CyberVoices - Cybersecurity News

Cybersecurity Has a Prioritization Problem. AI Is About to Make It Worse

Written by Francois Guay | Sep 1, 2026, 10:25:27 AM

Companies are drowning in vulnerabilities, spending heavily on security and facing attackers moving faster than ever. Open Security founder Matthew Toussain argues the real advantage now comes from knowing which risks matter.

For years, the cybersecurity industry has operated on a relatively simple assumption: find more vulnerabilities, fix more vulnerabilities and organizations will become more secure. Matthew Toussain thinks that assumption is increasingly wrong.

The founder of Open Security has spent years breaking into systems, responding to cyber incidents and helping organizations understand how attackers operate. His conclusion is uncomfortable for an industry built around finding problems and selling solutions. Businesses do not necessarily need more security information or another dashboard showing thousands of weaknesses. They need a much better way of determining which weaknesses can hurt the business.

That distinction is becoming more important as artificial intelligence accelerates software development and vulnerability discovery while organizations contend with expanding attack surfaces, growing security budgets and more technology than their teams can reasonably assess. The industry can already identify far more potential problems than most companies could ever fix.

“We still cared exclusively about that needle,” Toussain told me. “Find the needles, don’t add more hay.”

The 50,000-vulnerability problem

Consider the numbers. Toussain points to roughly 50,000 new Common Vulnerabilities and Exposures reported last year, while the actual number of weaknesses across software environments is considerably larger. Yet no serious attacker is incorporating 50,000 new techniques into an arsenal every year, and no security team could intelligently respond to that volume either.

That creates an important distinction between what is technically vulnerable and what represents meaningful business risk. Toussain argues that organizations should be asking whether a vulnerability is exploitable, whether attackers are using it and whether the affected system matters enough to the business to warrant immediate attention.

“The real question isn’t should we fix vulnerabilities,” he said. “The question is which vulnerability should we fix.”

The broader security establishment is increasingly acknowledging the same problem. The U.S. Cybersecurity and Infrastructure Security Agency maintains a Known Exploited Vulnerabilities catalogue specifically to identify vulnerabilities for which there is evidence of active exploitation and recommends organizations use it as an input into vulnerability management prioritization.

The message is important. A vulnerability can be technically severe without representing the most urgent business risk.

In practice, much of cybersecurity still rewards discovery rather than prioritization. Thousands of vulnerabilities can appear on corporate dashboards, many carrying high or critical ratings, creating enormous remediation backlogs. Security teams can spend considerable time eliminating weaknesses that may never be exploited while the vulnerability that matters remains buried somewhere inside the noise.

That is no longer simply a technical problem. It is a capital allocation and management problem.

Attackers are compressing the clock

The consequences become more serious when vulnerability volume is combined with another trend Toussain is watching closely: vulnerability velocity. The important measurement is increasingly not how many vulnerabilities exist, but how quickly a consequential vulnerability moves from discovery to exploitation.

Rapid7 provided striking evidence of that shift in its Attack Intelligence Report. It found that 53 per cent of new vulnerabilities associated with widespread attacks during its study period were exploited as zero days. It also found significant exposure among network and security appliances; the very technologies organizations frequently rely upon to protect their environments.

 

"53 per cent of new vulnerabilities associated with widespread attacks during its study period were exploited as zero days"

Rapid7

 

That helps explain why Toussain believes vulnerability velocity deserves much more attention from executives.

He has seen the consequences firsthand. One organization he worked with suffered a ransomware attack after attackers exploited a vulnerability in its internet facing firewall. The company had an annual penetration testing contract, but did not have continuous vulnerability scanning. Its penetration test provided a periodic snapshot of security. The attackers operated on a clock measured in days.

When the organization later asked what it could have done differently, Toussain found the answer unsatisfying: it could have spent more money. That experience helped drive the development of Sirius Scan, the open-source vulnerability scanner he has worked on for approximately six years. Its original purpose was straightforward: give organizations continuous visibility into vulnerabilities without making the ability to purchase another commercial product a prerequisite for basic security.

 

| THE SIGNAL: Vulnerability velocity is becoming a business risk|

 

The number of vulnerabilities is becoming less important than the speed at which consequential vulnerabilities move from discovery to exploitation. Rapid7's finding that 53 per cent of new vulnerabilities associated with widespread attacks were exploited as zero days is an important indicator, particularly as AI reduces the cost and time required to analyze software and identify weaknesses.

For business leaders, the implication is significant. Cybersecurity strategies built around finding and fixing everything become less effective as vulnerability volume and exploitation speed increase. The advantage shifts toward organizations that can identify the relatively small number of exposures capable of materially disrupting the business and act on them faster.

AI is changing the economics

There is enormous attention being paid to whether AI will create entirely new classes of cyberattack. Toussain believes that framing can distract executives from what is already happening. Attackers are using AI, but many of the most effective applications are relatively ordinary: improving language, producing more convincing resumés, strengthening social engineering and helping malicious actors impersonate legitimate workers.

North Korean threat actors provide a useful example. AI can improve written English, alter voices and make fraudulent job candidates appear more convincing. None of those techniques represents a science fiction version of autonomous cyberwarfare. They simply make existing forms of deception cheaper, faster and more scalable.

Where Toussain becomes more concerned is the ability of AI to accelerate vulnerability discovery and exploitation. AI does not have to invent a fundamentally new form of hacking to change the economics of cybersecurity. If it materially compresses the time between discovery and exploitation, corporate security processes designed around slower assessment, prioritization and remediation cycles may no longer keep pace.

