top of page
shield_bg_smaller_edited.jpg

Stay in the know with Sapphire's industry insights

background_edited_edited.jpg

A Vulnerability Wave Is Building and Most Organisations Are Not Ready

  • Jul 7
  • 4 min read

Updated: 6 days ago



For over 30 years, Sapphire has helped organisations understand and manage cyber risk across IT and OT environments. Today, one theme is coming through louder than ever.


The vulnerability landscape is shifting fast. There is a lot of noise right now around AI driven cyber attacks. From Anthropic’s Claude Mythos preview to wider hype around autonomous attackers, it is easy to think this is all about new threats.


But the real story is something else entirely. It is about the scale of vulnerabilities already sitting across organisations, and the wave that is now building. This was a key theme at Cyber UK, and it is only becoming more urgent. Organisations need to take a step back, reassess what they are doing, and make a clear plan. The vulnerability wave is already here.


The warning from the NCSC


The UK’s National Cyber Security Centre has warned that a “patch wave” is coming.

This is not speculation. It is the result of years of accumulated technical debt across systems, applications, and infrastructure.


As NCSC CTO Ollie Whitehouse explains, organisations have prioritised short term gains over building resilient products. Now, with AI accelerating vulnerability discovery, that backlog is being exposed all at once.

Artificial intelligence is enabling skilled individuals to identify and exploit weaknesses at scale and at speed. The result is a forced correction across the technology ecosystem.


In simple terms, more vulnerabilities are going to be found, and they will need to be fixed quickly. This is the patch wave.


Why this matters now


This would be challenging enough on its own. But the reality is that many organisations are already struggling to keep up.

At the same time, attackers can act in hours or days. That gap is where risk lives. The patch wave will only increase the pressure. More vulnerabilities. More patches. Less time to respond.


AI is accelerating the problem, not creating it


There is a lot of focus on AI as a new source of cyber risk  and is exposing what was already there.

Phishing and stolen credentials are still the most common entry points. Attackers are not relying on entirely new techniques. They are taking advantage of existing weaknesses.


What has changed is speed. AI lowers the effort required to find vulnerabilities and shortens the time it takes to exploit them. It  enables vendors to discover and patch issues faster, which adds to the growing volume of updates.


What the patch wave looks like in practice


This is not just theory. Recent examples show how quickly this can scale. AI tools such as Claude Mythos are already being used to identify significantly more vulnerabilities in widely used software.


This highlights the real challenge for organisations. It is not just about finding vulnerabilities. It is about being able to respond at the same pace.


The three priorities for organisations


To respond to this shift, the NCSC outlines three clear priorities:


1. Prioritise external attack surfaces


Focus first on systems exposed to the internet.


Start with your perimeter, then move inward across cloud and on premises environments. If you cannot patch everything, prioritise what attackers can reach first. It’s important to recognise that some systems cannot be patched. Legacy or unsupported technology may need to be replaced or brought back into support.


2. Prepare to patch faster and at scale

The patch wave will require faster and more frequent updates.

Enable automated updates and hot patching where possible. Where this is not available, ensure processes support rapid, risk based decisions, even where there are operational trade offs.


3. Go beyond patching


Patching alone will not solve the problem.


The underlying issue is technical debt. Organisations need to strengthen cyber fundamentals, reduce reliance on outdated technology, and improve overall resilience.


Why traditional approaches will not hold up


Many organisations still follow a traditional model.


Scan. Report. Prioritise. Fix.


In a patch wave scenario, this approach struggles.


There is simply too much to fix, and not everything matters equally.


As per our understanding, Gartner® highlights the need to move towards continuous exposure management. This means prioritising what is actually exploitable and what matters most to the business, not just what appears on a scan.


A shift in leadership focus


The patch wave is not just a technical challenge. It is a leadership one.

Cyber leaders need to change how risk is discussed and understood.


They need to act faster, focus on outcomes, and recognise that the vulnerability wave is already here.



Gartner® is a trademark of Gartner, Inc. and/or its affiliates.

bottom of page