Left Arrow Icon
All articles

Enterprises Rebuild Vulnerability Remediation as a Business Continuity Program

The Security Digest - News Team
Published
August 3, 2026

Chris Thatcher, Director of Cyber Security Solutions at EPAM Systems, explains why AI collapsing the window between vulnerability discovery and exploitation forces enterprises to fund remediation, legacy modernization, and incident rehearsal as one board-level program.

Credit: The Security Digest

Make The Security Digest one of your go-to sources on Google

Google Icon
Add The Security Digest on Google
Quote Icon
Close to 25% of zero-days are being exploited within the first 24 hours, while the mean time to remediate in the enterprise is still five months. Every day that we know about a problem and do nothing is self-inflicted exposure.

Chris Thatcher

Director of Cyber Security Solutions

Chris Thatcher

Director of Cyber Security Solutions
EPAM Systems

CDK Global went down and thousands of car dealerships wrote up sales by hand for weeks. The Change Healthcare breach left pharmacies unable to process claims. MGM's casino outage showed up in the next quarter's earnings. None of the three involved AI. Two came down to stolen credentials, the third to a convincing phone call, and basic identity validation would have stopped all of them. That was the easy version.

Chris Thatcher is Director of Cyber Security Solutions at EPAM Systems, a digital engineering and consulting firm that builds and modernizes software for large enterprises. He's spent more than thirty years in business and sales leadership, the last twenty-five in security and compliance, and holds a CISSP. He recently published a book on the translation gap between technical and business audiences, the same gap that decides whether remediation work gets funded.

"Close to 25% of zero-days are being exploited within the first 24 hours, while the mean time to remediate in the enterprise is still five months," Thatcher says. "Every day that we know about a problem and do nothing is self-inflicted exposure."

The backlog stopped being a safe place to put things

For years, the model was simple. Fix what's marked critical or high, let everything else pile up. One client is carrying backlog items twenty years old. That no longer holds.

"People have demonstrated with AI they can stitch together these low and medium severity vulnerabilities into high severity and criticals," he says. "That backlog we've been shoving into a closet for twenty years is no longer a safe space." The discovery side has gotten cheap, and it doesn't require anyone's flagship model. In his experience, it comes down to coordinating ordinary models through a harness, which puts attacker-side speed within reach of more people than the headlines suggest.

Clearing tens of thousands of findings is not a job for a staffed team. Thatcher sorts the work into three tiers, automating what can be automated, using AI to triage the middle band before handing it to people for final patching, and reserving people for the most sensitive applications. "It's not a security problem. It's an engineering solution to a business continuity problem."

Legacy systems AI can read fluently

The second exposure is the estate nobody wanted to touch. Financial systems, inventory systems, and SCADA environments in power and energy run on platforms that lost support years ago, in languages whose authors have retired.

"Nobody's writing the code," Thatcher says. "AI can read and write it fluently." Modern energy operators lost their air gap along the way, since those systems now have to reach the internet and cloud to function. "It was never affordable before AI, and it wasn't vulnerable before AI. Now it's both affordable to fix and vulnerable to those who don't fix it."

Catching defects before they promote

Cleaning up the past only buys time. "As long as we're developing code, we're going to be introducing vulnerabilities," Thatcher says. His answer puts agentic monitoring across code repositories, triaging and patching in real time. "If you can get agentic AI into your development pipeline, you can reduce vulnerabilities that are actually promoted into production."

Getting it funded

The failure Thatcher sees most often is financial, not technical. Teams try to fund this from existing budget, and the scope is too wide for that to work.

One North American client brought in two Big Four firms and got back three-hundred-page reports cataloging every exposure and recommending nothing. "The easy part is shining a light on the problem. The hard part is putting the engineering processes in place to actually do the fixing." Thatcher's team paired that assessment with a plan, working across the CISO, CIO, and CTO. The board approved it without asking the price and asked when work could start. A European client with more than 10,000 engineers put 20% of them on remediation almost immediately.

That requires authority the middle of the organization doesn't have. "The thing that makes it most difficult is silos and tribalism," Thatcher says. "If you come at it from the bottom up, you're herding cats. You're given a task without the authority to execute." The programs making progress treat this as one coordinated effort rather than a set of projects.

None of it matters if the response plan is fiction. Thatcher started as an auditor, opening binders five years out of date, listing contacts who'd left and systems that no longer existed. What companies need is a clear inventory of business-critical applications, an honest read on the likeliest incidents, and a plan they've actually run.

"They need to rehearse that," he says. "Rehearse it in a way that makes it real and makes it hurt, makes people uncomfortable enough that they make changes, and then they do it again." The alternative is figuring it out live, which is how weeks of downtime start.