A recent analysis of internet-facing systems across 1,293 organizations in the US, UK, and Nordics revealed that the vast majority of critical and high-severity vulnerabilities remain unaddressed for over 90 days. Specifically, 97% of such flaws in the Nordics, 92% in the UK, and 86% in the US had been exposed for more than three months at the time of the study.
The findings, based on payload-based testing that confirms exploitability, indicate that these organizations are generally aware of the vulnerabilities. While a long-lived flaw might be deliberately left open due to low asset value, existing compensating controls, or planned system retirement, the prevalence of such old vulnerabilities suggests a broader issue of "risk tolerance drift," where unaddressed flaws become implicitly accepted.
Among various sectors, public-sector organizations demonstrated the lowest remediation rate, resolving only 8.3% of their critical and high-severity findings within 90 days of detection. This contrasts sharply with consumer packaged goods and brand companies, which resolved 46.2%, followed by technology at 37.4%, financial and banking at 30.6%, and manufacturing at 23.9%. Across all severities, public bodies in the Nordics resolved 4.3% of vulnerabilities, and in the US, 2.3%.
Several factors likely contribute to the public sector's slower remediation, including extensive legacy infrastructure, fragmented ownership of systems, lengthy procurement and change-management processes, limited specialist cybersecurity capacity, and systems that cannot easily be taken offline for maintenance. Effective remediation in these environments often requires clearer asset ownership, better prioritization based on risk, and streamlined processes for addressing critical vulnerabilities.
Geographically, UK organizations actively monitor 72.4% of their verified internet-facing domains, significantly higher than the Nordics (31.9%) and the US (28.9%). However, UK customers have historically closed the lowest percentage of critical and high findings ever raised (18.6%), compared to the US (20.7%) and the Nordics (31.9%). The Nordics, despite having the highest percentage of old vulnerabilities in the snapshot, also show the highest overall closure rate, suggesting they address more issues but leave a persistent backlog.
The US has the largest measured attack surface, with its verified domains growing approximately 20% in the last year, adding over 100,000 new domains. UK domains grew 14%, and Nordic domains 3.4%.
A growing concern is the increasing number of publicly exposed AI platforms, such as Lovable and Base44, on customer estates. Early data indicates that organizations with exposed AI tooling resolve critical and high-severity flaws at less than half the rate of the general customer base. While this may not necessarily be "shadow AI," as much of it could be known and approved, it highlights a potential gap in asset visibility and governance.
Tools like Open WebUI or LibreChat can be deployed rapidly by individual teams, sometimes bypassing standard inventory, ownership, and security review processes. The challenge lies in ensuring that AI infrastructure is visible, governable, and subject to the same vulnerability management and remediation protocols as all other internet-facing assets, rather than allowing experimentation to create invisible infrastructure.






