The State of Play

A living index of AI adoption across industries — where established practice meets the bleeding edge
UPDATED DAILY
← 🛡️ IT Operations & Security

Vulnerability & attack surface management

GOOD PRACTICE— Steady

194 evidence items

AI that continuously scans for vulnerabilities, monitors the attack surface, and prioritises remediation based on exploitability and exposure. Includes risk-based vulnerability ranking and external attack surface discovery; distinct from penetration testing which actively attempts exploitation.

Overview

Vulnerability and attack surface management has matured into a proven operational discipline with GA tooling, analyst recognition, and documented ROI. The question facing most organisations is not whether to adopt it, but how to close the persistent gap between discovery and remediation. Platforms from Qualys, Rapid7, and Tenable can surface thousands of vulnerabilities daily across cloud, on-premises, and SaaS environments. Analyst frameworks from GigaOm, IDC, Forrester, and SANS have formalised evaluation criteria, and the CAASM market is projected to reach $12.6B by 2033.

The technology works, but it has fundamentally failed. The constraint is not discovery but remediation physics. Empirical research from May 2026 on 500K+ vulnerability reports (HackerOne) shows discovery velocity up 76% YoY while remediation throughput collapsed 46%, creating a widening exposure debt. More critically: Mandiant's incident response data (500K+ investigation hours) found the mean time-to-exploit is now -7 days—exploits are weaponised and active BEFORE patches are released, rendering patch-based defense obsolete. The asymmetry is structural: AI-driven discovery (10-40x faster), PoC generation (60x faster), and weaponisation (172,000x faster) now exceed enterprise patch deployment (45-90 days) by orders of magnitude. Qualys analysis of 1B+ remediation records across 10,000 organisations shows critical vulnerabilities remaining open at Day 7 increased from 56% to 63%, with manual remediation failing 88% of the time—evidence the operational model has hit a structural ceiling. Remediation capacity hasn't merely stalled—it has degraded: analysis shows remediation times increased 47% over five years (171→252 days), and organisations can remediate only 1 in every 10 CVEs monthly. Alert fatigue affects 90% of teams, and fewer than one in four use advanced prioritisation methods like CISA KEV or EPSS. The CVSS-based strategy achieves only 3.96% efficiency despite 82% coverage. June 2026 data hardened the finding: Cloud Security Alliance research confirms vulnerability exploitation has become the #1 initial access vector at 31% of breaches (up from 20% prior year, a 55% increase), displacing credential abuse; only 26% of critical CISA-tracked vulnerabilities are fully remediated; median remediation time increased to 43 days (up from 32 days). Regulatory response is accelerating: FedRAMP Notice 14 (effective December 2026) replaces flat 30-day patch windows with risk-based remediation, requiring critical vulnerabilities addressed within 12 hours. Agentic AI remediation is emerging as operational necessity: Atlassian's DevSecOps platform achieved 51% automated vulnerability remediation at scale. However, market signal is mixed: Cobalt's 2026 pentesting survey shows trust in AI automation collapsed from 29% to 9% of organisations relying entirely on it, with 78% reporting fully automated tools miss critical vulnerabilities—indicating organisations are shifting toward hybrid human+AI models. For well-resourced enterprises with embedded automation, autonomous remediation, and continuous risk management loops, the practice delivers ROI. For everyone else, the practice has become a compliance theatre generating activity metrics disconnected from actual security outcomes.

Current Landscape

Qualys leads the vendor field with 54%+ customer penetration and $669.1M in 2025 revenue, backed by 88% user recommendation rates and 11% YoY growth continuing into H2 2026. Autonomous remediation has moved to production scale: Qualys disclosed 40 million vulnerabilities patched autonomously in the past year with exposure windows compressed from 21 days to minutes, and rollback rates below 0.1% across 150M total patches deployed. Its MITRE ATT&CK integration has reduced vulnerability scope by 85% for adopters, and comprehensive VMDR deployments report 403% three-year ROI. Tenable Nessus remains broadly deployed across 43,000+ organisations; Gartner's June 2026 AI Vendor Race identifies Tenable as the "company to beat" for AI-powered exposure assessment due to long-standing dominance in vulnerability assessment and strong platform execution on AI strategy. Rapid7 has expanded its platform through the Noetic acquisition for asset inventory and launched AI-driven Software Visibility providing continuous vulnerable software tracking across tech stacks. GigaOm's 2026 Radar evaluated 32 ASM vendors, recognising Bishop Fox as a leader for its human-in-the-loop exploitation methodology -- a sign that the market is consolidating around differentiated approaches rather than feature parity. Gartner's 2026 Magic Quadrant recognizes Tenable as a Challenger in cyber-physical systems protection with unified exposure visibility across IT, cloud, identity, and OT assets.

Regulatory pressure reinforces adoption. Federal FISMA M-24-04 zero-trust mandates have driven enterprise-scale ASM deployments, with Qualys CSAM discovering 100K+ domains and 3M+ subdomains for individual customers. SANS published formalised ASM evaluation frameworks in late 2025, cementing the practice's institutional standing; July 2026 SANS white paper validates exposure management as necessary evolution from traditional vulnerability management in response to 48,000+ annual CVE volumes and adversary weaponization velocity exceeding enterprise patch cycles. Named organization deployments demonstrate concrete ROI: a mid-market manufacturer reduced ransomware dwell time from 42 to 5 days (8x improvement) with strong ASM visibility; regional bank under regulatory supervision consolidated 23 vanity charts into 7 decision-grade indicators and received regulatory notation "above expectations"; cloud-native SaaS reduced MTTR 50%+ within two quarters by operationalizing ASM governance.

May 2026 empirical research crystallised the nature of the remediation crisis. HackerOne analysis of 500K+ vulnerability reports showed discovery submissions up 76% YoY but resolution rate down 46%—the opposite trajectory needed. Unresolved critical vulnerabilities grew 25x, creating exponential exposure debt. Mandiant's incident response dataset (500K+ hours, 2025 investigations) found median time-to-exploit at -7 days: exploits are weaponised before patches are released. Meanwhile, Lyrie research quantified the velocity asymmetry: AI discovery 10-40x faster, PoC creation 60x faster, weaponisation 172,000x faster, but enterprise patch deployment flat at 45-90 days. Remediation time per organisation has degraded 47% over five years (171→252 days), and capacity is fundamentally bottlenecked at 1-in-10 CVEs per month. Vendor innovation shifted toward autonomous remediation and data-aware prioritisation: Rapid7's Kenzo Security agentic AI agents achieve 94% investigation time reduction; Qualys integrates Data Security Posture Management to prioritise by breach impact; ServiceNow (which acquired Armis for $7.75B) orchestrates multi-rule workflows. Platform vendor commitment intensified: Microsoft Defender EASM and Security Exposure Management GA with native cloud integration; Qualys VMDR and CNAPP on Oracle Cloud Marketplace. Yet practitioner critique from the JupiterOne Industrial Complex analysis documented the discipline's fundamental misalignment—CVSS strategies require 57.4% of remediation effort for 3.96% efficiency. The constraint is not discovery but remediation and measurement discipline.

June 2026 findings validated and extended the May crisis narrative. Verizon's 2026 DBIR (22,000+ breaches across 145 countries) shows vulnerability exploitation as primary initial access vector (31%, up 55% YoY from 20%), the first 19-year inversion of the credential-abuse dominance pattern. Real-world sensor data from GreyNoise documented pre-disclosure reconnaissance activity on internet-facing assets 8-39 days before public CVE disclosure, with 11-day median lead time—indicating organized adversary activity ahead of vendor patches. Microsoft's June patch cycle hit record-breaking scale (206 CVEs, 33 critical) with mean time-to-working-exploit at 21.5 hours post-disclosure; the record was driven by 100+ AI agents in Microsoft's MDASH platform discovering new flaws. CrowdStrike threat data confirms 42% YoY increase in zero-day exploitation before public disclosure and 89% surge in AI-enabled adversary operations. The bottleneck evidence persists: only 26% of CISA-tracked critical vulnerabilities achieved full remediation (down from 38%); median patch time rose to 43 days (up from 32 days). Scanner coverage gaps remain endemic: 55.7% of critical CVEs receive no scanner coverage at all, and 62% of real-world exploits become available before scanner detection signatures ship. The National Vulnerability Database backlog swelled to 27,000+ unprocessed CVEs with 60,000+ projected for 2026 alone, per U.S. OIG audit. Industry response is shifting from traditional vulnerability management to Continuous Threat Exposure Management (CTEM)—Gartner positioning it as the new maturity framework, with organizations underestimating attack surface by 30% due to forgotten infrastructure, unmanaged assets, and cloud/SaaS sprawl. Supply chain risk has surfaced as critical: 65% of organizations experienced software supply chain attacks in 2026, with 454,000 malicious packages published to open-source registries (75% YoY increase).

July 2026 data hardened evidence that the practice has reached an inflection point driven by AI-accelerated discovery. Anthropic's Claude AI identified 1,596 verified vulnerabilities over 9 weeks in open source—a 177/week discovery rate—but only 97 patches deployed by week 9 (16.5:1 discovery-to-repair ratio), demonstrating that ecosystem-scale remediation cannot keep pace with AI-driven discovery. Epoch AI tracking shows high/critical CVE disclosures spiked to ~1,500 in June 2026 (3.5× prior monthly record) following Claude Mythos release; Project Glasswing partners found 10,000+ vulnerabilities but only 97 had been patched at analysis date—a structural evidence-action gap. FIRST Vulnerability Forecasting Team projects 66,000 CVEs for 2026 (up from February forecast of 59,427), driven by AI-assisted discovery, GitHub ecosystem surge (+449% YoY), and NVD backlog absorption (+3,119%); critically, only ~7% clear exploitability thresholds (EPSS+CISA KEV), leaving 93% as noise. Ecosystem-level adoption acceleration: Chainguard's Athena coalition processed 20,000+ AI-generated findings, producing 2,000 patches across 500 projects; separately, GitHub's own Advisory Database processed 1,560 reviewed advisories in May 2026 and 6,000+ decisions/month—together institutionalizing AI-augmented disclosure at ecosystem scale. Time-to-exploit compression continues to validate the patch-obsolescence thesis: CVE-to-exploit window collapsed to <12 hours (from 745 days in 2020); 73.2% of zero-days exploited before public disclosure. Practitioner assessments reveal persistent tool limitations: AI scanners miss business-logic vulnerabilities, authentication bypasses, and race conditions—field reports show 83% of findings false positives despite high-confidence tool usage, and authors propose layered approaches (AI + deterministic rules + fuzzing + runtime monitoring) achieving 35–45% fewer critical escapes. Deployment outcomes remain mixed: Intermex achieved 98% reduction in critical DMZ vulnerabilities over <1 year using Falcon Exposure Management; however, survey data from 250 DevSecOps leaders shows 82% suffered container-related breaches despite 100% prioritizing containerization, indicating capability-execution gap at scale. The practice is operationally mature for well-resourced enterprises with automation and continuous risk management loops, but remains bottlenecked by remediation physics and false-positive epidemics for the broader market.

