Jon Baker is VP, Threat-Informed Defense at AttackIQ.gettyThe world has changed. Attackers are faster and more effective than ever. Security teams were already overloaded with alerts, findings and vulnerabilities before that acceleration began. The old model isn’t holding up. We need to move beyond chasing lists of findings and focus on the real adversary opportunity in our environment.According to CrowdStrike’s "2026 Global Threat Report," the average eCrime breakout time—the period between an initial system compromise and the first instance of lateral movement—has decreased to 29 minutes, representing a 65% increase in attacker speed compared with 2024. In the most extreme case observed, lateral movement occurred in just 27 seconds. Anthropic recently announced that its latest AI model can autonomously discover thousands of vulnerabilities and generate working exploits across major operating systems and browsers. The Cloud Security Alliance reports that the mean time from disclosure to exploitation fell from roughly 32 days in 2022 to about 5 days, with nearly one in three exploits now appearing on or before the disclosure date. This trend toward faster, more sophisticated adversaries and reduced time to exploit has been visible in the data for years. AI capability advances are making it impossible to keep ignoring.It is time for organizations to take a proactive threat-informed approach to managing adversary opportunity.Manage Adversary Opportunity, Not FindingsStop reporting on the vulnerability backlog as if it were the exposure picture. Counting vulnerabilities isn’t wrong. Patching matters, and no version of a security program ignores it. But the set of conditions that create adversary opportunity is broader than the vulnerability list. It includes misconfigurations, identity and access gaps, segmentation drift, controls that pass inventory but fail under test, detection gaps and the increasingly large footprint of unmanaged AI agents and third-party integrations. Each gets discovered by a different team, with different tools, on a different cadence. Most of them sit outside what a traditional vulnerability program tracks.What makes this harder is that no single category is dangerous on its own. A vulnerability becomes meaningful when an adjacent misconfiguration allows an attacker to take the next step. A weak control becomes a problem when identity exposure bridges it to something the business cares about. The risk lives in the combinations, not the components. Measuring any one category in isolation gives a partial picture at best.This combined condition is threat debt: the true adversary opportunity in an environment, weighted by the adversaries that actually target the business, the assets the business cares about and the defenses that have been proven to work. The name deliberately borrows from technical debt. Like technical debt, it compounds when ignored. Unlike technical debt, threat debt is rarely chosen. It accumulates from drift, configuration changes, identity sprawl and adversary evolution. The management discipline is similar: Measure it, prioritize it, pay it down where the interest is highest. The difference is what it costs you. Technical debt costs velocity. Threat debt costs breach exposure.Adversary Opportunity Is An Organizational ConditionReducing threat debt requires shared accounting: one number that every group with a stake in paying it down can read. The work to reduce it is distributed across the organization. Security identifies viable attack paths and validates which defenses break them. The work to actually break those paths usually sits with IT: firewall rules, identity architecture, segmentation, configuration discipline, change management. The priorities (which assets matter, which adversaries to worry about) come from the business.Without a shared vocabulary, those three groups argue about different things. Security talks in techniques and findings. IT talks in tickets and SLAs. The business talks in risk scores it doesn’t fully trust. Calling the underlying condition by one name doesn’t solve that on its own, but it gives three groups something concrete to align on and see how their efforts reduce it.Measuring Threat DebtThreat debt is measured in viable attack paths to business-critical assets, with each path weighted by the impact of the asset it reaches, the relevance of the adversaries that would use it and the residual gap after proven controls. The unit of measure is the path, not the finding. A 10,000-finding backlog often turns out to be a 50-path problem once you map the combinations, and path-breaking scales in a way finding-by-finding patching never will.A threat debt index aggregates this into a single number, reported as a stock (the current balance) and a flow (paid down minus accrued over the period). Compensating controls that demonstrably interdict a path count as paydown, which is the part IT actually cares about: Their work shows up as defensive impact instead of disappearing into a vulnerability count that doesn’t move.What ChangesMost of what changes is the conversation. Patch rates and vulnerability counts aren’t wrong metrics, but they don’t answer the question the board is actually asking: whether the organization is getting harder or easier to compromise. A stock-and-flow view of threat debt (what was paid down, what accrued, where the balance is moving) is closer to that question, and it’s a question security, IT and the business can answer together.It doesn’t make the underlying work easier. Threat debt gives three groups something concrete to align on, which in my experience is harder than the technical work. It reorients organizations on a model that lets them manage adversary opportunity proactively rather than chase vulnerabilities reactively. The shift from measuring activity to measuring adversary opportunity is the one that matters.Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?
Threat Debt: A New Lens On Cyber Defense
The old model isn’t holding up. We need to move beyond chasing lists of findings and focus on the real adversary opportunity in our environment.







