.
This summary reflects the contributions of Ryan Blanchard, Director of Product Marketing, XM Cyber, and is intended for informational use.