The barriers remain structural. Edgescan data shows remediation cycles ranging from 63 days in software to 104 days in construction, and large enterprises leave 45.4% of vulnerabilities unaddressed. Unit 42's analysis of 750+ incidents found 87% of breaches spanning multiple attack surfaces with a 72-minute average exfiltration window -- far faster than most teams can respond. Practitioner analysis reveals endemic false positive epidemics (277 false-HIGH findings in single projects) exposing context-blindness as a root cause of scanner output misalignment with actual production risk. Even mature scanning platforms exhibit critical blind spots: independent benchmarking shows tools flag vulnerabilities based on patch catalog availability, missing entire vulnerability sets in specific software versions (LibreOffice 7.1.8.1 with 100+ documented CVEs reported as "No Known CVEs") and remaining invisible to software installed outside package managers -- a structural limitation affecting deployment accuracy. Tool reliability remains a recurring irritant: both Rapid7 InsightVM (CVE-2026-1814) and Tenable Nessus Agent (CVE-2026-2026) required emergency patches in February 2026. Practitioners have begun questioning the metrics themselves, arguing that vulnerability counts are poor proxies for risk reduction and incentivise activity over outcomes.

Tier History

ResearchJan-2018 → Jan-2018
Bleeding EdgeJan-2018 → Jan-2019
Leading EdgeJan-2019 → Jan-2020
Good PracticeJan-2020 → present
Open on full timeline →

Evidence (194)

— IDC analyst report confirms Tenable's sustained market leadership, $260M ahead of nearest competitor; reflects vendor consolidation and enterprise adoption of AI-driven exposure management.

— Tenable One Adversary View using Claude Mythos 5 to discover hidden attack paths; GA rollout to initial customers September 2026, demonstrating frontier LLM integration into commercial ASM platforms.

— Record-breaking CVE volume (974 total, 723 in Windows alone) indicates sustained acceleration; Rapid7 notes no reason to expect return to pre-2026 volumes, validating AI-driven discovery surge.

— Security consulting assessment documenting the 'AI vulnerability gap' and capacity ceiling; negative signal on remediation capacity scaling with discovery velocity acceleration.

— Federal mandate replacing 14-day KEV requirement with four-variable risk tiers; five remediation tiers from three-day action with forensic triage down to deferral, effective December 7, 2026; pilot showed 60% defer eligibility, 1% required three-day action.

189 more · latest 2026-09-04 →

— Attack Surface Intelligence automated signatures generated within 31 minutes post-CVE; 900,000+ detection events across 46,000+ hosts, impacting 75% of customer projects.

— Recorded Future threat analysis of 215 actively exploited CVEs (34% YoY increase) validating exposure/reachability context as primary exploit predictors, substantiating context-aware prioritization requirements.

— Qualys InstaScan GA enables continuous vulnerability detection within minutes across 90% of supported technologies; 46,048 CVEs published in first seven months 2026 with 9-day median detection-to-closure for KEV instances, demonstrating shift from scan-cycle to real-time intelligence-driven detection.

— Case study: Tempo deployed ULTRA RED EASM discovering AI infrastructure assets never registered in security inventory, validating exploitability of discovered exposures, addressing blind spot in rapidly scaling AI deployments—evidence of modern ASM discovery effectiveness.

— Bitsight research across 3,500+ customers quantifies exploitation timeline collapse from 30 days (2022) to 5 days (2025), with 33% of vulnerabilities attacked within 24 hours of disclosure, invalidating scan-cycle-based remediation and driving adoption of continuous risk visibility.

— Peer-reviewed SiMLA 2026 survey documenting systematic trustworthiness crisis in LLM-driven vulnerability assessment—hallucinated vulnerabilities, incorrect patches, semantic repackaging—revealing adoption barrier: AI findings cannot be trusted at scale without human verification.

— Kaspersky independent research: CVE volume surge driven by widespread AI adoption (OpenClaw project ranked 12th with 200+ CVEs); critical vulnerability count jumped sharply; researchers publishing exploits before patches, demonstrating AI-accelerated discovery and exploitation timeline compression.

— CSA research documents AI-driven discovery acceleration with specific metrics: Microsoft Patch Tuesday 570 fixes (3× prior record), Palo Alto Unit 42 14,090 previously unknown vulnerabilities, Project Glasswing 1,596 disclosed (only 97 patched), demonstrating structural patch capacity ceiling.

— Qualys VMDR demonstrates real zero-day detection and patchless remediation for CVE-2026-69414 without vendor patch available, enabling identification and mitigation during unpatched window—evidence of practice evolution toward remediation without patches.

— Critical assessment documenting false assurance from high-precision AI models that still miss majority of real vulnerabilities, creating coverage blind spots despite high confidence—negative signal of adoption barrier when organizations mistake partial detection for complete assurance.

— Google/Mandiant's AVDH deployed internally for 10 months found 100+ verified high-severity flaws in 48 hours on stolen repositories, producing 12 assigned CVEs with multi-agent architecture and human validation—demonstrates frontier AI discovery deployment maturity.

— Harness production GA of AI SAST (79% false-positive reduction), agentic triage, remediation agent, Zero-Day Agent, and virtual patching—compresses discovery-to-fix from weeks to hours with continuous CI/CD integration and autonomous PR generation.

— Z.ai shipped OpenVuln powered by GLM-5.3 discovering 2,436 vulnerabilities across 269 open-source projects (1,097 critical/high), including 40-year-old DNS bugs and zero-days, demonstrating open-weights frontier model capability for vulnerability discovery reaching production deployment.

— CISA BOD 26-04 (June 2026) mandates shift from CVSS-only to risk-based vulnerability prioritization with 3-day SLA for highest-exposure vulnerabilities, formalizing operational model change at federal policy level for exposure-aware remediation.

— Verizon DBIR metrics show preemptive KEV remediation fell to 12% (from 17%), 35% remain open Day 28, 48% show persistent exploitation—indicating remediation capacity has stalled despite discovery advances and organisational maturity remains at operational ceiling.

— 1Password Off-By-1 Labs research: frontier LLM models generated patches for 6 complex CVEs with 53.9% failure rate (only 26% complete fix, 49.3% failed to fix vulnerability)—reveals that AI-assisted remediation maturity lags AI discovery, introducing quality constraints on automation.

— Rapid7 Labs research demonstrating agentic workflows with AI models and expert guidance to discover complex proprietary zero-days (CVE-2026-63520 + CVE-2026-55040 RCE chain), validating AI-assisted discovery on real enterprise targets.

— Qualys reported 11% revenue growth to $182.2M; disclosed autonomously patched 40 million vulnerabilities over past year with exposure windows reduced from 21 days to minutes; new AI capabilities (InstaScan, Agent Val, Agent Sarah) compress disclosure-to-remediation timelines.

— Qualys platform deployment metrics: 150 million patches deployed in past year, 40 million fully autonomous, rollback rate below 0.1%; wave-based deployment with AI-guided rollback demonstrates production-scale autonomous remediation maturity.

— iSECTECH practitioner analysis documenting ASM maturation to board-level priority; three anonymized deployments (manufacturer: ransomware dwell 42→5 days; regional bank: control improvements; SaaS: MTTR 50%+ reduction) demonstrate operational ROI for organizations with embedded automation.

— Gartner June 2026 AI Vendor Race identifies Tenable as 'company to beat' for AI-powered exposure assessment; long-standing dominance in vulnerability assessment with strong platform execution and AI strategy positioning.

— Rapid7 Software Visibility (preview-to-GA) provides continuous vulnerable software tracking across tech stacks without disruptive scans; enables vulnerability-to-asset correlation for preemptive exposure management before exploitation.

— SANS Principal Instructor establishes exposure management as necessary evolution from traditional vulnerability management; 48,000+ CVEs in 2025, adversaries weaponize faster than enterprises patch; recommends AI-driven exposure control as response.

— Independent benchmark of four VM tools reveals critical blind spots: tools flag vulnerabilities based on patch catalog availability, missing 100+ CVEs in LibreOffice 7.1.8.1 and Firefox ESR 115; no tool detects software outside package manager—negative signal on tool limitations constraining practice maturity.

— Named organization deployment: Intermex CISO reports measurable outcomes (98% DMZ critical reduction, 92% servers, 86% workstations) over <1 year with Falcon Exposure Management—concrete production-scale ROI evidence.

— Safe Security critical assessment: CVSS-based prioritization produces wrong fix lists, asset criticality context missing, discovery outpaces remediation velocity—programs fail from wrong prioritization model, not lacking capacity. Negative signal on practice maturity.

— CrowdStrike 2026 report: 89% YoY increase in adversary AI adoption; exploit window shrinking to real-time; frontier models collapsing vulnerability discovery-to-exploitation gap—drives need for continuous agentic defense matching AI-assisted attacker speed.

