FL Fredrik Lindstrom

Cyber Governance

When the Security Product Becomes the Breach

The metrics that matter when the control is the exposure. Why the board dashboard of the last decade is finished, and the six numbers that replace it.


Hero — When the security product becomes the breach.

By Fredrik Lindstrom · ~13 minute read · July 2026

On 11 February 2025, Ivanti shipped a fix for a buffer overflow in Connect Secure, its remote-access product. The company had assessed the flaw as low risk, not exploitable for anything worse than a denial of service, so the fix went out quietly in a point release. No CVE. No advisory. Nothing for a customer to act on.

A China-nexus group took the patch apart, worked out what had been fixed, and built a working remote-code-execution exploit against every customer still running the older version. Google’s threat intelligence team dates the first observed exploitation to mid-March. Ivanti disclosed on 3 April, by which point the flaw had a CVE, a 9.0 severity score and a month of intrusions behind it.

The product was a security product. Its one job was to control who reached the corporate network. It became the way in, and the quiet fix was the map.

An MRI is a diagnostic device. It exists to find disease and it has no licence to cause any. Radiation therapy is the opposite case: it harms by design, dosed and targeted, and the harm is justified by what it cures. That distinction is the whole argument. A machine that only exists to detect carries a harm budget of zero, and one that started seeding the condition it was built to find would not be recalibrated. It would be pulled from every hospital that owned one. The same must apply to the vendors selling security.

A security product sits on the diagnostic side of that line. It is bought to find and stop attacks, not to trade harm against benefit. There is no dose to justify.

On the customer side of the Ivanti story, nothing in a standard board pack could have turned red. There was no CVE to track, no advisory to log, no missed patch deadline, no absent control. The vendor itself was saying there was nothing to see. Green, vacuously.

That is why the security dashboard of the last decade is finished. The metrics boards learned to trust rest on two assumptions, and both are now gone, if they were ever valid.

The first was that threats move at human speed.

The second was that the security stack is the solution rather than part of the attack surface.

What follows are the numbers that replace them, starting with the one almost no board has ever been shown.

The control became the exposure

The first metric is the share of your critical exposure this quarter that originated in the products you bought to reduce exposure.

No board pack I have seen carries this line, because security spend is reported as protection and never as surface. The firewall, the secure-access gateway, the endpoint agent, all of them sit as line items under defence. None appears under risk introduced. When a defensive product opens the door, the failure lands nowhere on the report the board actually reads.

This is not one vendor having a bad year. On 9 December 2025, Fortinet disclosed two critical authentication bypasses in FortiCloud single sign-on, CVE-2025-59718 and CVE-2025-59719, both scored 9.8. Arctic Wolf observed malicious logins against FortiGate appliances on 12 December, three days later. The attackers signed in as administrator and exported the device configuration file, hashed credentials included.

Six months on came the case that matters more, because it never produced a vulnerability at all. In June 2026, researcher Kevin Beaumont and others confirmed an exposed dataset holding administrator and VPN credentials for roughly 74,000 internet-facing FortiGate devices across 194 countries. Beaumont’s Shodan-based estimate put that at close to half of every such device reachable from the internet. Around 30,800 of the credentials were verified as still working. Fortinet’s position was that no new flaw existed in its products: the credentials traced to earlier compromises and to brute force against devices with weak passwords and no multi-factor authentication. That answer was technically defensible, and it was also beside the point.

Split the affected population and you can see why. One part of it did have weak passwords and no MFA, and that part failed controls any competent programme already measures. The other part did not. What made the dataset crackable at scale was a design decision: Fortinet moved administrator credentials to PBKDF2 hashing in FortiOS 7.6.1, which shipped in late 2024 and was backported through 2025, but the upgrade rehashed nothing already stored. An administrator’s password stayed in the older SHA-256 format until that administrator next logged in, and a backward-compatibility setting could hold the weaker hash even after that. A device could be running current firmware, fully patched, clean on every compliance check, and still holding its administrator credential in the format an attacker cracks offline the moment a configuration file leaks.

For that second group there was no CVE, no patch to apply and nothing a vulnerability dashboard could render. Eighteen months after the stronger algorithm shipped, the exposure was still sitting in the gap between upgrading and the upgrade taking effect, and no metric in the standard reporting set was pointed at that gap.

Which tells you how to build the metric, and how not to. If vendor-introduced exposure is sourced from the KEV catalogue alone, it would have caught both Fortinet bypasses and the Ivanti flaw once each carried a CVE, and it would have read green straight through the credential case. KEV requires a CVE and a remediation action. Define the metric by origin instead: exposure attributable to a security product, whatever shape it arrives in, drawn from KEV matches, vendor advisories, disclosed design and migration gaps, and your own credential-store audits. The credential case is the reason the metric cannot stop at KEV.

Scope the claim honestly too. Two vendors is not a whole stack, and the demonstrated pattern here is internet-facing security appliances rather than every product with a security label. That pattern is real and measurable: network-edge devices account for roughly a third of the 2025 KEV entries flagged as ransomware-linked, and VulnCheck’s work on edge devices suggests KEV undercounts the category. Run the number for your own estate before you accept mine.

