Companies keep getting breached by vulnerabilities they already knew about

Source: Help Net Security

Author: Mirko Zorz

URL: https://www.helpnetsecurity.com/2026/07/16/ciso-vulnerability-remediation-gap/

ONE SENTENCE SUMMARY:

Despite improved vulnerability discovery, organizations struggle with ownership, handoffs, and verification, causing delayed remediation and incidents from known weaknesses.

MAIN POINTS:

  1. Vicarius surveyed 300 US/UK IT and security leaders at mid-sized organizations.
  2. Human effort remains central, with 58% of remediation requiring direct intervention.
  3. Only 7% fully remove people from remediation workflows across sizes and industries.
  4. Separation between discovery and fixing teams prevents consistent same-team remediation for 82%.
  5. Multiple handoffs and ambiguous ownership frequently stall remediation decisions and execution.
  6. Opening Jira/ServiceNow tickets is the most common first response to critical findings.
  7. About a quarter can trigger automated remediation directly from their platform.
  8. Fully closed-loop remediators use one platform, grant frontline authority, and require verified rescans.
  9. 79% suffered incidents tied to previously known vulnerabilities, often lingering 30–90 days.
  10. Verified-rescan “done” correlates with fewer incidents than softer closure definitions.

TAKEAWAYS:

  1. Reducing handoffs and clarifying accountability may speed fixes more than improving scanning.
  2. Consolidating discovery-to-verification into a single platform enables consistent remediation execution.
  3. Granting frontline teams authority to implement fixes eliminates approval bottlenecks.
  4. Treating “fixed” as “verified by rescan” materially lowers known-vulnerability incident rates.
  5. Competing priorities and change-management friction are the dominant barriers to timely remediation.