— Anthropic Claude AI identified 1,596 verified vulnerabilities over 9 weeks (177/week) in open source, but only 97 patches deployed—16.5:1 discovery-to-repair ratio demonstrates ecosystem-scale remediation physics failure at AI-driven discovery speed.

— Epoch AI data: June 2026 published ~1,500 high/critical CVEs (3.5× prior monthly record); Project Glasswing found 10,000+ vulnerabilities but only 97 patched—strong evidence of AI-accelerated discovery creating structural finding-fixing gap.

— Survey of 250 DevSecOps leaders: 100% prioritize containers but 82% suffered breach; 95% containers account for 50%+ production but 91% cite component visibility gaps; 100% likely to use AI automation, 95% expect intelligent remediation standard by 2026.

— Chainguard, Anthropic, GitHub, Linux Foundation report: 20,000+ AI-generated findings processed, 2,000 patches across 500 projects, 1,560 advisories/month, 6,000+ decisions/month—ecosystem-level adoption demonstrating practice transformation and process strain at scale.

— Practitioner technical analysis: AI scanners miss logic flaws, authentication bypasses, race conditions; author reports 39/47 findings were false positives; proposes layered defense (AI + deterministic rules + fuzzing + runtime monitoring) with 35–45% fewer critical escapes. NEGATIVE signal on AI-only scanning.

— FIRST Vulnerability Forecasting Team: 66,000 CVE projection for 2026 driven by AI discovery (164% spike), GitHub ecosystem surge (+449% YoY), and backlog absorption (+3,119%); only ~7% clear exploitability threshold—critical insight on practice noise/signal ratio.

— CVE explosion (48,185 in 2025, +20.6% YoY); time-to-exploit collapsed from 745 days (2020) to <12 hours (2026); 54% of CVEs published have no detection signature at disclosure—demonstrates detection gap as practice constraint.

— Continuous Visibility GA in Falcon Exposure Management: evaluates cloud assets continuously as vulnerability intelligence updates without periodic scan cycles; addresses architectural detection gap in real-time threat environment.

— Negative signal: Organizations relying entirely on AI automation for pentesting dropped 29%→9% YoY; 78% report AI tools miss critical vulnerabilities; LLM vulnerability MTTR rose 19→36 days; signal market correction away from pure automation toward hybrid approaches.

— Empirical analysis of 69,159 CVEs showing exploit timelines collapsed from 125 days to 0.5 days; 62% of critical vulnerabilities with working exploits circulated before any scanner shipped signatures; reveals structural maturity challenge in vulnerability detection approaches.

— Federal mandate (effective Dec 7, 2026) replaces 30-day patch cycles with risk-based model requiring critical vulnerabilities addressed within 12 hours; ecosystem-wide regulatory signal forcing adoption of AI-acceleration velocity requirements.

— Multi-year vulnerability and exploitation trend analysis (ProjectDiscovery, Mandiant, CrowdStrike, Google TIG): CVE volume explosion (30k→60k/year), mean time-to-exploit collapse (63 days 2018 → -7 days 2026), 70% of exploited bugs now zero-days, AI-assisted exploit generation 10-15 min/attempt.

— Real-world deployment: agentic AI embedded in Jira/DevSecOps workflow achieving 51% automated vulnerability remediation over 6 months; context-aware agents grounded in organizational knowledge deliver 44% higher accuracy than generic agents; demonstrates operational success of agentic remediation at scale.

— Large-scale empirical analysis (1B+ CISA KEV records, 10K organizations) showing critical vulnerabilities remaining open at Day 7 increased from 56% to 63%; manual remediation failed 88% of the time; demonstrates structural ceiling in human-driven operations.

— Record 206 CVEs (previous 175), 33 critical, mean time to exploit 21.5 hours post-disclosure; Microsoft MDASH orchestrates 100+ AI agents for discovery; volume trend 71% month-over-month increase.

— Sysdig metrics: risk prioritization achieved 75% YoY reduction in exploitable in-use vulnerabilities; VulnCheck data shows 2018 TTE 1 year, 2026 median 24 hours; agentic AI remediation emerging as operational necessity.

— Analysis of 22,000+ breaches: vulnerability exploitation primary initial access (31%, up 55% YoY); remediation deteriorated (only 26% of critical KEV vulns patched); median patch time 43 days (up from 32 days).

— SANS keynote: AI-collapsed zero-day economics; 65% of orgs experienced supply chain attacks; Josh Wright warns 'AI has made the gap unbridgeable at our current pace' between attacker and defender speed.

— Curated research aggregation: AI-compressed exploit timelines from 125 days (Jan 2025) to 0.5 day (Apr 2026); 55.7% of critical CVEs never scanned; 62% of exploits ship before scanner signatures available.

— Intruder 2026 Index from 3,000+ clients: >25% expose MySQL databases; ~50% expose risky ports/RDP; WordPress/phpMyAdmin panels frequently internet-facing; larger enterprises manage significantly more external assets.

— Real-world sensor data: pre-disclosure reconnaissance activity observed 8-39 days before public CVE disclosure; 33 CVEs showed median 11-day lead time; organized reconnaissance preceding formal announcements.

— U.S. OIG audit: NIST NVD backlog 27,000+ unprocessed CVEs; projected 60,000+ annual CVE disclosures 2026; systemic scaling limits as supply chain complexity and AI acceleration outpace analysis capacity.

— Gartner Sr. Director Analyst: organizations underestimate attack surface by 30%; gaps in forgotten infrastructure, unmanaged assets; introduces CTEM (Continuous Threat Exposure Management) framework and AEV (Adversarial Exposure Validation).

— Threat research: zero-day exploitation before public disclosure up 42% YoY; AI-enabled adversary operations up 89% YoY; mean time to lateral movement 29 minutes; 27-second fastest observed.

— Peer-reviewed CSA research: vulnerability exploitation now 31% of breaches (vs 13% credentials), marking first 19-year inversion; Mandiant mean time-to-exploit at -7 days; only 26% of critical KEV vulns fully patched.

— Vendor-neutral market research: Global ASM market $980.4M in 2023 with 31.3% CAGR forecast 2024–2030, driven by cloud/SaaS/IoT/third-party complexity and rapid expansion.

— Independent analyst frames Mandiant -7 day finding as practice paradigm shift: quarterly patch cycles are 'obsolete before the quarter started'; autonomous defense at attacker speed is the evolution requirement.

— Product launch addressing scanner coverage gap: 62% of exploited critical vulns had circulating exploits before scanner signature release; 5.1-day average lag between CVE publication and detection capability.

— SANS/CSA/OWASP collaborative briefing (60+ contributors, 250+ CISO review) documenting 12-month escalation of AI-driven discovery: median time-to-exploit fell from 2.3 years (2019) to <1 day (2026).

— Zero-Day Clock data: median disclosure-to-exploit timeline collapsed from 771 days (2018) to <1 day (2026); 73.2% of zero-days exploited before public disclosure, showing patch-cycle defense obsolescence.

— Comprehensive SANS survey of ASM practitioner adoption, technology effectiveness, organizational gaps, and industry barriers to remediation at scale.

— Platform data from 11,000+ vulnerabilities: MTTR for critical/high vulns cut 47% YoY via shift to Continuous PTaaS; exploitation window collapsed to hours, remaking remediation velocity the primary battleground.

— MDR operations data from 11,500+ customers: vulnerability exploitation now 38% of initial access (vs social engineering 24%); median time from disclosure to CISA KEV fell from 8.5 to 5.0 days.

— Real-world deployment data: 60% with exposed admin panels, 42% databases; remediation gap 5x slower in midmarket (56 days) vs enterprise (11 days), documenting structural capacity constraints.

— Analysis of DBIR data: median patch time increased 34% YoY to 43 days; warns that AI vulnerability discovery tools (Mythos) may break the patch cycle by flooding CVE database with unmanageable volumes.

— Industry scan: 71–88% false positive rates across vulnerability tools; engineers spend $20K annually triaging false positives; 22% of teams disabled security tooling due to alert fatigue.

— Comprehensive indictment: remediation time degraded 47% over five years (171→252 days); capacity 1-in-10 CVEs/month; CVSS strategy achieves 3.96% efficiency despite 82% coverage—fundamental structural failure.

— Only vendor with Customers' Choice award in two consecutive years; independent customer satisfaction signal reflecting market confidence in unified exposure management platform maturity.

— Tenable received highest possible scores across breadth, exposure assessment, reporting, and benchmarking; Forrester evaluation validates structured market category with defined criteria for unified VM platforms.

— 500K+ incident response hours show mean time-to-exploit at -7 days (exploits weaponized before patches released); patch management as primary control demonstrably failed; lateral movement collapse from 8+ hours to 22 seconds.

— Analysis of 500K+ vulnerability reports shows discovery velocity up 76% YoY but monthly remediation rate fell 46%; cumulative backlog of unresolved criticals grew 25x, quantifying structural remediation capacity collapse.

— AI-driven discovery (10-40x faster), PoC creation (60x faster), and weaponization (172,000x faster) now exceed enterprise patch deployment (45-90 days) by orders of magnitude; demonstrates asymmetry invalidating traditional VM cycles.

— Q1 revenue $175.6M (+10% YoY), 47% EBITDA margin, Agent Val GA, partnerships with OpenAI/Anthropic; reflects production-scale VMDR adoption with autonomous remediation capability advancement.

— UK government official guidance establishes six foundational VM principles including policy, active exploitation response, asset identification, triage/prioritization, senior risk ownership, and verification—authoritative baseline.

— Empirical analysis of 1B+ CISA KEV records across 10,000+ orgs shows 88% of weaponized vulnerabilities fail manual remediation processes; median time-to-exploit now -1 days, demonstrating structural remediation capacity gap.

— Microsoft Defender External Attack Surface Management (EASM) GA with automated asset discovery, integration with Security Exposure Management, and attack path analysis—signals major platform vendor commitment to ASM category.