This is where the medical frame stops being a rhetorical device. Primum non nocere, first do no harm, is the physician’s founding obligation, and a diagnostic tool that becomes the injury has broken it. That obligation belongs in the contract, which is where procurement and finance come in.

The clock the old metrics never showed

The second number is the gap between how fast you remediate and how fast the flaw is weaponised.

Mandiant has tracked that interval for years. Its figures put the average at 63 days in 2018, minus one day in 2024, and an estimated minus seven for 2025, published in M-Trends 2026. Exploitation now routinely precedes patch availability. Patched within 30 days was a defensible bar when weaponisation took two months. Against minus seven it describes a race that ended before the team clocked in.

The honest caveat sharpens the point rather than blunting it. That average is computed over vulnerabilities that were exploited, and it is dragged below zero by the growing share of zero-days in the sample. Which is exactly the problem: the flaws attackers now prefer are the ones no patch cadence can beat. So the population has to be split, and the board pack has to split with it.

For flaws disclosed before anyone exploited them, the race is winnable and the measurement is straightforward: days from KEV listing to remediation, per item, against the published due date. For flaws exploited before a patch existed, patch speed is not the control at all. Detection and containment are. That means dwell time and blast radius belong on the same page, and a board reading only remediation speed is being shown half the fight.

This is not a fringe reading. In an April 2026 note titled “Fortifying the enterprise: 10 actions to take now for AI-ready cyber resilience,” JPMorganChase’s Global Technology Leadership Team wrote that adversaries are compressing the time from vulnerability discovery to exploitation, and that patch and remediation cycles are accelerating, often exceeding an organisation’s capacity for change. The same note is blunt about exercises: plans that have not been tested under realistic conditions will fail under real pressure. When the technology function of America’s largest bank says the patch-cadence model has broken, the board can stop treating it as a vendor talking point.

None of this is news to the security team. Exploitation-led prioritisation has been federal practice since CISA’s BOD 22-01 in 2021, and in June 2026 BOD 26-04 went further, moving federal remediation off CVSS base scores onto a risk model built on exploitation status, exposure and impact, with a three-day tier for the most dangerous entries. Your team has almost certainly worked this way for years. The failure is not in the programme. It is that the board pack still shows severity-bucketed counts, twelve criticals and three hundred and forty highs, which launders exploitation reality out of governance entirely. A CVSS score rates theoretical impact. It says nothing about whether anyone is using the flaw.

What the dashboard still isn’t showing

The third number is whether your incident response has been tested under pressure, not whether your leadership believes it would hold.

Barclays surveyed a thousand senior decision-makers across UK businesses this spring, from micro firms to large enterprises, and fewer than three in ten were confident in their ability to respond to a major cyber incident. Confidence is not a metric. An exercise is. What belongs on the report is not whether a response plan exists, because every organisation has a plan in a binder, but when an outside party last put it under pressure and what that surfaced. An asserted readiness is a feeling. A tested readiness is a date, an adjudicator and a list of findings.

One more belongs there before it belongs in a breach post-mortem. In Okta’s 2026 research, only about a third of executives said their organisation always applies the same security controls to its digital workforce as to its human one. That is an admission at organisation level, not a census of agents, and the gap between those two things is itself the point: most boards cannot say how many agents are running, let alone what controls they carry. Agent governance coverage is the number, and it has to be paired with what an independent sweep finds outside the inventory, or it improves every time discovery gets worse.

Who owns which number

A metric without an owner is a slide. Each of these needs a name against it.

The Board

The board must stop accepting a green dashboard as evidence of safety, and start refusing any pack that arrives without numbers benchmarked against an adversary rather than against last quarter. A programme that looks finished against its own task list can be wide open against the threat. Management builds these numbers. The board is the body positioned to refuse the pack without them, and regulators on both sides of the Atlantic are moving toward demanding exactly that.

The CISO

The executive reporting upward must define “the control failed” as a measurable event before anyone else can act on it. Report exposure, not activity. “We closed 4,000 tickets” is activity. “Our exposure window against actively exploited flaws is eleven days, and three of our defensive vendors account for a quarter of it” is exposure. One of those sentences changes a decision.

Procurement

Procurement must stop accepting the standard liability cap on security-critical functions. Security obligations already appear in contracts all the time, and since January 2025 DORA Article 30 has made them mandatory for EU financial entities. What almost never appears is a remedy costing the vendor more than an apology. The obligation exists on paper. The price of breaching it does not.

The achievable ask is not uncapped liability, which no platform vendor sells at any price a buyer can pay. It is a security super-cap, a stated multiple of fees with carve-outs for breach of security obligations, alongside committed remediation windows and evidence-of-security warranties. Delta is still litigating against a cap of roughly twice fees paid after the 2024 CrowdStrike outage, which tells you what the boilerplate is worth when it matters.

