CSAIChaptersEventsBlog
Join Anthropic, AWS, Google Cloud, Microsoft, SANS, and more this August at the SANS Cloud Security Exchange Summit →
Open Peer Review Tag

The VulnOps Operating Model

Open Until: 08/19/2026

AI Safety

The VulnOps Operating Model
Vulnerability management still runs on periodic cycles: scheduled scans, monthly patch windows, CVSS-sorted queues. AI is breaking that model on both ends. Discovery has accelerated sharply, with autonomous tools surfacing hundreds of validated vulnerabilities in a single pass and vendors shipping AI-accelerated patch volumes that dwarf prior release cycles. Remediation throughput has not kept pace, and the gap shows up directly in the data: vulnerability exploitation is now the leading initial access vector, and organizations fully remediated only a quarter of known exploited vulnerabilities in 2025. This paper proposes VulnOps, an operating model that replaces batch vulnerability management with a continuous pipeline, in the same way DevOps replaced scheduled software releases. Three inbound streams, pre-release code, deployed systems, and external disclosures, converge on one flow of triage, validation, sequencing, deployment, and verification, gated by evidence rather than schedule. The paper defines absorption rate (findings resolved versus findings created) as the program's core health metric, sets out governance and human-in-the-loop requirements for agent-driven discovery, and lays out the prerequisites and pilot structure for standing up the function within an organization.
Key Takeaways
  • Vulnerability management's batch model (scheduled scans, monthly patch windows, CVSS queues) is breaking under AI-accelerated discovery and vendor patch volume.
  • Exploitation is now the leading initial access vector; only 26% of known exploited vulnerabilities were fully remediated in 2025.
  • VulnOps replaces the cycle with one continuous pipeline across three streams (pre-release, deployed systems, external disclosures), gated by evidence rather than schedule.
  • Absorption rate (findings resolved ÷ findings created, rolling 30 days) is the core health metric; above 1.0 means the program is keeping pace.
  • Governance-in-the-loop (GITL) is default, with human-in-the-loop reserved for exploit confirmation, out-of-class production deployment, and external disclosure.
  • Seven prerequisites (named owner, asset inventory, deployment automation, etc.) must be in place before piloting; the recommended charter timeline is 12 months.

Contribute to Peer Review

Peer Review Agreement

By participating in this peer review, you acknowledge and agree to the following:

  • Your name will be included as a reviewer only if you provide substantive feedback (e.g., content, clarity, accuracy). Feedback limited to grammar, syntax, or formatting will not qualify for acknowledgement.
  • CSA's authors will have final discretion over which suggestions are incorporated into the document. Not all feedback will be implemented.
  • You will not plagiarize or submit unmodified AI-generated text. If using AI-generated content, you must apply your expertise to refine, reformat, or integrate it meaningfully into the document.
Peer Review Illustration

Open Until: 08/19/2026

Featured by CSA

Want to see your content featured here?

Contact us to learn more!

Premier AI Safety Ambassadors

Premier AI Safety Ambassadors play a leading role in promoting AI safety within their organization, advocating for responsible AI practices and promoting pragmatic solutions to manage AI risks. Learn more about how your organization could participate and take a seat at the forefront of AI safety best practices.

Explore More of CSA

Research & Best Practices

Stay informed about the latest best practices, reports, and solutions in cloud security with CSA research.

Upcoming Events & Conferences

Stay connected with the cloud security community by attending local events, workshops, and global CSA conferences. Engage with industry leaders, gain new insights, and build valuable professional relationships—both virtually and in person.

Training & Certificates

Join the countless professionals who have selected CSA for their training and certification needs.

Industry News

Stay informed with the latest in cloud security news - visit our blog to keep your competitive edge sharp.