— ServiceNow's acquisition of ASM specialist Armis signals vendor consolidation—real-time asset visibility across IT/OT/IoT now integrated into enterprise platform with 100% YoY growth in Security & Risk business.

— SANS Institute published 5-point vulnerability management maturity model (Oct 2025), establishing institutionalized framework for evaluating VM program effectiveness across cloud and enterprise environments.

— Industry-wide analysis across hundreds of organizations and 11 years of data shows 48,185 CVEs in 2025 and mean remediation time of 54.81 days for critical app/API vulns; documents remediation capacity constraints across enterprises.

— Microsoft Security Exposure Management reached GA with CAASM and attack path analysis; Atlas Copco case study shows organizational role evolution (RiskOps) for managing exposure reduction workflows.

— Qualys VMDR and CNAPP now available on Oracle Cloud Marketplace with native OCI integration and one-click provisioning; reflects multi-cloud vendor consolidation strategy and market maturity toward unified risk management across infrastructure, applications, and AI.

— Gartner Magic Quadrant 2026 recognizes Tenable as Challenger in cyber-physical systems protection with unified exposure visibility across IT, cloud, identity, and OT; also Leader in 2025 Exposure Assessment Platforms, confirming analyst validation of integrated approaches.

— Manufacturing industry ASM outcome evidence: ransomware dwell time 42→5 days with strong visibility (8x improvement). Advocates outcome metrics (MTTC for production systems, unauthenticated endpoint reduction) over discovery volume; reflects sector-specific deployment patterns.

— 1B+ remediation records across 10K+ organizations (2022-2025) show 88% of weaponized vulnerabilities fail manual processes; median time-to-exploit -1 days (exploitation precedes patches); manual human-speed response inadequate at scale; calls for autonomous Risk Operations Centres.

— Rapid7 Kenzo Security agentic AI agents achieve 94% investigation time reduction, alert coverage 12%→100%; DSPM integration enables data-aware remediation prioritization by breach impact vs. severity rankings alone; addresses known adoption challenges.

— Practitioner analysis with three case studies documenting endemic false positive epidemic (277 false HIGHs in one project) revealing context-blindness as root cause; shows misalignment between raw scanner output and actual production risk.

— ServiceNow Vulnerability Response platform automation: configurable remediation task rule evaluation (Match First vs Match All), compensating control inheritance reduces re-evaluation friction. Signals enterprise-scale ITSM vendor maturity in vulnerability orchestration at remediation-focus stage.

Plugins | Tenable®Adoption Metric

— Official product data: 318,996 published plugins covering 116,840 CVEs and 30,933 Bugtraq IDs with continuous update cadence, demonstrating organizational maturity of vulnerability detection as core platform capability and breadth of asset coverage.

— Independent analyst validation from IDC tier-1 firm positioning CrowdStrike as Leader in exposure management with AI-driven prioritization and real-time visibility, signaling market maturity and mainstream adoption of continuous risk-based approaches.

— Large-scale empirical analysis of 1 billion remediation records across 10K organizations showing 88% of weaponized vulnerabilities fail manual processes, with 50% exploited before patch availability; identifies operationalization patterns and metrics for closable gap.

— Quantified threat landscape acceleration: 105% YoY increase in confirmed CVSS 7-10 vulnerability exploitation (71→146); median publication-to-KEV time 5.0 days, showing traditional reactive remediation cycles cannot keep pace with adversary speed.

— Critical practitioner analysis documenting zero-day dominance (70% of exploited vulns are zero-days) and negative time-to-exploit trends (-1 days), challenging viability of traditional priority models and detection-based remediation strategies.

— Named-organization deployment (New Resources Consulting, IT services firm) of Rapid7 InsightVM and InsightIDR with measured operational outcomes: 4 hours/week time savings, centralized asset visibility, production-stage integration across diverse client environments.

— Rapid7 InsightVM Splunk add-on (v1.5.2) enabling asset and vulnerability data import with 7,303+ downloads demonstrates ecosystem maturity for integrating vulnerability management into operational intelligence platforms.

— GigaOm evaluated 32 ASM vendors in 2026 Radar, recognizing Bishop Fox as Leader for validated exposure management using human-in-the-loop exploitation methodology to eliminate false positives and advance practice maturity.

— Analysis of 750+ incidents showing 87% of attacks span multiple surfaces with 72-minute average exfiltration time and 89% exploiting identity weaknesses, justifying continued investment in comprehensive attack surface management.

— Vulnerability in Tenable Nessus Agent v11.1.0-11.1.1 and v11.0.3-prior (CVE-2026-2026) reinforces pattern of tool reliability challenges that constrain operational maturity and create adoption friction despite platform capability advancement.

— Vulnerability in Rapid7 InsightVM and Nexpose prior to v8.36.0 (CVE-2026-1814) demonstrates meta-risk: vulnerability management tools themselves require continuous patching, creating circular dependency and adoption barriers.

— Qualys reported 10% revenue growth to $669.1M in 2025 with VMDR platform traction, plus GigaOm and IDC analyst recognition in attack surface management, signaling sustained vendor growth and market maturity.

— Wesley Mission Queensland deployed InsightVM and MDR for ISO 27001 compliance and remote workforce security, reporting incident reduction to near-zero, demonstrating operational effectiveness of integrated vulnerability and detection workflows.

— Tenable recognized as Leader by Gartner, Forrester, and IDC for exposure management platform, providing third-party analyst validation of vendor platform maturity and market positioning.

— Critical analysis documenting endemic ROI measurement challenges in ASM—alert fatigue, unclear incident reduction linkage, and disconnects between discovery and outcome metrics—exposing maturity gaps despite platform advancement.

— December 2025 French CERT advisory documents multiple vulnerabilities in Tenable Nessus <10.9.6 and <10.11.1, including denial of service and data integrity risks—demonstrating that vulnerability management tools themselves require continuous patching and monitoring.

— November 2025 analyst comparison (151 Qualys, 34 Fortra reviews) shows Qualys VMDR composite score 8.8/10 vs Fortra 7.3/10, with 88% Qualys likelihood to recommend and 94% renewal intent—indicating strong user satisfaction and market leadership consolidation.

— SANS Institute 2025 survey assesses state of attack surface and vulnerability management, examining effective technologies and organizational exposure gaps—signaling industry-wide standardization of ASM evaluation.

— Tenable November 2025 whitepaper advocates risk-based vulnerability management using machine learning and threat intelligence for continuous visibility across cloud, AI, and OT assets—signaling vendor platform maturity toward integrated exposure management approaches.

— October 2025 analysis reports 21,500+ CVEs disclosed in H1 2025 with 38% rated High/Critical and 133 new flaws daily, with attackers weaponizing new CVEs within hours—underscoring urgency for continuous vulnerability and attack surface management.

— Research Intelo projects CAASM market growth from $1.8B (2024) to $12.6B by 2033 (23.7% CAGR), with North America at 38% share and Asia Pacific at 27.1% CAGR—confirming sustained rapid market expansion and organizational investment in attack surface management.

— Rsnake critical analysis argues that traditional VM metrics (vulnerability volume fixed) are poor ROI proxies, creating misaligned incentives; advocates risk-based prioritization (exploitability, attacker behavior, business impact) and measuring success by avoided loss, exposing fundamental measurement problems.

— SANS Institute published formalized ASM evaluation framework and best-practice guide, signaling maturation of attack surface management as an institutionalized practice with standardized selection and implementation methodologies.

— Info-Tech SoftwareReviews head-to-head analysis (Aug 2025) shows Qualys VMDR Composite Score 8.8/10 vs Tenable 7.9/10, Qualys LTR 88% vs Tenable 90%, Qualys emotional footprint +97 vs +88, revealing user preferences and competitive positioning in market consolidation.

— Rapid7 launched AI Attack Coverage for GenAI applications (OWASP Top 10 LLM modules) and Remediation Hub unified interface for asset/threat intelligence integration, signaling vendor platform evolution addressing modern attack surfaces and remediation workflow maturity.

— Edgescan's empirical analysis of thousands of 2024 assessments reveals significant industry variance in vulnerability remediation efficiency: software sector (63 days), construction (104 days); larger enterprises leave 45.4% of discovered vulnerabilities unaddressed, quantifying operational maturity gaps.

— CERT-FR advisory (July 2025) documents critical vulnerabilities in Tenable products (Security Center 6.4.x–6.5.x, Nessus <10.8.5/10.9.0) including RCE (CVE-2025-24855, CVE-2025-29087) and privilege escalation (CVE-2025-36630), highlighting meta-risk that vulnerability management tooling itself is vulnerable.

— Qualys VMDR wins SC Awards Europe 2025 for third consecutive year; customer testimonials cite 20-30% estimated ROI with automated patching and compliance tracking; company reports 10,000+ subscription customers worldwide, signaling sustained vendor momentum and customer validation.

— Independent security review confirms Tenable Nessus maintains position as most widely deployed vulnerability scanner with ~43,000 organizations relying on the platform, including Fortune 500 adoption, demonstrating established market penetration.

— Outpost24 report projects External Attack Surface Management market growth to $930.7M by 2026 (17.5% CAGR) with broader ASM market reaching $9.19B by 2032 (30.4% CAGR), confirming accelerated industry investment and organizational adoption.

— AWS Marketplace verified customer reports 50% reduction in exploitable vulnerabilities using Rapid7 InsightVM, with 20+ years of deployment experience, demonstrating concrete operational risk reduction in production environments.

— Seemplicity survey reveals 41% of organizations struggle to make vulnerability findings actionable, 90% report alert noise issues, and CISA KEV/EPSS adoption remains low (18-23%), highlighting persistent operational maturity gaps despite vendor platform advancement.

— French national CERT documents multiple critical vulnerabilities in Tenable Nessus (RCE, privilege escalation, data integrity breach) affecting versions prior to 10.8.4, revealing security risks in core vulnerability management tooling.

— SoftwareReviews aggregated user data (151 reviews) for Qualys VMDR shows 88% Likeliness to Recommend, 94% Plan to Renew, and +97 Net Emotional Footprint, signaling strong user satisfaction and platform retention.

