Vulnerability management in the AI age – Focusing on the risks that matter.
The number of disclosed vulnerabilities continues to rise each year, but the volume of reports is not the greatest challenge for companies. What matters is their ability to identify the risks that genuinely affect them and take the right action quickly.
Key takeaways.
-
A rise in disclosed vulnerabilities does not automatically mean greater risk. The priority is to determine whether your environment is affected and respond in the right order.
-
AI can help defenders identify existing security issues more quickly.
-
Effective vulnerability management depends on asset management, risk assessment and consistent patching, including virtual patching.
More than 40,000 new vulnerabilities were disclosed worldwide in 2024, an increase of 39% year on year. Yet a higher number of disclosures does not necessarily translate into greater risk. What matters is whether a company’s environment is affected and how likely the vulnerability is to be exploited. The ability to assess risks quickly and determine the appropriate response is therefore becoming increasingly important, particularly as only a small proportion of known vulnerabilities are ever used in attacks.
AI brings hidden vulnerabilities to light.
Artificial intelligence is often seen as a key factor behind the growing number of security flaws being discovered. The issue has become particularly relevant now that AI can identify vulnerabilities in software, hardware and infrastructure at low cost and machine speed, performing work that once required highly specialised experts. In the hands of attackers, however, the same technology can not only find vulnerabilities but also develop ready-to-use exploits.
Rather than creating entirely new attack vectors, AI often exposes existing weaknesses faster and on a much larger scale. Modern analysis tools can scan extensive IT environments in very little time, uncovering vulnerabilities that might previously have gone undetected, but attackers and defenders have access to the same technological capabilities. For companies, the critical question is therefore not what is driving the surge in reported vulnerabilities, but how quickly they can identify and assess the risks and put effective safeguards in place.
Prioritising risk.
The growing number of disclosed vulnerabilities makes effective vulnerability and exposure management more important than ever. A robust approach combines technical safeguards with clearly defined processes for testing, patching and reporting as part of professional risk management. Every assessment begins with visibility. Companies need an accurate inventory of the systems and applications in use before they can determine whether a newly disclosed vulnerability affects their environment and evaluate the actual risk. Technical severity is only one consideration. Exposure, likelihood of exploitation and existing security controls are equally important. The aim is to direct limited resources towards the vulnerabilities that pose the greatest threat.
Visibility is essential.
Bechtle combines automation with specialist expertise to support this approach. Vulnerability scanning, the consolidation of relevant security information and ticket creation can largely be automated, while security specialists remain responsible for assessing and prioritising the findings.
Effective vulnerability management also depends on an up-to-date inventory of every system and application in use. Without it, organisations cannot reliably determine whether a vulnerability affects their environment. Software bills of materials (SBOMs) are becoming increasingly important, providing visibility into software components and enabling organisations to assess their exposure quickly. In complex IT landscapes, such insight can be crucial to identifying risks early and mitigating them effectively.
The advantage no longer lies in patching first, but in being the first to assess the risk correctly, make the right decision and take action.
Patrick Pötz, Team Lead Information Security, Bechtle Austria
Regulation increases the pressure to act.
Alongside technological developments, regulatory requirements are driving demand for professional security services. Regulations such as NIS2, DORA, the Cyber Resilience Act and the AI Act are also increasing the pressure on organisations to manage cyber risk more systematically. Meeting these requirements is not a matter of introducing isolated short-term measures, but of continually implementing reviewing and improving security across the organisation.
Less time to respond.
As the interval between the disclosure of a vulnerability and its exploitation continues to shrink, companies may have only a few hours to act. An effective response therefore depends on automated processes, reliable data and clear lines of responsibility that allow risks to be assessed and appropriate action taken without delay.
AI is expected to help make digital products more secure by revealing vulnerabilities earlier, but the proliferation of cloud platforms, SaaS applications, connected devices and AI systems is also expanding the attack surface. Ultimately, IT decision-makers will not be judged by how many security tools they deploy, but by the quality of the processes, data and decisions behind them.