Urgent.News

600+ sources. One page. See who else covered it.

Editions

Tech

Why security debt belongs on the boardroom agenda

the importance of security debt and how businesses should address it.

Why security debt belongs on the boardroom agenda

Security leaders have made strides in enhancing threat detection across businesses, identifying vulnerabilities in applications, dependencies, and development pipelines with greater consistency. However, a persistent issue remains: vulnerabilities are being discovered at a faster rate than they can be remediated. Currently, 82% of organizations carry security debt, defined as unresolved vulnerabilities that have persisted for over a year.

Furthermore, the proportion of severe vulnerabilities likely to be exploited is growing, leading to their persistence in production environments long enough to be weaponized.

Describing security debt as financial debt can help business leaders appreciate its impact. Like financial debt, security debt accumulates and compounds when left unmanaged, resulting in delayed releases, emergency remediation efforts, audit findings, incident responses, and heightened organizational risk. To manage security debt effectively, organizations need to understand the extent of their debt, prioritize vulnerabilities based on their significance, and make informed decisions about where to allocate remediation resources. Ignoring this aspect will only exacerbate the backlog and increase the organization's overall risk.

The primary challenge lies in capacity, not visibility, as organizations typically know where many of their security vulnerabilities lie. However, their engineering teams struggle to resolve them quickly enough, leading to security debt growth. To gain support from the wider C-suite, CISOs must demonstrate this capacity gap by highlighting the disparity between discovered and fixed vulnerabilities, the duration of unresolved high-risk issues, and the exposure of critical systems.

Presenting remediation as an operational constraint makes it easier for executives to grasp the broader business benefits of addressing it, such as improved engineering capacity, reduced costs, and enhanced service availability.

When evaluating the success of security debt reduction, focus should not solely be on the count of vulnerabilities found or closed, but rather on factors such as the number of exploitable vulnerabilities in critical systems, their average age, and the overall security debt. Implementing formal risk acceptance for unresolved high-risk issues, coupled with dedicated engineering time, automation, and AI-assisted remediation, can substantially improve remediation throughput without hampering development progress.

Not every vulnerability poses the same level of risk. While severity scores like the Common Vulnerability Scoring System (CVSS) can be useful, they do not consider exploitability, enterprise context, or the criticality of affected applications. A more effective approach would involve combining severity with exploitability and organizational context to pinpoint the small percentage of vulnerabilities most likely to impact the business.

Prioritizing crown-jewel applications—such as customer-facing platforms, revenue-generating services, or applications handling sensitive data—enables organizations to mitigate risk more effectively while providing security leaders with a clear way to communicate remediation priorities using business terms rather than technical jargon.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.

Read the original at techradar.com →

More in Tech

How to Handle Audio Transcription API 404/501 — available=false Speech-to-Text in 2026

Short answer: route production supplier-invoice audio to an external speech-to-text provider whenever the model catalog does not advertise an available ASR model, and record that routing decision…

  • 404, 501, or available=false status indicates unavailable ASR model
  • External speech-to-text provider recommended for production invoices
  • System implements ASR port with catalog check and tenant usage ledger