14 August 2026
Vulnerability Lifecycle: Why Tooling Is Not Enough
By Greg Tereszczyn, Founder & Principal Consultant
Plot capability across the vulnerability lifecycle and most programmes do not produce a line. They produce a curve - a tall peak in the middle where the tooling sits, and collapsed ends either side.
The middle is well served. Scanning, detection, severity scoring, dashboards: this is what the market sells, what the budget buys, and what an auditor can be shown. Either side of it - knowing what to scan in the first place, and getting findings actually closed - is where programmes fail. Neither end can be bought.
The Left End: You Cannot Assess What You Never Found
A vulnerability programme is only ever as complete as the asset list it runs against. This is the least interesting stage and the one most often assumed to be solved.
It usually isn't. Arctic Wolf's 2026 State of the Cybersecurity Attack Surface report, built on telemetry from more than 800,000 IT assets, found that 33% of assets are missing at least one critical control - including 17% that are invisible to vulnerability management tooling entirely. Not unpatched. Not misconfigured. Invisible. An asset that is not in vulnerability management is never scanned, never reported, and never part of a risk decision.
The causes are mundane. IT operations and security work from separate inventories that were never reconciled. Credentialed scans stop authenticating after a service account rotation and quietly downgrade to unauthenticated results. An exclusion added "temporarily" during a change freeze is still in place three years later.
The consequence is worse than a gap. The scanner returns a clean, confident, well-formatted answer about part of the estate, and the organisation reads it as an answer about the estate. Verizon's 2026 DBIR is direct about where attention belongs: inventory and minimise your internet-facing footprint. That is a discovery instruction, not a tooling one - as is scanner placement, which we covered in Why Layer 2 Matters.
The Middle: Where the Money Goes
The peak of the curve is the platform - the one part of the lifecycle with a product category, a licence, a renewal date, and a vendor motivated to help you justify it.
It is also crowded. IBM's Institute for Business Value puts the average organisation at 83 security solutions from 29 vendors. The industry calls the reflex shiny tool syndrome, but that undersells it: this is a structural bias toward the part of the problem a purchase order can solve. Few organisations are short of tooling. Most are short of what sits either side of it.
The Right End: Findings That Never Close
Detection without closure is not risk reduction. It is documentation. (The workflow that closes the loop - detect, prioritise, remediate, verify - is one we have written about in our NinjaOne partnership post.) This is where the 2026 Verizon DBIR - drawing on more than a billion vulnerability detection records - becomes uncomfortable reading.
Only 26% of CISA Known Exploited Vulnerabilities were fully remediated during 2025, down from 38% the year before. Median time to full resolution rose from 32 days to 43. Over the same period, exploitation of vulnerabilities became the most common initial access vector in breaches for the first time, at 31%, overtaking credential abuse.
Then the finding that should end the "buy a better tool" conversation. By Day 7, between 60% and 70% of known-exploited vulnerabilities remained open - regardless of year, of volume, or of organisational maturity. The best-performing organisations closed only 30-40% in that first week.
Maturity did not move that number. The constraint is not detection - and it is not knowledge either. Of the vulnerabilities the DBIR classes as under persistent exploitation, 80% were registered before 2024, giving organisations roughly two years' notice on the flaws attackers actually use.
Why the Ends Stay Weak
Because compliance asks a different question than security does.
An audit asks whether you have a vulnerability management capability. A licence key answers it. The evidence is dated, filed, and the finding closes.
What no audit asks: whether your credentialed scans still authenticate; whether the asset group has drifted since the day it was built; whether that exclusion is still justified; whether last quarter's critical findings were remediated or simply rolled forward. Those questions determine whether the programme works, and not one of them has a purchase order attached.
A tool is procured once. A capability has to be fed and maintained continuously. Organisations routinely buy the first and assume they have acquired the second.
Essential Eight maturity makes the distinction concrete. The ACSC measures patching in elapsed time - how long between a patch being available and it being deployed everywhere. No licence confers a maturity level. The operated process does, and it depends on knowing what you own and closing what you find.
Capability Mapping
The corrective is unglamorous. Take the lifecycle stage by stage - discovery, assessment, prioritisation, remediation, verification, reporting - and for each one name the capability that serves it, the person who owns it, the data source it depends on, and the evidence it produces.
The stages that come back with no owner and no evidence are the real finding. In our experience the gap is rarely a missing product. It is more often an existing product that cannot see the whole estate, or one whose output never reaches anyone with the authority and the change window to act on it.
Where the exercise does surface a genuine capability gap, buying becomes a deliberate decision with a defined job to do - not a default that raises a peak already tall enough.
What We Are Building
The mapping described above is manual work, and it does not scale. Doing it properly for one organisation takes days. Doing it across every framework that organisation reports against takes longer than most engagements allow.
So we are building it.
TERESEC is developing a research capability that answers a question most organisations cannot answer today: of all the requirements across the frameworks you report against, which ones do the tools you already own actually evidence? Not which products you have - which obligations they discharge. The work spans the ACSC Essential Eight, the ISM, ISO/IEC 27001, NIST CSF, PCI DSS, the CIS Controls and SOC 2.

Three questions become answerable in an afternoon rather than a quarter:
- What are we already paying for but not using? Usually the cheapest uplift available.
- What genuinely requires a purchase? A defensible business case rather than a vendor's claim.
- What is not a tooling problem at all? The requirements that are policy, process or people, where software would be money wasted.
This is early work and not a product announcement. It informs how we advise clients today, and it is why our recommendations start from what you already own.
Sources
- Verizon, 2026 Data Breach Investigations Report - exploitation as the leading initial access vector at 31% (p. 10); 26% of CISA KEV fully remediated and a 43-day median time to resolution (pp. 10, 17); Day 7 survival analysis (p. 18); persistent exploitation and vulnerability age (p. 19).
- Arctic Wolf, State of the Cybersecurity Attack Surface 2026 - 33% of assets missing at least one critical control, including 17% invisible to vulnerability management tooling, across 800,000+ assets.
- IBM Institute for Business Value, How unified cybersecurity platforms add business value - an average of 83 security solutions from 29 vendors.
- Tenable Research, Key findings from the Verizon DBIR 2026 - analysis from a contributor of vulnerability data to the report.
- ACSC, Essential Eight Maturity Model - patching maturity measured in elapsed time.
Engaging Us
If you would like an independent view of where your vulnerability programme sits on that curve, and which stages have no owner, we are available to help.
Contact us to discuss your requirements.
About the author
Greg Tereszczyn
Greg Tereszczyn is the founder and principal consultant of TERESEC, an Australian cyber security consultancy for small and medium business. He turns the Essential Eight, the ISM, ISO/IEC 27001, NIST CSF and IEC 62443 into plain-English advice a business can act on.