Vulnerability Remediation Gap: 79% Breached by Known Weaknesses

A security analyst sits at a desk, focused on a monitor

Most security teams track their vulnerabilities carefully. Most get breached by them anyway. Vicarius, the vulnerability remediation platform provider, surveyed 300 IT and cybersecurity leaders for its 2026 State of Vulnerability Remediation report. It found that 79% experienced a security incident last year tied to a weakness already in their inventory, and how a team defines done is the variable that best predicts whether it gets breached.

  • 58% of all remediation activity still requires direct human intervention; only 7% of organizations have removed people from the loop entirely.
  • 82% of organizations cannot close a vulnerability inside the team that found it. Every fix depends on a handoff, and 38% of respondents say ownership is situational or outright ambiguous.
  • Organizations that define “remediated” as a verified rescan had a 65.8% known-vulnerability breach rate. Every looser definition clustered between 89% and 93%, nearly 40% higher.
  • Tightening that definition, not buying more scanning tools, is what separated the small group that eliminated manual remediation from the rest.

79% Breached by Vulnerabilities Already in Their Inventory

The 300 leaders Vicarius surveyed came from companies with 500 to 2,000 employees, spanning financial services, healthcare, manufacturing, government, and IT services. The pattern held everywhere. Detection improved substantially over the past decade. The systems built to fix what detection finds did not keep pace.

When a critical vulnerability surfaces, the most common first move for 42% of respondents is opening a ticket in a workflow system like Jira or ServiceNow. That ticket tracks the work. The exposure stays open. Only 25% deploy an automated remediation action directly from their platform. The rest hand the finding to someone who may lack the context, tooling, or authority to act quickly, and the window stays open while they sort it out.

Roi Cohen, CEO of Vicarius, put the core finding plainly: “The difference between the organizations getting breached by vulnerabilities they already knew about and the ones that never are isn’t better detection. It’s whether ‘done’ means the exposure is gone, or just that someone wrote it down.”

Why Vulnerability Remediation Stalls: Ownership Gaps, Not Missing Tools

The pipeline breaks at the handoff. In 82% of organizations, the team that identifies a vulnerability cannot consistently fix it without looping in someone else. Responsibility moves from group to group, each transfer adding delay. More than a third of respondents say ownership depends on the situation or has no clear home at all. Vulnerabilities enter a fix workflow with no defined path to resolution before anyone has started working.

Six of the top seven barriers cited in the Vicarius report are organizational: competing priorities, approval steps, unclear ownership, change-management friction, and coordination across teams. Insufficient tooling ranks fourth. Remediation loses priority battles to outages, projects, and business demands in settings where it has no protected time. Teams have built strong detection pipelines and never finished the pipeline for acting on what those pipelines find.

Leadership perception compounds this. 62% of leaders rate their remediation program as somewhat or very mature. Directors are most likely to call it very mature at 29%; VPs, the layer closest to day-to-day operations, are least likely at 13%. The people with the clearest view of what vulnerability remediation looks like day to day are the most cautious about calling it mature. Programs are better at producing dashboards than at closing exposures. We have covered related patterns, including why traditional vulnerability management fails in cloud environments where asset inventories shift faster than remediation workflows can track.

Three Traits That Closed the Vulnerability Remediation Gap

A small set of organizations in the Vicarius sample, just 20 out of 300, eliminated manual remediation entirely. Their path was consistent. Cohen noted: “This isn’t a group that got there through different paths. It’s the same path, taken by everyone who arrived.” Three traits defined every one of them. First, each ran the entire pipeline through a single platform from discovery to verified closure, compared to an average of three tools across the wider sample. Second, frontline teams had authority to fix findings without escalating for approval, a setup fewer than one in five organizations report. Third, all required verified rescan as the definition of done.

That third point drives the breach-rate gap directly. Organizations closing findings only on verified rescan sat at 65.8%. Every group using softer signals, such as a patch deployed with no confirmation, a ticket assigned, or a risk accepted by leadership, clustered between 89% and 93%. Teams applying the loosest definitions were nearly 40% more likely to be breached by a weakness already in their inventory. The definition of fixed is a better predictor of breach exposure than tooling, headcount, or self-assessed maturity score.

Here is what that means operationally. The sequence matters because each step enables the next.

Redefine done as verified rescan, not ticket closure – The 65.8% versus 89-93% breach-rate gap is too wide to be noise. Audit how your program currently closes a finding: if a ticket marked resolved counts as remediated, your incident rate is tracking with the higher group regardless of how mature the rest of your process looks.

Give the identifying team authority to fix without a handoff – With 82% of organizations routing fixes through multiple groups and 38% reporting ambiguous ownership, the bottleneck is governance design, not tooling. Mapping where authority to close a finding actually lives, and compressing that path, is the structural fix the scanning budget cannot buy.

Consolidate to one platform covering discovery through verified closure – The 20 organizations that closed the loop each ran one end-to-end platform against the sample average of three. As AI shortens attackers’ exploitation window, every platform boundary in the fix chain is a gap that stays open longer than it needs to. The organizations on Cohen’s single path arrived by eliminating those handoffs, not by adding another tool to the stack.

Join our LinkedIn group Information Security Community!

Holger Schulze
Holger Schulze is the founder and publisher of Cybersecurity Insiders, an independent cybersecurity research and media company. He writes about how AI is reshaping cybersecurity, where attackers are moving faster than defenses, and what security leaders can do about it. His work draws on original research and real-world incidents, translating both into practical guidance for security teams. Holger moderates the Information Security Community on LinkedIn, one of the largest professional networks in cybersecurity. Connect at linkedin.com/in/holger-schulze

No posts to display