Discussion about this post

User's avatar
Max's avatar

The exploit survival curve is the chart that matters. If nothing survives six weeks and the median exploit lands in a day, then every software defence is competing on the same clock as the attacker, and it is a clock software cannot win.

Jenny’s point about buying cycles goes further than incumbency. If procurement takes a quarter and exploitation takes a day, the only defences that hold are the ones that do not need to be re-bought, re-tuned or re-patched per threat. That is a hardware property, not a software one.

We are building exactly that at VISS: a hardware appliance that reduces the endpoint to a pixel stream over an optical air gap, so an attacker who owns the PC has no executable path to the endpoint. Any exploit, any speed, same result: dead end.

Whether the new sheriffs are software platforms or hardware primitives is, I think, the real question behind this chart.

Aziz's avatar

Reading this from the GCC, where we invest behind cyber growth, the procurement point in the comments inverts.

In Saudi, buying is not the binding constraint. National Cybersecurity Authority, Central Bank, and Capital Market Authority (SEC in the US) mandates budget in place ahead of the threat rather than after it, and boards approve on a compliance timetable, not an incident one. What is scarce is people to operate what has been bought, and data residency rules that keep much of the global stack outside the estate.

So the same collapse in exploitation timelines selects for something different here: not the fastest tool, but the one that runs with the fewest hands and lands inside the sovereign boundary.

(On the 87% — the Zero Day Clock was rebuilt after this went out and has retired that metric; its current read is roughly 130 of c.485 for H1.)

4 more comments...

No posts

Ready for more?