Intelligent CISO Issue 100 | Page 40

f

e

a

t

u

r

e

The age of managing vulnerabilities at human speed has ended. The real question is:‘ How fast can you embrace and trust autonomous remediation?’
There are no firewall rules to interpret and no policies to maintain. The restriction is absolute.
As AI adoption accelerates, organisations that succeed will not be those that block innovation or pursue it without restraint. They will be those that redesign their architectures from the outset, ensuring intelligence can flow in while risk is structurally designed out.
Shailesh Athalye, Senior Vice President, Product
Management, Qualys
When Anthropic partnered with other tech leaders under Project Glasswing to release Claude Mythos as an autonomous discovery tool for vulnerabilities, it could operate at speeds that even experienced human analysts would find impossible. We can be certain that CVE disclosures are about to surge and add to an already long backlog. However, just because a tool identifies a vulnerability doesn’ t mean it poses a risk in your environment.
The light at the end
Applying fixes takes time. Organisations do not have unlimited resources to patch everything. The good news is, you don’ t have to patch everything. Instead, organisations need to employ hyperprioritisation, determined by a combination of threat, business and asset context.
The next vital step is exploit validation. Even if you have a known exploitable vulnerability that exists in a business-critical asset, it might not be exploitable in your unique environment given existing security controls. Therefore, it’ s crucial to validate exploitability against compensating controls, and do so at machine speed.
Here’ s where AI can come in to help cyberdefenders move at scale and speed. AI-backed adversaries will not wait while we examine the problem from multiple angles. Defenders must eliminate legacy workflows of handoffs between detection, triage, ticketing, human investigation and change management. We must move from discovery to context-aware prioritisation to effective remediation. The lag between confirmed discovery of a business risk and its resolution is the only metric that should matter in today’ s threat landscape.
Finally, now that we have narrowed down the deluge of exposures to the sub-one percent that actually need to be fixed, organisations need to be judicious about which of these can be patched autonomously and which need to be mitigated in other ways. Autonomous remediation is the only way to combat the influx of exposures from AI.
Trust is earned
Given the scepticism around autonomous remediation, we must build a trust infrastructure that makes autonomy safe enough for enterprisescale operation by testing the reliability of patches before they are autonomously deployed.
Organisations can do so by allowing AI agents to trace the attack path in the live environment without disrupting production. There are also other options for mitigations, such as for zerodays when either the patch is not yet available or patching is operationally impractical.
It is also worth discussing how best practices in AI-powered vulnerability management extend to custom applications and all the IDEs, APIs and other tools and services used in their construction.
No matter how a software flaw is found, the organisation must be able to detect it in a production environment, validate its business risk and mitigate it just as quickly as it would a critical third-party vulnerability. Increasingly, enterprises are relying on the Risk Operations Center( ROC) model to deliver AI-powered risk management. I see this operationalisation as the defining cybersecurity challenge of 2026.
AI-driven discovery of software vulnerabilities is an undeniable leap forward. But in dealing with what comes after discovery, we must prioritise with context, not legacy scoring systems. Design your risk management approach and workflow around what makes sense to your unique business and AI will take its place as a valued tool and a game changer for cybersecurity.
The age of managing vulnerabilities at human speed has ended. The real question is:‘ How fast can you embrace and trust autonomous remediation?’
40 WWW. INTELLIGENTCISO. COM