Then let the arithmetic bind. If your remediation window runs to forty days and a vendor has historically shipped actively exploited flaws more often than that, being exposed is not an accident, it is the expected state. Crossing that line should make no-buy the automatic position, reversible only by a documented risk acceptance signed at board level, naming the compensating controls and carrying a dated review. Not an unappealable veto, which no board can lawfully adopt and which would empty the market anyway. A default the board has to sign its name to override, with the number and the signature both on the record, feeding straight into what finance carries.

Anyone who thinks buyers cannot move a vendor on security terms should look at what happened to Microsoft. The audit logs that detect exactly this class of intrusion sat behind the E5 tier, at around fifty-seven dollars per user per month, until Storm-0558 took State and Commerce email in 2023 and the logging gap became public. CISA, the FBI and a run of customers called it pay-to-play security. Microsoft made those logs free for standard customers. Jen Easterly, then CISA director, noted it took more than a year of collaborative work. Nobody blacklisted anyone. Concentrated buyer pressure moved the largest software company on earth on a term it had already priced and sold.

The CFO

Finance must price the residual, and the instrument matters. Accounting standards will not let you book a reserve against generalised future cyber risk. ASC 450 requires a loss that is probable and reasonably estimable from a past event, IAS 37 requires a present obligation, and general reserves for unspecified business risk are prohibited outright. Which is precisely why this exposure hides so well: it can sit off the balance sheet and off the dashboard at the same time.

So quantify it instead and put it on the risk report. Retained exposure is modelled loss, less what the vendor contract actually returns, less what the insurance tower pays after retention and exclusions. Two gaps sit behind the green dashboard, not one: the liability cap and the coverage gap. That figure is the most honest number in the programme, and it is the one the board signs against whenever it overrides a procurement block.

What the new dashboard looks like

Six numbers fit on one page. Each benchmarks against an adversary rather than against the organisation’s own task list, each carries a named owner, and each has a threshold that forces a conversation rather than a footnote.

MetricThe question it answersWhere the data comes fromRed line
Vendor-introduced exposureWhat share of our critical exposure this quarter originated in the products we bought to prevent exposure?KEV matches, vendor advisories, disclosed design and migration gaps, credential-store auditsShare rising across three quarters, or any security-product entry without remediation or compensating control at 72 hours
Exposure window, disclosed-first flawsFor flaws disclosed before they were exploited, are we closing faster than they are being weaponised?Days from KEV listing to remediation, per item, against the CISA due dateAny item past its CISA due date, or past 72 hours with no mitigation in place
Dwell time and blast radiusFor flaws exploited before any patch existed, how long were they inside and how far could they reach?Detection telemetry and segmentation testing, benchmarked to the published medianDwell time above the current published median, or lateral reach untested this year
Tested response readinessWhen did an outside party last put our response under pressure, and what did it surface?Date, adjudicator and findings of the last externally run exerciseNo externally adjudicated exercise in two quarters, or findings closed without retest
Agent governance coverageWhat share of AI agents in production carry the controls a human with the same access would carry?Identity inventory, paired with agents found by independent sweep that were not in itCoverage falling, or independent sweep finding agents absent from the inventory
Retained security exposureWhat loss would we carry ourselves after the contract and the insurance tower have paid?Modelled exposure, less contractual recovery, less insurance recovery net of retentionExposure unquantified, or not re-modelled after a material vendor incident

Report the first three monthly and the last three quarterly. Every line carries a date and a direction of travel against its external benchmark, because a number without a trend is an anecdote. The 72-hour thresholds are not arbitrary, and they are no longer aggressive: they match the tier CISA now applies to federal agencies for the most dangerous exploited flaws.

Who counts the counters

Every metric above can be gamed by the people who report it, and pretending otherwise would repeat the mistake this piece is about. The security function decides what counts as a security product, what registers as an agent, what qualifies as a full exercise. Reward “it held” and you will get exercises designed to hold. Score coverage against a self-maintained inventory and coverage improves every time discovery gets worse.

Financial reporting faced this exact problem and answered it structurally. After Enron and WorldCom, Sarbanes-Oxley made named executives certify the numbers personally, required management to assess its own internal controls, and put an independent auditor on that assessment. Security reporting has none of the three. It also has no restatement mechanism: when a vendor incident proves last quarter’s exposure figure was wrong, nothing compels anyone to correct the record.

So write the defences in at the start. Freeze the definitions in a charter the board approves, and version every change so it shows up in the trend. Have the numbers attested outside the security function, by internal audit or an external assessor. Have exercises designed and adjudicated by someone who does not own the outcome, and report findings surfaced and closed rather than a binary verdict. An exercise that passes every time is measuring its own design.

Security posture done right produces compliance as a by-product. The reverse has never held. A passed audit is a lagging indicator of a security posture, not a substitute for one, and an instrument calibrated to produce passing audits will keep reading green right up to the morning the breach is on the front page.

Minus seven days is not the floor. Every economic incentive of automated exploitation pushes that interval further in the attacker’s favour. The boards still reading a green dashboard a year from now will not be measuring whether they are safe. They will be measuring how long ago they stopped looking.