— User forum discussion documenting negative impact of Rapid7's AI-powered CVSS scoring changes (Feb 18, 2025) on vulnerability management workflows, with practitioners reporting erratic scores and severe workflow disruption.

— Energie Suedbayern (German energy provider, 2,000 IP addresses) deployed Rapid7 InsightVM and InsightIDR enterprise-wide for ITSG compliance, reporting 60% time savings and successful vulnerability management at scale.

— Research and Markets projects Attack Surface Management market growth from $1.06B (2024) to $4.09B (2030) at 24.98% CAGR, driven by cloud adoption and digital transformation, confirming accelerated organizational investment.

— Practitioner analysis quantifies vulnerability management false positive rate at 99.59% (26,447 identified, only 109 exploited in 2023 per CISA KEV), with SaaS companies facing 98% best-case false positive rate—highlighting fundamental practice inefficiency.

— Forrester analyst webinar on Q3 2024 Wave ASM evaluation presents findings on vendor landscape, market trends, and selection criteria for 23-criterion assessment of attack surface management providers.

— Cloud Security Alliance identifies systemic CVE program limitations: data quality issues, outdated information, missing metadata, and lack of interoperability—highlighting foundational tool constraints affecting vulnerability management effectiveness.

— DefCamp benchmark testing of 167 vulnerable environments found Qualys second in detection accuracy (behind Pentest-Tools), Nessus fourth with 18.56% accuracy vs promised 55.09%—revealing tool capability variability and performance gaps.

— Team Cymru survey of 440 ASM practitioners finds 49% plan to replace their current vendor within 12 months, with 79% citing dissatisfaction with value or performance rather than cost—signaling significant tool maturity and adoption gaps.

— Survey of 312 IT security professionals reveals 49% of companies have immature EASM programs, 90% experienced increase in attack surface incidents, and 66% dissatisfied with tool actionable insights—confirming persistent organizational and tool maturity constraints.

— Forrester Wave Q3 2024 ASM report ranks Qualys CyberSecurity Asset Management as Strong Performer, validating market maturity and platform capability for enterprise attack surface monitoring across internal and external exposure.

— AppTrana WAAP blocked 2.37B attacks in Q2 2024 with vulnerability targeting surging 1,200% year-over-year, demonstrating heightened attack activity pressuring organizations to adopt and operationalize vulnerability management at scale.

— Market research projects ASM category growth from $0.9B in 2024 to $3.3B by 2029 (29.3% CAGR), driven by digital transformation and cyber threat escalation, confirming accelerated organizational adoption of attack surface management.

— Rapid7 acquired Noetic to enhance cyber asset inventory and attack surface visibility across endpoints to cloud, demonstrating vendor platform consolidation to address discovery-remediation capability gaps.

— Exponent engineering consulting firm deployed Rapid7 InsightVM for vulnerability management and asset discovery across diverse environments, with 24/7 MDR coverage providing real-time threat detection and remediation.

— Vendor analysis argues traditional vulnerability management approaches fail in modern application security due to lack of developer context and poor workflow integration, indicating scope limitations for application-layer vulnerability coverage.

— NetSPI security practitioner analysis identifies persistent implementation gaps: organizations flooded with daily vulnerabilities, lack centralized tracking across multiple scanners, and face complex remediation workflows—signal of operational maturity constraints.

— Market research projects ASM category growth from $0.9B in 2024 to $3.3B by 2029 (29.3% CAGR), with SMEs as fastest-growing segment and cloud deployments dominating, confirming rapid market expansion and ecosystem breadth.

— Spanish national cybersecurity institute (INCIBE-CERT) documented low-severity information disclosure vulnerability in Rapid7 InsightVM, exposing sensitive data in authentication flows—highlighting tool reliability challenges.

— Qualys CSAM platform addresses federal FISMA M-24-04 zero-trust requirements; platform has discovered 100K+ domains and 3M+ subdomains for enterprise customers, signaling regulatory-driven adoption acceleration.

— Qualys integrated MITRE ATT&CK prioritization into VMDR, aggregating 73,000+ vulnerability signatures with 25+ threat intel sources to enable threat-informed vulnerability prioritization, reducing scope by up to 85%.

— Macropraxis research identified average business uses 80 IT-sanctioned SaaS apps (5x growth in 3 years) with 65% shadow IT usage, revealing unmanaged SaaS sprawl as critical attack surface blind spot.

— Intruder reported customer remediation time for critical vulnerabilities improved from 30 to 17 days due to continuous monitoring and attack surface reduction focus, quantifying operational efficiency gains.

— Oryx Align consultancy documented barriers limiting SME vulnerability management adoption: budget constraints, resource gaps, patch complexity, lack of expertise, and compliance pressure—highlighting persistent organizational readiness gaps.

— Qualys Q1 2024 reported VMDR fueling new logos, 19% growth in $500K+ customers to 192, and major wins including Forbes 1000 company replacing 3 vendors with Qualys EASM, signaling strong enterprise platform consolidation.

— Trend Micro analysis identifies attack surface management challenges in distributed environments: irregular asset inventory, alert overload, inability to keep pace with cloud service changes and remediation burden.

Get the Most Out of VMDRAdoption Metric

— Qualys reports customers leveraging comprehensive VMDR features achieve 403% ROI over three years, quantifying deployment value for enterprises using full platform capabilities.

— SecureOps analysis of 421 security professionals reveals critical implementation gaps: 24% experienced breach due to unaddressed vulnerabilities, only 11% patch same day, 47% take >1 week—indicating capability-maturity disconnect.

— Bitsight named KuppingerCole 2023 Leader in Attack Surface Management; outlines five-step strategy (discover, analyze, remediate, track, prioritize) reflecting vendor ecosystem maturity in EASM category.

— Palo Alto Unit 42 analysis of 250+ organizations reveals 80% of security exposures in cloud, 20% monthly service churn, and 45%+ high-risk exposures on new services—highlighting attack surface volatility.

— Rapid7 InsightVM wins SC Awards 2023 for Best Vulnerability Management; customer US Signal reports centralized visibility and team collaboration improvements, validating production-scale deployment.

— French CERT advisory on vulnerabilities in Nessus Network Monitor (versions <6.2.2): remote code execution, denial of service, data integrity/confidentiality breaches. Highlights ongoing tool reliability challenges.

— Forrester Total Economic Impact study reports 125% ROI over 3 years with 6-month payback; 20% breach risk reduction ($1.5M saved), 12% analyst efficiency gain ($276K), 7,800 annual hours saved in IT ops.

— Domestic & General (3,000+ employees, 23M appliances) deployed Rapid7 InsightVM across international offices; CIO reported simplified data digestion, integrated cybersecurity, and cost reduction on security staff.

— Bitsight analysis of 100K+ organizations reveals only 5% monthly vulnerability remediation rate; expansion of attack surface from cloud, IoT, vendors, and remote work outpacing remediation capacity.

— Qualys reported VMDR deployed by 54% of customers worldwide; F100 biotech expanded to 290K+ assets, Fortune 200 customer monitoring millions of containers daily, signaling strong enterprise adoption breadth.

— Forrester analyst report defines ASM as continuous discovery and assessment of IT asset exposures; identifies 36 vendors addressing asset visibility gaps that leave organizations blind to exploitable risks.

— IDC market forecast recognizes ASM/BAS as distinct software category enabling proactive risk management; analyst validates attack surface visibility and testing before attacker engagement.

— Security practitioner highlighted vendor maturity gaps: CVSS v3 support added 7 years after standard release (2015), and dashboard usability issues persisted—signaling tool evolution lag despite market advancement.

— Qualys VMDR won SC Awards 2022 Best VM Solution, led GigaOm Radar Q3 2022, and ranked #1 on G2 (92 score). Customers reported 23–50% risk reduction, validating risk-quantification maturity.

— Rapid7 released CVSS v3 support, asset correlation for VDI, and Scan Assistant improvements, signaling continued vendor platform maturity and operational integration with enterprise IT.

— Cortex Xpanse research across 50M IP addresses and 100+ enterprises (Mar 2021–Jun 2022) found 90% of issues in cloud, 25% RDP exposure, 30% EOL software with active CVEs, and no industry showing surface reduction—revealing persistent deployment maturity gaps.

— Survey of 426 security professionals: 70% rate their vulnerability management program 'somewhat effective or worse'; 58% lack risk-based prioritization; 62% take 48+ hours to remediate; 58% report vulnerability volumes doubling/tripling.

Introducing Qualys VMDR 2.0Product Launch

— Qualys VMDR 2.0 launch with TruRisk risk quantification: beta customers prioritized 28% fewer critical vulnerabilities and achieved 23-50% risk reduction; integrated ServiceNow ITSM and patch management.

Why You Need ASM ASAPIndustry Report

— Palo Alto Networks summary of ESG ASM research: 25% of external assets have exposed RDP, 32% run EOL Apache, 29% run EOL Exchange; 69% of organizations compromised via unknown assets; automated discovery reveals 40% more assets than perceived.

— Rapid7 product updates including CISA Known Exploited Vulnerabilities catalog integration and Log4Shell mitigation checks, showing vendor response to operational incident response requirements.

— Analyst opinion citing ESG data: only 9% of organizations monitor 100% of attack surface, 43% take 80+ hours for discovery, 69% experienced attacks from unknown assets—signaling persistent maturity gaps despite vendor consolidation.

— Forrester trend report examining emerging ASM market, recommending enterprise consideration of attack surface discovery and risk management solutions.

— Rapid7 InsightVM provided operational response to Log4Shell (CVE-2021-44228) with authenticated checks and agent-based detection, demonstrating real-world incident response capability.

— Qualys reported VMDR deployed by 32% of their customer base worldwide with $70M in Cloud Agent subscriptions (40% YoY growth), indicating widespread enterprise adoption.

— Invicti security analysis examined false-negative accuracy challenges in vulnerability scanning, arguing that inherent trade-offs between coverage and specificity limit real-world tool effectiveness.