This creates a paradox for business. AI can help defenders identify vulnerabilities and analyze threats more quickly, but those same economics apply to attackers. The result may be a security environment where both sides have more intelligence and more automation, but dramatically less time to act.

The real gap may be between engineers and executives

Perhaps Toussain’s most interesting argument has little to do with technology. Ask executives why cybersecurity fails, and the answer often points toward employees who click malicious links, engineers who miss vulnerabilities or systems that were improperly configured. Toussain sees a broader organizational weakness: the communication gap between technical teams and leadership.

Engineers understand technical weaknesses. Executives understand capital allocation, operations and enterprise risk. Between them sits the difficult job of translating one language into the other. Toussain believes that middle layer is frequently where organizations struggle, leaving executives without a clear understanding of which technical issues translate into material business risk.

When that translation fails, executives can make perfectly rational decisions based on badly prioritized information. A major attack makes headlines, senior leaders hear about it, vendors arrive with solutions and money begins moving toward the newly visible problem. The threat may be legitimate, but it may still have little relationship to the organization’s most important exposure.

Toussain jokingly blames “salespeople” for organizations continuing to fail at security fundamentals, but there is a serious business point underneath the provocation. Cybersecurity spending can become influenced by what is newest, easiest to explain or easiest to sell rather than what is most important to fix. In an industry where fear creates urgency and urgency creates budgets, that distinction matters.

Trust becomes part of the security architecture

This communication problem helps explain why independent expertise becomes more valuable as cybersecurity grows more complicated. Toussain frequently finds himself speaking separately with technical teams and senior executives inside the same organization, only to discover that much of his role consists of translating what each group is already trying to tell the other.

His advantage is not necessarily access to information they lack. It is trust. He has no internal budget to defend and, in those conversations, no technology purchase to justify. That independence allows him to serve as an intermediary between people who understand different parts of the same problem but lack a common language for discussing it.

The issue becomes more important in the AI economy. Executives are facing an extraordinary volume of vendor claims, automated analysis, threat intelligence and machine generated recommendations. AI itself can help organizations research and challenge those claims, but so can independently research, trusted industry peers and credible third parties. The objective is to establish enough trusted intelligence that leaders can distinguish a meaningful signal from a compelling sales pitch.

When the employee and the machine share an identity

AI is also beginning to challenge one of cybersecurity’s most basic assumptions: that organizations can identify who is performing an action. Historically, identity and access management has distinguished relatively cleanly between people and machines. Employees require broad and changing permissions because their work is unpredictable, while traditional machine identities can be tightly constrained because their functions are predetermined.

AI agents complicate that model. An autonomous agent can operate using a person’s permissions while making decisions and taking actions on that person's behalf. As agents gain access to corporate email, documents, applications and business processes, security teams may increasingly confront an uncomfortable question during an investigation: did the employee perform the action or did an AI agent acting with the employee’s authority perform it?

Toussain argues that this makes entitlements, essentially who or what has permission to access systems and information, part of the new corporate security perimeter. The edge of the enterprise was once the firewall, then increasingly the employee. In an agentic AI environment, it may be the permissions themselves.

The implications extend beyond the security department. Companies rushing to automate business processes with AI will need to understand not only what their agents can do, but what corporate authority those agents inherit when they act on behalf of humans.

Cyber insurance could become a powerful security lever

There is another force capable of changing corporate behaviour that receives considerably less attention: insurance. Toussain argues that cyber insurers can become an important mechanism for turning better security into a direct economic incentive, particularly if insurers become better at measuring which controls reduce losses.

He recently taught a course attended by representatives of a European insurance company wrestling with a practical problem. They wanted to reward customers with stronger security practices, but requiring an expensive penetration test could simply push customers toward competitors with fewer requirements. The opportunity was to find a lower cost method of establishing whether an organization was exercising reasonable security diligence.

The insurance market is already evolving beyond simply paying claims after an incident. Coalition's 2026 Cyber Claims Report, based on more than 100,000 policyholders, reported that 86 per cent of businesses affected by ransomware in 2025 refused to pay a ransom and that 64 per cent of closed claims resulted in not out of pocket loss for policyholders. The numbers point toward an increasingly important relationship between prevention, incident response and financial risk transfer.

Open-source tools potentially add another dimension. If insurers can inexpensively assess meaningful security practices, companies demonstrating stronger controls could receive better terms while organizations ignoring basic protections pay more. Instead of merely compensating businesses after cyber incidents, insurers could increasingly influence behaviour before those incidents occur.

That would make cyber insurance more than a financial backstop. It could become a market mechanism for better security.

Cybersecurity becomes a capital allocation decision

The temptation when looking at AI, ransomware, zero days, autonomous agents and accelerating vulnerability discovery is to conclude that businesses simply need dramatically more cybersecurity. Toussain’s argument points somewhere more useful. Businesses need better prioritization, better communication and better intelligence about where technology risk intersects with business risk.

That changes the conversation at the executive and board level. Every organization has finite money, people and time. If AI dramatically increases the number of vulnerabilities that can be discovered while simultaneously reducing the time attackers require to exploit important ones, attempting to eliminate every technical weakness becomes economically unrealistic.

Companies instead need to know which vulnerabilities are exploitable, which systems are genuinely important, which identities possess dangerous permissions and which security investments materially reduce their exposure. Technical teams then need to communicate those realities to executives in language that can survive the journey from the security operations centre to the boardroom.

AI will almost certainly discover more vulnerabilities. Attackers will exploit some of them faster. The cybersecurity industry will produce more products promising to stop them. All of this will create an extraordinary amount of additional information for business leaders to process.

The organizations that gain an advantage may not be those that see the most threats. They may be the ones that get much better at knowing which one’s matter.

You can connect with Matthew here.