Security1 distinct publisher3 min readPublished
Verizon now puts vulnerability exploitation at 31% of initial access, up from 20%. Arctic Wolf's telemetry says about 17% of assets never appear in legacy vulnerability management at all, which sets a hard ceiling on any patch program.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Legacy vulnerability management is an enumeration problem before it is a remediation problem. Arctic Wolf's guide puts the root cause as siloed inventories: the identity provider holds users, EDR holds only the endpoints where the agent actually installed, and the CMDB holds whatever someone remembered to register [8]. None of those produces a list of assets that exist but were never enrolled. That is where the 17% sits [4].
The arithmetic is worth stating in units of machines rather than percentages. Seventeen percent of a sample of more than 800,000 assets is roughly 136,000 assets that no scanner was ever pointed at [2][4][12]. On the breach side, 20% to 31% is an 11 point move, about 55% growth in one report cycle [13].
The buckets do not stack. The same post reports 18% outside enterprise patch or configuration management, 10% with no endpoint protection, and 19% at end of life [5][6][7], and it publishes no overlap between those groups, so adding them into a single number for the exposed share of an estate is not supported. The 19% is the category with no patch to apply at all [7]. Discovery there produces decommissioning tickets and compensating controls, not remediation work.
Two notes on provenance. The material circulated in UK and US editions of the same Arctic Wolf post [14], so this is one vendor's telemetry appearing twice, not two datasets. And the DBIR figure is relayed by that vendor rather than read from Verizon here [1]. Arctic Wolf also asserts that closing the visibility gap costs less than a manual asset audit or an annual red team [9], a claim it makes as the supplier of the continuous alternative and without publishing a figure on either side.
The acronym sorting in the market (ASM, EASM, CAASM, exposure management) does not change any of the above. Neither does the model itself, which is inventory, then find exposures, then verify remediation [11]. CIS Controls 1 and 2 have asked for inventory of enterprise assets and inventory of software assets for years, and are the two oldest controls in the set [10]. What the DBIR delta changes is the order of operations, because an unpatched VPN appliance is an attack vector whether or not it appears in the console [16].
Practically, this reframes what a patch compliance report means. A 98% figure computed over the enrolled estate says nothing about the unenrolled part, and the useful question to put to whoever owns the number is how the denominator was built and what reconciles against it. Diffing the identity provider, EDR, and CMDB lists against each other is the cheapest version of that work, and the resulting mismatches are the queue.
Ranked by verification strength, evidence, and original report placement.
The same Arctic Wolf guide, with identical figures and headline, was published on both the arcticwolf.com UK blog and the arcticwolf.com US blog.
Arctic Wolf analysed more than 800,000 real-world assets.
Roughly a third of the assets analysed are missing at least one critical security control.
About 17% of the assets analysed are invisible to legacy vulnerability management tooling altogether.
18% of assets are not covered by enterprise patch or configuration management.
10% of assets are missing endpoint protection entirely.
Distinct publishers with included, body-backed reporting in this cluster.
2 articles · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
96% confident, 63% breached: the confidence number boards should stop accepting1 distinct publisher
security
CISA asks buyers to make eliminated vulnerability classes a contract condition1 distinct publisher
leadership
Exploited software flaws now open more breaches than stolen credentials do1 distinct publisher
security
43 days, 26 percent, and a pitch that saves you 29 minutes1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One document, two addresses
Every figure in this story comes from a single Arctic Wolf post that exists twice — UK blog and US blog, same hour, same numbers. The Verizon 31% is relayed rather than read: the 2026 DBIR is not among our sources, so the statistic carrying the headline arrives with no methodology attached. The telemetry beneath it is the company's own count of its own observed estate, with no sample definition and no outside audit.
A number of assets, no named users
The only real-world footprint on offer is Arctic Wolf's own: more than 800,000 assets under observation. Nobody deploying continuous attack-surface work is named, no customer speaks, and no third party has measured whether teams are closing these gaps or merely reading about them.
The leap, not the arithmetic
The numbers are plausible and modestly stated; the overreach is in the generalisation. That 17% of Arctic Wolf's observed assets sit outside legacy scanning is a fact about Arctic Wolf's telemetry, offered to the reader as a fact about 'the average environment.' Add an unpriced claim that fixing this beats a manual audit or an annual red team, and the gap between what was measured and what is implied does real work.
Each finding maps to a feature
The company measuring the problem sells the remedy, and the findings line up with the product almost item for item: invisible assets call for discovery, missing controls for coverage, end-of-life systems for prioritisation. The piece even pre-empts the buying objection — you needn't rip out your scanner or CMDB. Publishing the identical guide to US and UK audiences within the hour is distribution strategy, and it tells you what this text is for.
Sure of the shape, not the digits
Two things are beyond doubt: who is speaking and what they sell. What cannot be checked from here is whether a third of assets truly lack a critical control, or whether Verizon's 31% survived the trip into someone else's blog post intact. So we hold the structural argument — you cannot patch what never appears on a list — with some confidence, and the specific percentages at arm's length.