— SoftBank deployed Rapid7 InsightVM across hundreds of thousands of assets, automating vulnerability prioritization and enabling focus on remediation response efforts at enterprise scale.

— French CERT advisory documented multiple vulnerabilities in Tenable Nessus Agent (versions 7.2–8.x), allowing remote denial of service and data breach, highlighting tool reliability challenges.

— Palo Alto Networks deployed Cortex ASM internally across 700,000+ cloud instances, achieving 95% cost reduction, 10x coverage increase, and 3 hours per-vulnerability investigation savings.

— ESG survey of 200 organizations reveals attack surface maturity gap: 98% cite it as top priority, but 68% experienced attacks from unknown assets and only 9% test 100% of their surface.

— Survey of 100+ IT leaders shows 84% perceive mature programs despite significant gaps in orchestrated remediation (48% maturity), continuous automation (48%), and hygiene alignment (31%).

— SAI Global deployed InsightVM across 4,000 assets in one month; Trov reported reduced false positives with centralized visibility; education institution resolved misconfigurations in minutes vs days, demonstrating production-scale ROI.

— Qualys VMDR reaches general availability with early adopter Toyota Financial Services deploying on 10,000+ devices, achieving real-time asset management and vulnerability prioritization at scale.

— IDC reports Tenable #1 in worldwide vulnerability management market share for 2019, with 30,000+ customers including 50% of Fortune 500, confirming category-level commercial dominance.

— Ovum analyst report recognizes Qualys VMDR as next-generation leader, offering seamless end-to-end workflow with integrated patching and xDR alignment, validating enterprise-scale product maturity.

— Forrester TEI study based on five customer deployments reports 342% three-year ROI with 22% false positive reduction and 60% patching effort reduction, quantifying real-world operational benefits.

— Forrester Wave analysis names Rapid7 InsightVM a leader with highest scores across nine VRM criteria (footprinting, prioritization, ecosystem), signaling third-party validation of market maturity.

— Contrast Security critiques legacy SAST/DAST approaches for high false positives and manual processes, advocating instrumentation-based AppSec as alternative to traditional network-level vulnerability scanning for applications.

— Rapid7 integrates Project Sonar (232M+ assets, 8B+ DNS records weekly) with InsightVM to enable automated discovery of unknown internet-exposed assets, advancing ASM capability breadth.

— Independent security consultant reports reflected XSS vulnerability in InsightVM, signaling that even mature commercial tools have exploitable flaws and perfect coverage remains unrealistic.

— Named customers Guidewire (5,000 AWS workloads) and CognitiveScale deployed InsightVM with pre-authorized scanning, reducing operational overhead and providing real-time risk visibility across cloud infrastructure.

— NIST-published journal article formalizing network-level attack surface metrics for zero-day resilience, providing authoritative peer-reviewed foundation for the practice.

— SAP-developed open-source tool with 20K+ production scans across 600+ Java projects at enterprise scale, demonstrating real-world adoption in supply chain vulnerability assessment.

— Analysis of 2,100 organizations finding 48% adopted strategic vulnerability assessment but only 5% at highest maturity, indicating adoption breadth with significant maturity gaps.

— Named-organization deployment of Rapid7 InsightVM reducing vulnerability detection and remediation time to under a week, demonstrating concrete operational improvement.

— Research extending attack surface metrics to cyber-physical systems with case study on power grid SCADA, advancing theoretical foundations for industrial security.

— Critical assessment by WhiteHat Security founder challenging ROI of broad vulnerability scanning, citing vendor-customer misalignment and low exploitation rates of reported vulnerabilities.

History

2026-Sep: Discovery-side tooling advanced further: Qualys shipped InstaScan targeting faster vulnerability detection following new disclosures, and UltraRed launched AI attack-surface security validating what AI infrastructure actually exposes, extending exposure management into AI-specific assets (per Bitsight's framing of what frontier AI means for exposure management programs). Securelist's Q2 2026 vulnerability-landscape analysis and Cloud Security Alliance research on AI discovery outpacing patch capacity reinforced the widening discovery-remediation gap, while a CVE-2026-69414 "ShieldBreak" zero-day with no available patch triggered a CISA BOD 26-04 14-day mitigation deadline. Academic and practitioner analysis also flagged a reliability risk in AI-assisted vulnerability assessment itself: a survey catalogued reasoning failures and hallucinations ("AI slop") in AI-generated vulnerability findings, and a companion piece examined what breaks when AI-based vulnerability detection has low recall. Market and regulatory structure hardened further: IDC confirmed Tenable's eighth consecutive year at #1 market share (24.6%, $260M ahead of nearest competitor) and GA'd Claude Mythos 5 integration into Tenable One's Adversary View for hidden attack-path discovery; Microsoft's September Patch Tuesday set a new record (974 vulnerabilities, 113 critical), with Rapid7 seeing no return to pre-2026 volumes; and CISA's BOD 26-04 formally replaced the uniform 14-day KEV patch deadline with four-variable risk-based tiers (three-day action window for the highest-risk exposures, effective December 7, 2026; pilot data showed 60% qualify for deferral and 1% required three-day action). Recorded Future evidence reinforced the discovery-remediation asymmetry from both sides: automated signature creation now generates detections within 31 minutes of CVE publication (900,000+ events across 46,000+ hosts, 75% of customer projects impacted), while separate analysis of 215 actively exploited CVEs found exposure and reachability more predictive of exploitation than CVSS severity alone. Commentary continued to frame an "AI vulnerability gap" — discovery outpacing patch capacity as a structural capacity-ceiling risk.
2026-Aug: Qualys' Q2 earnings disclosed 40 million vulnerabilities autonomously patched over the past year with exposure windows compressed from 21 days to minutes (150M total patches deployed, rollback rate below 0.1%), and Gartner's June 2026 AI Vendor Race named Tenable "the current company to beat" for AI-powered exposure assessment. Rapid7 advanced Software Visibility from preview to GA for continuous vulnerable-software tracking without disruptive scans, and iSECTECH's practitioner analysis of three anonymized deployments documented concrete ROI (ransomware dwell time 42→5 days; 50%+ MTTR reduction). SANS reiterated that exposure management is a necessary evolution from vulnerability management given 48,000+ annual CVEs outpacing patch cycles. Countervailing evidence persisted: an independent benchmark of four VM tools found each missed 100+ CVEs in specific software versions (e.g., LibreOffice 7.1.8.1) and none detect software installed outside package managers, confirming structural blind spots in mature scanning platforms. AI-driven discovery accelerated sharply: Google/Mandiant's AVDH tool (10 months in internal deployment) found 100+ verified high-severity flaws in 48 hours yielding 12 assigned CVEs; Z.ai's open-weights OpenVuln scanner (GLM-5.3) discovered 2,436 vulnerabilities across 269 OSS projects; Rapid7 Labs used agentic workflows to chain two zero-day RCEs in Microsoft SharePoint; and Harness reached GA with AI SAST, agentic triage, and a Zero-Day Agent compressing discovery-to-fix from weeks to hours. Regulatory and outcome data underscored the remediation gap this discovery wave feeds into: CISA's BOD 26-04 mandated risk-based prioritization with a 3-day SLA for highest-exposure vulnerabilities, Verizon's 2026 DBIR found preemptive KEV remediation fell to 12% (from 17%), and SANS-reported 1Password research showed frontier LLM-generated patches failed to fix vulnerabilities 53.9% of the time — confirming AI-assisted remediation maturity continues to lag AI-assisted discovery.
2026-Jul: July data hardened evidence of an AI-driven inflection point: Anthropic's Claude identified 1,596 verified open-source vulnerabilities in nine weeks but only 97 were patched (16.5:1 discovery-to-repair ratio), and Epoch AI tracked a 3.5x spike in high/critical CVE disclosures following the Claude Mythos release. FIRST's Vulnerability Forecasting Team raised its 2026 CVE projection to 66,000 (only ~7% clearing exploitability thresholds), while Intermex reported 98% reduction in critical DMZ vulnerabilities via Falcon Exposure Management even as practitioner analysis found AI scanners missing business-logic flaws at scale (39 of 47 findings false positives).
Show earlier history (2018–2026 · 21 more) →

