← Blog

The window closes on a decision.

Gartner® published a research note on 24 September titled Modernize Exposure Management to Counter AI-Augmented Vulnerability Discovery. The full citation is at the foot of this page. We think Most of it is about what AI does to the attacker’s side of the clock.

The window closes on a decision.

Gartner® published a research note on 24 September titled Modernize Exposure Management to Counter AI-Augmented Vulnerability Discovery. The full citation is at the foot of this page. We think Most of it is about what AI does to the attacker’s side of the clock. One sentence is about the defender’s:

Gartner notes “Comparing internal response timelines with observed attacker behavior often highlights a mismatch: Attackers can take advantage of viable access paths quickly once conditions exist, while remediation cycles typically take days to weeks.”

We think days to weeks is the general case, and that in the cloud it is months. 53% of everything our customers’ scanners have ever detected is still open. A critical finding stays open 150 days on average. Both figures come from our State of Cloud Remediation 2026 research, 14.86 million detections across the cloud security platforms those customers already run, and both are worse than a year earlier, when they were 41% and 128 days.

That is not a backlog. It is a window, and it has been open for most of a year.

That is not a backlog. It is a window. Still open: 41% to 53%. Days a critical finding stays open: 128 to 150.

Why we feel it stays open

In our view, The note is specific about where the lag is:

Gartner states “While organizations are increasingly adopting AI to improve identification and prioritization, remediation processes remain largely human-centered and may struggle to keep pace with increasingly compressed attacker timelines.”

We believe remediation is human-centered for a reason, and the reason is not that people are slow. It is that a change in production has a name on it, and nobody approves a change a machine cannot explain. Automation was supposed to remove that wait. Mostly it moved it: the engine will make the change, a person has to be willing to switch the engine on, and the first wrong change is the last day it stays on.

So we think the question is not how to take the human out of remediation. It is what a machine has to show before a human lets it act.

From a ranking to a decision

We think The note’s answer to the backlog is to stop ranking it:

Gartner says “Exposure prioritization must evolve from an ordering exercise into a discipline that shapes decisions about where to act, where to defer and where to seek additional confidence before expending effort.”

We think those three decisions are exactly what a verdict is. Our engine gives every finding one of three. SAFE is where to act. AWAITING DATA is where to seek additional confidence, and the engine names the one fact it is waiting for. RISKY is where to defer.

From a ranking to a decision. SAFE: where to act. AWAITING DATA: where to seek additional confidence, and the engine names the one fact it is waiting for. RISKY: where to defer.

The difference is who decides. Deferring has always been a person’s call, made after the tool has ranked. We believe the machine has to be able to make that call too, and to make it in writing: a change it cannot prove safe is declined, and the decline comes with what the engine read, the reason in a sentence an engineer can argue with, the one fact that would change the verdict, and how to do the work by hand. Six fields, the same six it writes when it acts.

A decline with the instructions attached moves the work. A decline without them moves the blame.

Where change management permits

On automating the change itself, in our opinion note sets one condition:

Gartner states “Trigger remediation, configuration fixes, compensating controls or predefined response actions where risk and change-management requirements permit.”

We think that condition is the whole product problem. Change management permits what it can audit. So we built the engine the way change management would have: read-only first, allowed to act one class of finding at a time on that class’s record, and a receipt on every decision, the refusals included. An audit trail that only records the yes is not an audit trail.

What it looks like

Six storage buckets, identical in the scanner: same alert, same severity. The engine read what depended on each, who owned it, what had changed, what the traffic said. Three closed through the customer’s own change process, rollback ready. Two were declined, in writing, over a live dependency the scanner could not see. One became a question, because the owner was unknown and the engine does not guess.

Six storage buckets, identical in the scanner. Three closed, two declined, one became a question.

Over four quarters, one customer’s quarterly reviews went from 6,074 open findings to 2,041, with 93% fewer new alerts arriving each quarter by the end. A system that mostly says no cannot produce that curve. A system that cannot say no should not be allowed to try.

From 6,074 open findings to 2,041.

How to check anyone in this category, including us

Show me a change your system declined, end to end: what it read, why it stopped, what would have changed its mind, and what my team got back when it did not act.

If the answer is a skipped row in a table, the product ranks. It does not decide.

Gartner, Modernize Exposure Management to Counter AI-Augmented Vulnerability Discovery, Mitchell Schneider, Jonathan Nunez, 24 September 2026.

GARTNER is a trademark of Gartner, Inc. and/or its affiliates. Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

Notes from the Healing Gap.

Teardowns, CTF write-ups and field notes from the people who close cloud findings for a living.

You're subscribed.

That did not go through. Try again, or write to [email protected].

At most one email a month. Unsubscribe from any of them.