A new vulnerability appears almost every day in some form. In fact, according to NIST, 18,378 vulnerabilities were reported in 2021, and most organizations' vulnerability management programs are not up to the task.

Each of these vulnerabilities presents a potential entry point for attackers to exploit and gain access to sensitive information. However, many organizations do not have the internal expertise or resources to patch these vulnerabilities at the pace required to keep their environment secure.
New research released today by the Resilience and Ponemon Institute found that 66% of security leaders report a vulnerability backlog of over 100,000 vulnerabilities. It also revealed that 54% say they have managed to patch less than 50% of the vulnerabilities in the backlog.
See also: TA453 team uses new technique for more realistic phishing attacks
Above all, the data suggests that the way most businesses approach vulnerability management is not fit for purpose and provides cybercriminals with ample ways to gain access to mission-critical data.
Why vulnerability management is proving difficult
Vulnerability management struggles are nothing new. According to NTT Application Security, the average time to patch a vulnerability in 2021 was 202 days. Rezilion’s research also highlights that remediation is a problem, with 78% saying that high-risk vulnerabilities take more than 3 weeks to patch.
At the heart of this failure to effectively mitigate vulnerabilities is the lack of the necessary tools.
See also: Hackers have injected malware into extensions from FishPig
Rezilion CEO and co-founder Liran Tancman also emphasizes that few organizations have the visibility or context necessary to determine what needs fixing.

Automation is the answer
Fortunately, automation provides an effective answer to the challenge of vulnerability management, allowing security teams to automate the vulnerability scanning process and continuously detect exploits.
This not only reduces the time it takes to remediate vulnerabilities, but frees up the security team to focus on more rewarding tasks. Rezilion’s research suggests that automation can be a significant force multiplier for security teams, with 43% saying that response time was significantly faster.
See also: SparklingGoblin Team: Creates Linux variant of SideWalk backdoor
It is worth noting that, for the best results, organizations should look for solutions that offer risk-based prioritization if they want to maximize the effectiveness of their vulnerability management program.
Information source: venturebeat.com
