A recent survey of 200 senior security and technology leaders reveals significant concerns about the escalating complexity of software security programs, particularly in the wake of increased AI adoption. Over half of the respondents, primarily from companies with 10,000 or more employees, anticipate struggles in simplifying their security operations if current practices persist.
The core challenge identified is the post-scan process: determining the criticality of a flagged vulnerability, identifying its owner, and coordinating remediation across diverse teams and release schedules. This often leads to delays, with the median time to fully resolve a critical vulnerability currently standing at 43 days, according to Verizon's 2026 Data Breach Investigations Report.
AI is contributing to this pressure from two directions. While AI tools accelerate software development, AI-assisted scanning simultaneously uncovers a greater volume of weaknesses. Forty percent of respondents cited the sheer amount of AI-generated code awaiting human review as their most significant software security challenge. Although AI-generated code is not inherently insecure, its volume often overwhelms human review capacity. This figure represents the top concern for those respondents, indicating its prominence among the listed options.
To address this, a tiered strategy for AI-assisted vulnerability discovery was identified by 44% of respondents as the most critical transformation needed. This approach advocates for automation to handle deterministic tasks such as repeatable, low-risk findings, remediations, and mitigations. These tasks are well-suited for established workflows involving normalization, enrichment, ownership routing, ticket management, SLA management, and rescan verification.
The middle layer of this strategy would involve AI agents, which are software capable of performing multi-step tasks with limited supervision. These agents excel at deeper investigations and reasoning, such as assessing signals for reachability and exploitability, identifying correlated findings, and surfacing potential attack paths. Given the judgment calls involved, strong guardrails for auditability and review are essential.
Human involvement would be reserved for critical decisions and their consequences, including risk acceptance and exceptions. The goal is not to eliminate human oversight but to focus limited human time and attention on decisions requiring sound judgment and accountability. Ideally, this layered approach would also involve reviewing findings that reach human attention to identify opportunities to automate similar work in the future.
A primary concern for these leaders is the influx of low-context alerts—warnings that flag weaknesses without providing crucial information such as system reachability, exploitability, dependent business services, or responsible parties. This creates a dual problem of excessive volume and insufficient context for security teams.
Another significant challenge is the proliferation of security tools and the numerous handoffs required to address a finding. A single vulnerability might originate in one scanner, require context from multiple other systems, be prioritized by security, and then be assigned to a developer, cloud engineer, or external vendor. Each step in a separate workflow introduces context loss and delays. When considering tool consolidation, the advice is to merge tools with overlapping functions that produce undifferentiated findings, while retaining and connecting tools that offer significant depth or unique coverage through a common data layer. Key questions for each tool include its unique coverage, signal quality, integration capabilities, and user trust.
For reporting to the board, the primary metric should be the time to remediate meaningful, exploitable, and exposed systems, demonstrating an improving trend in risk management. Leaders also require visibility into organizational challenges, recognizing that organizations are often a collection of teams, assets, products, and business units, each contributing to overall exposure. This visibility helps identify areas needing support, where change is occurring, and potential hotspots across the organization.






