Risk-based maintenance is the future. AI has made it into table stakes

CISA’s Binding Operational Directive (BOD) 26-04 marks one of the most significant changes in state risk management in recent years. Rather than requiring agencies to address all significant risks on the same timetable, the guidance prioritizes risk-based remediation, with timelines ranging from three days for the highest risk to postponement for those that pose a lower risk. A welcome evolution, but it brings us to the starting blocks, not the finish line.
Security teams have long known that sharpness alone does not mean vulnerability. The CVSS score says little about whether the vulnerability is available online, exploitable, can be automated or gives an attacker control of the asset. BOD 26-04 acknowledges the context of risk by directing organizations to focus first on potential exposures.
However, AI is disrupting all stages of the attack lifecycle, changing the threat landscape faster than risk management processes can adapt. CrowdStrike reports that eCrime’s average exit time (Initial Lateral Movement) has dropped to 29 minutes, the fastest takeoff seen. 27 seconds. Once attackers gain a foothold, Mandiant found that they provide access between users in 22 minutes.
At the same time, AI itself is growing as an attack surface. Organizations are rapidly deploying backups, browser agents, automated workflows and other AI-powered systems, which introduce data, plugins, connectors and integrations that need to be protected.
Against this backdrop, the three-day guidance window for high-risk disclosures looks less like an aggressive target and more like a luxury.
Today’s attackers don’t just exploit CVEs. They combine vulnerabilities with stolen identities, cloud misconfigurations, exposed APIs, SaaS vulnerabilities and increasingly AI systems to build attack methods into valuable assets. BOD 26-04 takes us further, but AI requires defenders to not just speed up existing processes, but rethink them.
AI has changed the tempo and economics of cyberattacks
One of the biggest advantages of AI for attackers is its ability to automate tasks that previously required teams of humans. Surveillance, vulnerability research, exploitation, phishing, evidence harvesting and other aspects of collective movements can now be accelerated or, in some cases, greatly streamlined by AI.
Recent research has shown private agents doing most of the work for complex online campaigns while humans oversee broader objectives. As a result, campaigns become easier and less expensive to scale, more targets can be tracked simultaneously and attackers can explore more paths to a site before defenders realize they are being probed.
For years, risk managers assumed that organizations had weeks, or even months, to identify, prioritize and fix security issues. That thinking no longer reflects reality. Attackers often go from initial access to lateral movement in less than an hour, and vulnerabilities are often exploited soon after being discovered, and in some cases exploited before defenders even begin to explore them.
That’s why CISA’s move to risk-based adjustment matters. Prioritizing vulnerabilities based on exploits and operational vulnerabilities gives defenders the best chance of addressing problems that can be used against them. But risk represents only one piece of the picture of today’s world.
Modern attacks follow methods, not discoveries
Most security organizations still divide responsibilities into specialized teams. Risk management focuses on CVEs. Identity teams focus on authentication and authorization. Configuration of cloud security addresses. Application security update code.
Attackers do not meet those same restrictions. Their goal is to reach the valuable asset using any route available. A campaign may start with an exposed vulnerability, stolen data, excessive cloud permissions, a poorly configured SaaS application or a corrupted AI agent. More often than not, several of those conditions are combined. For example, the 2026 Verizon Breach Report found that while 31% of initial exploits last year were vulnerable, 39% of attack chains involved proprietary issues. For every significant breach, attackers combine various types of exposures to develop within networks.
An attacker who compromises a low-privileged account may gain an over-authenticated identity, navigate a heavy cloud workload, exploit a vulnerable operating system and ultimately gain access to critical business systems. None of these exposures would seem catastrophic when viewed independently. Together, they form an effective attack method.
With breaches often being a series of multiple exposures, and vulnerabilities representing only part of the story of how a breach actually occurred, this is where vulnerability-focused security begins to break down. CrowdStrike also reported a 42% year-over-year increase in exploits, before sellers even announce themselves. That means organizations working hard to block hundreds of high-stakes discoveries will be breached because they lack the context necessary to block an effective route an attacker can take to their sensitive assets.
Organizations must consider a breach and plan for where an attacker might end up. Security architectures should be as isolated as possible and limit how far an adversary, or a vulnerable AI agent, can travel after that initial compromise. And security controls should be continuously verified rather than simply assumed to be effective because they have been successfully implemented.
These goals shift attention away from individual discoveries and toward situations that allow for successful attacks.
How defenders can practice: Continuous assessment and validation
One effective way to make this change is to commit to implementing a Continuous Threat Exposure Management (CTEM) program, which establishes an ongoing process to understand and reduce exposure.
It starts with something that many organizations still struggle to maintain: the current understanding of the environment. That means continuing to map assets, ownership, cloud infrastructure, SaaS applications, AI systems and the relationships between them. From there, security teams can identify exposures, prioritize them based on usability and business impact, ensure they are truly achievable, and drive remediation across functional teams.
This continuous cycle restores what Mandiant calls the Defender’s Advantage. Attackers must first discover an unfamiliar environment before they can exploit it. Defenders already have that information – or should. The challenge is to keep it up as cloud services, ownership, AI applications and business systems evolve every day.
Embed validation into the process
Security teams also need to ensure that the exposures they find can actually be exploited and that remediation efforts remove significant vulnerabilities.
This is where verification of the opponent’s exposure becomes an important part of the process. Technologies such as breach and attack simulation, automated penetration testing and attack pattern analysis allow organizations to proactively assess their environments using techniques similar to real adversaries.
Instead of asking whether a vulnerability exists, exposure verification answers practical questions: Can an attacker access it? Can they exploit you? Can they pivot to something the business really cares about? Equally important, validation ensures that remediation efforts actually close the door rather than simply reducing the number of findings on the dashboard.
Put the business first, not the dashboard
Validation becomes even more valuable when integrated into the context of the business. A centralized vulnerability affecting a revenue-generating application, controlled data or critical operating system may represent a greater risk to the organization than multiple vulnerabilities affecting isolated development areas.
Prioritizing proven exposures in terms of business impact gives security leaders a remediation strategy that they can explain to management in operational rather than technical terms. More importantly, it directs defensive efforts and attack methods that may affect the organization.
BOD 26-04 is an important step forward. But AI has already made table stakes for risk-based amendments. In the age of AI, the most successful organizations will not be the fastest. They will be the ones who understand their exposure better than the attackers trying to exploit it.
This article was published as part of the Foundry Expert Contributor Network.
Want to join?



