AI collapsed the patching window. Washington needs a cyber risk operations doctrine. | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


The government’s cybersecurity crisis will arrive as a flood of software vulnerabilities are discovered faster than any agency can patch them.

The government’s cybersecurity crisis will arrive as a flood of software vulnerabilities are discovered faster than any agency can patch them.

The latest generation of frontier artificial intelligence models, including Mythos and GPT-5.5-Cyber, can identify software flaws at a pace no human research team can match. Anthropic reported that Mythos surfaced more than 10,000 high- or critical-severity bugs in its first month of limited availability under Project Glasswing. Developers in the United States have restricted public access to these capabilities, but comparable models are emerging from other vendors and countries, including China. The capability is no longer contained, and vulnerability discovery at machine scale is now a permanent feature of the threat landscape.

Why it matters

AI-discovered flaws pour into the overloaded government remediation queues that were struggling long before AI showed up. Faster discovery piles more work onto limited teams and slow approval processes, widening the gap between threat and response speed. The result is longer exposure of citizen data and critical services, more chances for attackers to exploit known issues and a growing list of vulnerabilities agencies can see but cannot fix quickly.

The math was already broken

Vulnerability disclosures nearly doubled in three years, Qualys found, from roughly 26,000 in 2022 to almost 50,000 in 2025, and 2026 is on pace to run hotter. Yet less than 1% of published common vulnerabilities and exposures (CVEs) are ever weaponized. Organizations that treat every finding burn finite engineering hours on exposures that pose no real-world threat while the small set that matters sits in the same queue.

Washington responded

The Cybersecurity and Infrastructure Security Agency’s Binding Operational Directive 26-04 moves organizations from blanket patching to risk-based vulnerability management. The directive requires agencies to rank threats by internet exposure, alignment with the Known Exploited Vulnerabilities (KEV) catalog, real-world exploitability and mission impact, then remediate the most dangerous class within 72 hours. BOD 26-04 requires forensic triage before patching. Patching over an active intrusion without investigation locks the adversary inside, destroys critical artifact data, and falsely marks the threat as resolved while the attacker maintains access through secondary backdoors.

The directive sets the standard. Compliance is the hard part.

A 72-hour clock cannot be met by adding headcount or running scanners. That’s unsustainable. Meeting this deadline requires a different operating model, one that has a growing number of practitioners shifting their operating model in security operations to a risk operations center, or ROC.

Security operations centers (SOCs), critical to agency defense, are already transforming by using AI to handle alerts, threat hunting and incident response triage. The next evolution is transforming traditional security operations into risk operations. This transformative approach allows security leaders to leverage risk-based context and prioritization in enhanced operational processes to mitigate human alert fatigue and focus efforts where the greatest measurable value exists. Establishing a risk operations mindset shifts the energy in traditional security operations to focus on risk-based analysis, while leveraging advanced orchestration and autonomous agents to prioritize response actions.

The ROC model runs a continuous analysis and feedback loop against a single question: What risk matters most right now, and how fast can it be reduced? The model’s loop has four stages governments should follow:

  1. Detection at AI speed. When a vulnerability shifts from theoretical to actively exploited, that state change must be visible across agencies within hours, not at the next scheduled scan.
  2. Prioritization with context. Threat intelligence, asset criticality and compensating controls can shrink tens of thousands of findings to the handful that are reachable and mission relevant.
  3. Exploitability validation. Safe testing confirms which exposures can actually be exploited in the agency’s environment. BOD 26-04 demands evidence-based risk outcomes, not theoretical risk.
  4. Autonomous remediation. Machine-speed patching, governed by reliability scoring, phased rollout and automatic rollback, is the only mechanism that can close the long tail inside a 72-hour window.

Risk operations strategies deserve a fresh look across government

In an environment where adversaries can weaponize newly discovered flaws in hours, continuing to rely on human-speed patching is a risk to essential services and national security. Automation is one component, alongside improved visibility, smarter prioritization and closer ties between mission leaders and security teams. The final step is how to modernize fast enough to keep essential services and national security intact, without overpromising what technology alone can do.

Frontier AI has permanently changed the input side of the vulnerability equation. BOD 26-04 changes the output side, requiring agencies to prove risk reduction rather than count patches. The organizations that thrive under the directive will be the ones to build a closed loop where detection feeds prioritization, prioritization feeds validated exploitability and validation feeds autonomous remediation.

Policy has moved. Emerging technology has accelerated and the attack surface as we know it has exploded. The missing piece is an operating model built around continuous risk evaluation, not periodic, sequenced remediation. The organizations that embrace the ROC model as their transformation mode of security operations are the ones that will be cyber ready when the next wave of AI-driven threats arrives.

Nathan Smolenski is chief information security officer at Qualys.

Copyright
© 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.



——————————————————-


Click Here For The Original Source.