2026

2026-Jun: Industry consensus shifted decisively toward Continuous Threat Exposure Management (CTEM) model away from traditional vulnerability management. Verizon 2026 DBIR analysis (22,000+ breaches, 145 countries) confirmed vulnerability exploitation as #1 initial access vector (31%, up 55% YoY from 20%), the first 19-year inversion of credential-abuse dominance; only 26% of CISA Known Exploited Vulnerabilities catalog fully remediated (down from 38% prior year); median patch time increased to 43 days (up from 32 days). Cogent empirical analysis of 69,159 CVEs confirmed exploit timelines collapsed from 125 days to 0.5 days, with 62% of critical vulnerabilities already having working exploits circulating before any scanner shipped detection signatures — a structural indictment of scanner-centric VM approaches. Qualys analysis of 1B+ remediation records (10K+ organizations) documented the remediation capacity ceiling: critical vulnerabilities remaining open at Day 7 increased from 56% to 63%, and manual remediation failed 88% of the time. Atlassian reported a production counterexample: agentic AI embedded in Jira DevSecOps workflows achieved 51% automated vulnerability remediation over 6 months, with context-aware agents grounded in organizational knowledge delivering 44% higher accuracy than generic agents. FedRAMP Notice 14 (effective December 7, 2026) introduced a structural regulatory forcing function: replacing 30-day patch cycles with risk-based remediation requiring critical vulnerabilities addressed within 12 hours. Cobalt's 2026 pentesting survey captured market correction: organizations relying entirely on AI automation dropped from 29% to 9% YoY, with 78% reporting AI tools miss critical vulnerabilities and LLM vulnerability MTTR worsening from 19 to 36 days — confirming industry shift toward hybrid human+AI models over pure automation. ProjectDiscovery multi-year trend analysis confirmed CVE volume has doubled (30K→60K/year), mean time-to-exploit collapsed to -7 days, and 70% of exploited bugs are now zero-days, with AI-assisted exploit generation taking 10-15 minutes per attempt. Despite market growth and vendor maturity, organizational remediation capacity remains the constraining factor: only 18% adopt EPSS/CISA KEV prioritization and agentic AI remediation is emerging as an operational necessity rather than an advanced option.
2026-May: The remediation physics crisis hardened into structural indictment. HackerOne analysis of 500K+ vulnerability reports showed discovery submissions up 76% YoY while resolution rate collapsed 46%, with unresolved critical vulnerabilities growing 25x. Mandiant's incident response dataset (500K+ hours) put mean time-to-exploit at -7 days — exploits weaponised before patches release — confirmed by the SANS/CSA/OWASP emergency briefing (60+ contributors) documenting median time-to-exploit collapsing from 2.3 years (2019) to under one day (2026). Lyrie research quantified the asymmetry: AI-driven weaponisation is 172,000x faster than enterprise patch deployment cycles, with 73.2% of zero-days now exploited before public disclosure. JupiterOne's practitioner analysis confirmed remediation time has degraded 47% over five years (171→252 days), with CVSS-based strategies achieving only 3.96% efficiency despite 82% coverage; Tenable's DBIR analysis added that median patch time increased a further 34% YoY to 43 days. Rapid7's Q1 2026 MDR data (11,500+ customers) showed vulnerability exploitation surpassing social engineering as the top initial access vector (38% vs 24%), with median disclosure-to-KEV time at 5 days. Synack's platform data from 11,000+ vulnerabilities confirmed MTTR for critical/high vulns cut 47% YoY via shift to continuous PTaaS, while Intruder's 2026 ASM Index documented structural midmarket capacity failure: remediation 5× slower (56 vs 11 days) with 60% of organizations exposing admin panels publicly. Against this, vendor consolidation and platform GA announcements continued: ServiceNow's $7.75B Armis acquisition integrated real-time IT/OT/IoT asset visibility into enterprise workflow orchestration; Microsoft Defender EASM reached GA with automated asset discovery and attack path analysis; Qualys posted Q1 revenue of $175.6M (+10% YoY) with Agent Val GA and Anthropic/OpenAI partnerships; Forrester named Tenable a Leader in unified VM; and the NCSC published authoritative six-principle VM guidance establishing baseline expectations. CrowdStrike earned Customers' Choice in EASM for the second consecutive year, signalling sustained enterprise confidence in consolidated exposure management — even as the structural gap between discovery speed and remediation capacity continued to widen.
2026-Apr: Empirical research hardened the case that the practice's core problem is remediation physics, not discovery. Qualys analysis of 1 billion remediation records across 10,000 organisations found 88% of weaponised vulnerabilities fail manual processes and 50% are exploited before patches arrive; Rapid7's 2026 Global Threat Landscape Report documented a 105% YoY increase in confirmed CVSS 7-10 exploitation with median publication-to-KEV time of 5 days. A practitioner analysis of zero-day dominance (70% of exploited vulnerabilities are zero-days, with exploitation sometimes preceding public disclosure by a day) challenged the viability of CVE-based prioritisation models as the primary defence. On the vendor side, Qualys VMDR expanded to the Oracle Cloud Marketplace with native OCI integration, Tenable was named a Challenger in Gartner's 2026 Magic Quadrant for cyber-physical systems protection, and Rapid7's Kenzo Security agentic AI agents reached GA with 94% investigation time reduction and alert coverage scaling from 12% to 100%. Sector-specific evidence confirmed outcome potential (manufacturing: ransomware dwell time cut from 42 to 5 days with strong ASM visibility), yet practitioners continued documenting endemic false positive epidemics (277 false-HIGH findings in single projects) exposing context-blindness as a root cause of scanner misalignment with actual production risk.
2026-Feb: Vendor financial performance and ecosystem maturity continued to advance: Qualys reported 10% YoY revenue growth to $669.1M in 2025 with strong VMDR traction, receiving analyst recognition from GigaOm and IDC for ASM leadership. Rapid7's Splunk integration (v1.5.2) reached maturity with 7,300+ downloads, signaling normalized operational tooling for vulnerability data integration into SIEM platforms. Threat landscape analysis (Unit 42) documented 87% of 750+ analyzed incidents spanning multiple attack surfaces with 72-minute average exfiltration time, reinforcing organizational need for comprehensive ASM coverage. GigaOm Radar 2026 evaluated 32 ASM vendors, recognizing Bishop Fox as Leader for human-in-the-loop exploitation validation and false positive elimination. However, tool reliability constraints persisted: Rapid7 (CVE-2026-1814 in InsightVM/Nexpose <8.36.0) and Tenable (CVE-2026-2026 in Nessus Agent) both published vulnerability advisories in mid-month, continuing pattern of ASM tooling introducing new attack surface risks requiring emergency patching. Market remained strong with growing third-party analyst validation and vendor ecosystem maturity, but meta-risk of tool vulnerabilities and organizational measurement discipline remained defining adoption barriers.
2026-Jan: Vendor platform validation continued with Tenable recognized as Leader by Gartner, Forrester, and IDC for exposure management platform. Named organization deployment: Wesley Mission Queensland deployed InsightVM and MDR for ISO 27001 compliance and remote workforce security, reporting incident reduction to near-zero. Critical practitioner analysis surfaced at month start, documenting endemic ROI measurement challenges in ASM—alert fatigue, unclear linkage between discovery and incident reduction, and disconnects between tool capability and outcome metrics—exposing persistent maturity gaps despite vendor platform advancement. Market remained robust with analyst validation and enterprise deployments demonstrating operational effectiveness, but fundamental measurement discipline and organizational readiness challenges persisted.

2025

2025-Q4: Vulnerability and attack surface management market sustained strong growth momentum with CAASM category expanding to $1.8B in 2024, projected for 23.7% CAGR to $12.6B by 2033 (North America 38% share, Asia Pacific 27.1% CAGR). Qualys VMDR maintained market leadership at 54%+ customer penetration with 88% likelihood to recommend and 94% renewal intent (Nov 2025, 151+ user reviews). Tenable Nessus remained broadly deployed (43,000+ organizations), though platform vulnerability count increased: December 2025 CERT-FR advisory documented critical RCE flaws in Nessus <10.9.6 and <10.11.1, reinforcing meta-risk that vulnerability management tooling introduces new attack surface requiring continuous patching. Industry demand remained strong: CVE disclosure accelerated with 21,500+ CVEs in H1 2025 alone (38% High/Critical, 133 daily new flaws), with attackers weaponizing exploits within hours/days. Vendor platform innovation continued: Tenable November 2025 whitepaper advocated risk-based approaches with machine learning and threat intelligence integration for cloud/AI/OT asset visibility. Industry standardization solidified: SANS published formalized ASM evaluation frameworks, signaling practice maturation. However, fundamental operational constraints persisted unchanged: discovery-remediation capability gap remained defining blocker (software 63-day avg, construction 104-day avg, 45.4% vulnerabilities unaddressed by large enterprises), alert noise endemic (90% fatigue), advanced prioritization adoption low (18-23% CISA KEV/EPSS), and practitioners documented ROI measurement problems (traditional metrics poorly aligned with risk reduction). Overall trend reflected market expansion, vendor platform maturity, and strong ROI for well-resourced enterprises alongside persistent organizational capability gaps, tool reliability escalation, and measurement discipline problems blocking broader SME adoption.
2025-Q3: Vulnerability and attack surface management market sustained strong growth with vendor platforms advancing and industry standardization accelerating. Rapid7 extended exposure management with AI attack coverage for GenAI applications (OWASP Top 10 LLM) and Remediation Hub improvements (Aug 2025), while Qualys VMDR maintained market leadership at 54%+ customer penetration with 403% three-year ROI for comprehensive feature adoption. Vendor competitive positioning refined: Info-Tech user comparisons (Aug 2025) showed Qualys VMDR outpacing Tenable in composite satisfaction (8.8 vs 7.9) and emotional footprint (+97 vs +88). Industry standardization strengthened: SANS Institute published formalized Attack Surface Management evaluation guide (Sept 2025), signaling maturation to institutionalized practice status. However, fundamental operational constraints remained unchanged: discovery-remediation capability gap persisted as defining blocker with empirical evidence from Edgescan (July 2025) revealing industry variance in remediation efficiency (software 63 days, construction 104 days) and 45.4% of vulnerabilities left unaddressed by large enterprises. Alert noise endemic (90% reporting fatigue) with CISA KEV/EPSS adoption still low (18-23%). Critical meta-risk surfaced July 2025: Tenable Nessus and Security Center discovered containing critical RCE vulnerabilities (CVE-2025-24855, CVE-2025-29087, CVE-2025-36630), exposing circular dependency where defenders' tooling introduces new attack surface. Practitioner analysis (Sept 2025) challenged ROI measurement fundamentals, arguing traditional metrics (vulnerability count) are poor risk proxies and incentivize activity over actual security outcomes. Overall trend reflected sustained vendor platform advancement and strong ROI for well-resourced enterprises alongside persistent organizational capability gaps, tool reliability concerns, and measurement discipline problems blocking broader operational maturity.
2025-Q2: Vulnerability management market accelerated with External Attack Surface Management (EASM) projected to reach $930.7M by 2026 (17.5% CAGR), and broader ASM market on pace for 30.4% CAGR to $9.19B by 2032. Vendor platform maturity and market validation strengthened: Qualys VMDR won SC Awards Europe 2025 for third consecutive year with customer ROI estimates of 20-30%; Rapid7 InsightVM deployments reported 50% reduction in exploitable vulnerabilities; Tenable Nessus confirmed as market leader with ~43,000 organizations using the platform. Analyst recognition continued: KuppingerCole Leadership Compass 2025 benchmarked vendors including Bitsight as Overall Leader for second consecutive year. However, operational maturity gaps persisted despite platform advancement: 90% of organizations reported alert noise challenges, 41% struggled to make findings actionable, and adoption of advanced prioritization methods (CISA KEV, EPSS) remained low at 18-23%. Critical infrastructure vulnerabilities exposed: CERT-FR documented multiple critical flaws in Tenable Nessus (RCE, privilege escalation, data breach risks), highlighting security risks within core vulnerability management tooling. Overall trend reflected sustained market growth and vendor platform recognition alongside persistent organizational remediation capacity and tool reliability limitations.
2025-Q1: Vulnerability management market expansion continued with Research and Markets projecting $4.09B by 2030 (24.98% CAGR from $1.06B in 2024). Vendor platform maturity advanced: Rapid7 integrating Noetic capabilities for asset inventory and cloud visibility. Qualys VMDR maintained strong adoption at 54%+ penetration with recent user surveys (151 reviews) showing 88% likelihood to recommend and 94% renewal intent, signaling strong customer satisfaction. However, significant operational challenges emerged: Rapid7 InsightVM users reported disruptive CVSS scoring changes from AI-powered vulnerability prioritization (February 2025), with practitioners highlighting negative workflow impact and quality concerns. This signaled real-world adoption friction despite vendor platform advancement. Concrete deployment: Energie Suedbayern (German utilities provider, 2,000 IP addresses) deployed InsightVM and InsightIDR for ITSG compliance, reporting 60% time savings and successful enterprise-wide rollout. Overall trend reflected market growth momentum alongside persistent tool maturity and organizational readiness gaps limiting broader adoption.

