Security
60% of enterprises take over a week to patch critical vulnerabilities despite AI threats: Kai report
2026-07-30
Most enterprises continue to rely heavily on manual vulnerability management processes even as AI accelerates cyberattacks, with 60% taking more than a week to remediate critical vulnerabilities, according to a new global survey of chief information security officers (CISOs).
The inaugural 2026 State of Autonomous Defense Report from cybersecurity company Kai found that security teams are struggling to match the speed of AI-driven attacks, exposing a widening gap between machine-speed threats and human-led cyber defence.
The survey of 500 CISOs found that 65% of organisations still depend on vulnerability management processes that are at least half manual, while 48% leave at least one-quarter of known vulnerabilities unpatched for more than 30 days.
Although 89% of respondents said their organisations are prepared for AI-driven cyberattacks, only 28% described themselves as "very prepared," suggesting that confidence has yet to match awareness. Nearly two-thirds (63%) believe attackers currently hold the advantage because of AI.
The report also highlights the operational burden facing security teams. More than three-quarters (77%) of CISOs said vulnerability management contributes to employee burnout, while most organisations still require human involvement to validate remediation activities and approve automated actions.
Despite these challenges, enterprises are gradually becoming more comfortable with automation. Around 55% of organisations already use automation for asset discovery and inventory management, while 49% automate vulnerability prioritisation. Nearly one-third (32%) now permit automated remediation in selected scenarios.
However, trust remains the biggest obstacle to wider adoption of autonomous security operations. More than half (52%) of respondents cited lack of confidence in automated decision-making as the primary barrier, followed by governance and compliance concerns (43%) and shortages of skilled cybersecurity professionals (38%).
Looking ahead, organisations expect machine-led security operations to become more common. Currently, 35% of respondents describe their vulnerability management programmes as primarily machine-led, a figure expected to rise to 45% over the next 12 to 18 months.
"The real opportunity today is trusted automation that doesn't just prioritise risk; it eliminates it," said Galina Antova, co-founder and CEO of Kai. She said security teams increasingly need AI systems capable of responding to threats at machine speed rather than relying solely on manual intervention.
Alongside the report, Kai introduced Auto Remediation, a capability designed to automatically assess confirmed vulnerabilities, determine whether they can be resolved safely without human intervention and either execute remediation or prepare change plans for security teams.
The findings underscore a growing shift in enterprise cybersecurity from AI-assisted detection toward autonomous remediation. While organisations are increasingly adopting AI to identify vulnerabilities, the survey suggests most security operations still rely on manual processes, leaving defenders struggling to keep pace with increasingly automated cyberattacks.
The inaugural 2026 State of Autonomous Defense Report from cybersecurity company Kai found that security teams are struggling to match the speed of AI-driven attacks, exposing a widening gap between machine-speed threats and human-led cyber defence.
The survey of 500 CISOs found that 65% of organisations still depend on vulnerability management processes that are at least half manual, while 48% leave at least one-quarter of known vulnerabilities unpatched for more than 30 days.
Although 89% of respondents said their organisations are prepared for AI-driven cyberattacks, only 28% described themselves as "very prepared," suggesting that confidence has yet to match awareness. Nearly two-thirds (63%) believe attackers currently hold the advantage because of AI.
The report also highlights the operational burden facing security teams. More than three-quarters (77%) of CISOs said vulnerability management contributes to employee burnout, while most organisations still require human involvement to validate remediation activities and approve automated actions.
Despite these challenges, enterprises are gradually becoming more comfortable with automation. Around 55% of organisations already use automation for asset discovery and inventory management, while 49% automate vulnerability prioritisation. Nearly one-third (32%) now permit automated remediation in selected scenarios.
However, trust remains the biggest obstacle to wider adoption of autonomous security operations. More than half (52%) of respondents cited lack of confidence in automated decision-making as the primary barrier, followed by governance and compliance concerns (43%) and shortages of skilled cybersecurity professionals (38%).
Looking ahead, organisations expect machine-led security operations to become more common. Currently, 35% of respondents describe their vulnerability management programmes as primarily machine-led, a figure expected to rise to 45% over the next 12 to 18 months.
"The real opportunity today is trusted automation that doesn't just prioritise risk; it eliminates it," said Galina Antova, co-founder and CEO of Kai. She said security teams increasingly need AI systems capable of responding to threats at machine speed rather than relying solely on manual intervention.
Alongside the report, Kai introduced Auto Remediation, a capability designed to automatically assess confirmed vulnerabilities, determine whether they can be resolved safely without human intervention and either execute remediation or prepare change plans for security teams.
The findings underscore a growing shift in enterprise cybersecurity from AI-assisted detection toward autonomous remediation. While organisations are increasingly adopting AI to identify vulnerabilities, the survey suggests most security operations still rely on manual processes, leaving defenders struggling to keep pace with increasingly automated cyberattacks.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




