In my previous column, I discussed the topic of Frontier AI and how enterprises can separate genuine AI capabilities from marketing hype when it comes to their vendors. In that piece I also noted that, regarding their own applications, enterprises are concerned they will not be able to keep up with the increased pace of identifying, mitigating, and patching vulnerabilities. I’d like to discuss that topic in this piece.

In 2018, it took attackers an average of 771 days to weaponize vulnerabilities. In 2026, that number is due to fall to just 4 hours! In other words, attackers are leveraging AI and other technologies to vastly increase the speed with which they can exploit vulnerabilities. Given the increased pace at which attackers can find vulnerabilities, develop exploits, and attack enterprises, what are some ways that enterprises can protect themselves and the applications they serve to their end-customers?

Simply put, it is not practical for enterprises to think that they will be able to keep up with a patching cycle measured in minutes and hours rather than in months and years. That being said, there are still many things enterprises can do to limit their exposure and mitigate their risk around the security of their own applications. While not an exhaustive list, I have put together a few recommendations here that I believe will help enterprises manage the exposure and risk that this new reality presents: