Qualys TRU remediation report: Risk operations centre to scale autonomous security

Bharti Trehan
Bharti Trehan
Qualys TRU remediation report: Risk operations centre to scale autonomous security

The traditional "scan-and-patch" model of cybersecurity has hit a "human ceiling." According to a groundbreaking report from the Qualys Threat Research Unit (TRU), titled "The Broken Physics of Remediation," the volume and speed of modern threats have fundamentally outpaced human capacity to respond.

Analysing over one billion CISA Known Exploited Vulnerabilities (KEV) records across 10,000 organisations between 2022 and 2025, the study reveals that while the number of closed vulnerabilities skyrocketed from 73 million to 473 million, actual security outcomes worsened.

1. The average window of exposure (AWE)

The report argues that Mean Time to Remediation (MTTR) is a flawed metric because it measures response speed rather than the total duration a system is vulnerable. Qualys introduces the Average Window of Exposure (AWE), which tracks the full lifecycle from exploitability to full remediation.

The data shows a terrifying reality: Time-to-Exploit (TTE) has dropped to -1 day. This means vulnerabilities are being weaponised before patches are even available. At the moment of public disclosure, 85% of assets remain unpatched, and nearly 12% stay exposed for more than 90 days.

2. Measuring risk mass

To quantify the danger of persistent exposure, Qualys introduced Risk Mass. This is calculated by multiplying the number of vulnerable assets by the number of days they remain exposed (exposure-days).

  • Example: A vulnerability affecting 400 assets closed in one day results in 400 exposure-days.

  • Contrast: The same vulnerability left open for 100 days results in 40,000 exposure-days, representing a massive accumulation of risk.

3. The solution: The risk operations centre (ROC)

The report concludes that the only path forward is the Risk Operations Centre (ROC), an automated pipeline that manages remediation at machine speed. A ROC is built on three pillars:

  • Embedded Intelligence: Automatically processing threat data into decision-making logic.

  • Active Confirmation: Using exploit-based validation to filter out "theoretical" risks and confirm actual exploitability.

  • Autonomous Action: Executing policies like automated patching or asset isolation without manual intervention.

Expert Perspectives

Sumedh Thakar, President and CEO of Qualys,shared his exclusive statement over this report, “The threat landscape has fundamentally shifted, and the defences most organisations rely on were not built for what comes next. Every generation of cybersecurity emerged in response to a platform shift. New technology created new risks, and defenders adapted. That cycle was linear and survivable. What is emerging now is not another platform shift. It is the first time the adversary itself is becoming autonomous. 

Today, offensive agents can discover, weaponise, and execute faster than any human-staffed operation can respond. The defensive side must make the same transition,  and this report measures the cost of every day the transition is delayed. The remediation requires a foundational architectural shift away from reactive human triage and toward a Risk Operations Centre (ROC) that fuses embedded intelligence, deterministic confirmation of actual exploitability, and autonomous remediation into a single operational loop.

The data in this report validates that reality across more than one billion CISA KEV remediation records spanning 10,000 organisations over four years. The average Time-to-Exploit has collapsed to negative one day, with adversaries weaponising vulnerabilities before patches even exist. 

Critical vulnerability volume has surged 6.5x, yet the percentage still open at Day 7 and Day 30 has worsened. Of the 52 high-profile weaponised vulnerabilities we tracked with complete exploitation timelines, 88% were remediated more slowly than they were exploited. Half were weaponised before public disclosure.”

Saeed Abbasi, Head of TRU at Qualys, added: “The attacker’s timeline is the only one that matters, and that timeline is predictable. This reinforces the need to rethink remediation as an operational capability that can keep pace with how threats actually evolve.”

Conclusion

The Qualys report serves as a wake-up call for the enterprise. In a world where attackers operate in "negative time," relying on human-driven remediation is a structural failure. The future of risk management must be autonomous, evidence-based, and focused on reducing Risk Mass before the window of exposure becomes a door for adversaries.

Read More:

MSP Market is Majorly Driven by AI Adoption : Rajesh Chhabra, Acronis

Cloud Security India: How Upwind is building a partner-first runtime security model

Inside the rise of managed cybersecurity services and recurring growth

Managed security services: How partners are becoming cyber risk owners

Latest Stories