2024

2024-Q4: Tool maturity challenges intensified: 49% of ASM practitioners planned to replace their solution within 12 months due to dissatisfaction with value/performance (Team Cymru survey of 440), and 66% reported dissatisfaction with actionable insights from EASM tools (312 IT professionals). Foundational constraints emerged: Cloud Security Alliance identified systemic CVE program failures (data quality, interoperability, metadata gaps), while DefCamp benchmarking revealed tool capability variability (Nessus achieved 18.56% vs promised 55.09% detection accuracy). Practitioner analysis quantified fundamental efficiency gap: 99.59% false positive rate in vulnerability management (only 109 of 26,447 identified vulnerabilities exploited in 2023 per CISA KEV). Discovery-remediation capability gap persisted as defining constraint despite platform maturity: organizational readiness and tool dissatisfaction revealed significant gaps between vendor capability advancement and real-world adoption effectiveness.
2024-Q3: Vendor ecosystem consolidation accelerated: Rapid7 acquired Noetic (July) to enhance cyber asset inventory and attack surface visibility. Qualys maintained market leadership with 54%+ customer penetration, benefiting from FISMA M-24-04 federal zero-trust requirements (Qualys CSAM discovered 100K+ domains, 3M+ subdomains). Forrester Wave Q3 2024 ASM report validated Qualys as Strong Performer for enterprise attack surface monitoring. Attack surface management market momentum strengthened with MarketsandMarkets projecting 29.3% CAGR to $3.3B by 2029. Attack activity escalated (vulnerability attacks +1,200% YoY) pressuring organizations to operationalize vulnerability management. Named organization deployments (Exponent engineering firm) continued with InsightVM+MDR integration. Discovery-remediation gap persisted as category constraint: tool fragmentation, alert overload, and organizational remediation capacity remained limiting factors for broader SME adoption despite vendor innovation and market growth.
2024-Q2: Market research confirmed ecosystem expansion: Attack Surface Management category projected to grow from $0.9B (2024) to $3.3B by 2029 (29.3% CAGR), with SMEs as fastest-growing segment and cloud deployments dominant. Vendor platform innovation continued across Rapid7, Qualys, Tenable, and emerging players (Bitsight, CyCognito, SecurityScorecard). However, critical gaps persisted: practitioners documented tool fragmentation (disconnected network, application, pen-test scanners), alert overload, and complex remediation workflows as recurring implementation barriers. Scope limitations emerged: analysis suggested traditional broad vulnerability management approaches insufficient for modern application security due to lack of developer integration and application context. Discovery-remediation capability gap remained the constraining factor despite vendor maturity and market growth.
2024-Q1: Qualys reported 19% YoY growth in large customers ($500K+), with major Fortune 1000 consolidation wins and March launch of MITRE ATT&CK integration reducing vulnerability scope by 85%. Federal FISMA M-24-04 requirements (zero-trust mandates) drove regulatory adoption signals: Qualys CSAM discovered 100K+ domains and 3M+ subdomains for enterprise customers. Remediation efficiency improved incrementally (30 to 17 days for critical vulnerabilities at leading vendors). However, SaaS sprawl research revealed 80-app average with 65% shadow IT usage, creating unmanaged attack surface blind spots. SME adoption barriers persisted: budget, resource, expertise, and patch management constraints limited DIY maturity despite vendor platform advancement.

2023

2023-H2: Qualys VMDR customers achieved 403% three-year ROI; Rapid7 InsightVM won SC Awards 2023 recognition. Palo Alto Unit 42 research found 80% of security exposures in cloud with 20% monthly service churn. However, implementation maturity remained the critical blocker: SecureOps survey of 421 professionals revealed 24% breached despite vulnerability awareness, only 11% patched same day, 47% took >1 week—demonstrating capability-maturity gap. Trend Micro analysis highlighted distributed environment challenges (inventory irregularity, alert overload). Vendor ecosystem grew with Bitsight named KuppingerCole EASM Leader, confirming market consolidation but persistent organizational remediation capacity constraints.
2023-H1: Qualys VMDR adoption reached 54% customer penetration worldwide with F100 biotech scaling to 290K+ assets and Fortune 200 monitoring millions of containers, validating enterprise scale-out. Cisco TEI study demonstrated 125% ROI over 3 years with 6-month payback and quantified savings ($1.5M breach risk reduction, 7,800 annual IT ops hours). Forrester ASM landscape expanded to 36 vendors, signaling category maturation. However, critical operational gap persisted: Bitsight analysis of 100K+ orgs revealed only 5% monthly remediation rate, exposing the disparity between discovery capability and organizational remediation capacity. Tool reliability challenges continued with French CERT advisories on Nessus vulnerabilities including RCE.

2022

2022-H2: Market legitimacy solidified with IDC recognizing ASM/BAS as distinct software category. Qualys VMDR won SC Awards 2022 and led GigaOm Radar Q3, validating third-party recognition of product maturity. However, large-scale observational research (Cortex Xpanse: 50M IPs across 100+ enterprises) revealed persistent deployment maturity gaps: 90% of issues in cloud environments, 25% RDP exposure, 30% of organizations running end-of-life software with active exploits, and no industry showing attack surface reduction. Vendor platform maturity lagged behind capabilities: practitioners noted CVSS v3 support arriving 7 years after standard release, signaling evolution delays despite category advancement.
2022-H1: Vendor innovation accelerated with Qualys VMDR 2.0 launch (June) featuring TruRisk risk quantification—beta customers achieved 28% reduction in critical vulnerabilities and 23-50% risk reduction. Rapid7 integrated CISA's Known Exploited Vulnerabilities catalog and Log4Shell detection. Forrester recognized ASM as emerging market (January). However, real-world program maturity remained low: 70% of security professionals rated their vulnerability management programs "somewhat effective or worse," with 58% lacking risk-based prioritization and 62% requiring 48+ hours for remediation. Only 9% of organizations tested their complete attack surface; 69% had been attacked from unknown assets; automation revealed 40% underestimation of actual attack surface.

2021

2021: Enterprise deployments accelerated: Palo Alto achieved 95% cost reduction with internal Cortex ASM rollout across 700,000+ cloud instances; SoftBank deployed InsightVM at hundreds of thousands of assets. Qualys VMDR penetration reached 32% of customer base ($70M Cloud Agent subscriptions, 40% YoY growth). Organizational demand for ASM governance rose sharply (61% of executives expected board ASM requests). However, tool reliability challenges emerged: French CERT documented Nessus Agent vulnerabilities (CVE-2021-20077 et al.); security researchers highlighted inherent accuracy trade-offs in vulnerability scanning. Log4Shell response (December 2021) demonstrated vendor capability for incident detection but also exposed the challenge of asset discovery: many organizations lacked visibility into their complete attack surface even with mature tools.

2020

2020: Market consolidation continued with Tenable leading in customer scale (30,000+) and Fortune 500 penetration. Qualys VMDR reached general availability with early enterprise deployments (Toyota Financial Services, 10,000+ devices). Rapid7 customers (SAI Global, Trov) scaled to 4,000+ assets with measurable false positive reduction and operational speed gains. However, adoption maturity lagged capability: ESG survey showed 98% identify ASM as priority but 68% had been attacked from unknown assets; only 9% test their complete surface. IT leader perception gap widened: 84% rated programs mature despite gaps in automation (48%) and business alignment (31%). The market showed technology maturation but persistent organisational adoption friction.

2019

2019: Rapid7 achieved Forrester Wave leadership with highest VRM scores; Qualys launched integrated VMDR platform; attack surface discovery expanded with Project Sonar (232M+ assets) and new ASM category (Bugcrowd). Cloud deployments scaled: Guidewire and CognitiveScale ran InsightVM on 5,000+ AWS workloads. Forrester TEI study quantified 342% three-year ROI with 22% false positive reduction. Market matured but fundamental challenges persisted: vendor tools reported excessive findings with low real-world exploitability; even market-leading tools contained vulnerabilities; alternative approaches (instrumentation-based AppSec) offered critical assessment of broad scanning ROI.

2018

2018: Research formalised attack surface metrics at network level (NIST) and cyber-physical systems (arXiv); vendor landscape solidified (Rapid7, Qualys, Tenable); Bow Valley College achieved sub-week remediation cycles with InsightVM; adoption reached 48% of organisations for strategic assessment but only 5% at high maturity; industry experts raised concerns about false positive burden, vendor incentive misalignment, and low exploitation rates of reported vulnerabilities.

Tools