Security1 publisher3 min readPublished
Detectify finds most exploitable flaws on customer perimeters have been open more than 90 days
Detectify found 86% to 97% of open critical and high flaws on 1,293 customers' internet-facing systems had been exposed for more than 90 days. Its scanner confirmed each with a working attack request, so these are known, reachable flaws left to age.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Public-sector organizations resolved 8.3% of critical and high findings within 90 days of first detection, the lowest of five sectors, against 46.2% for consumer brands.
- Among customers with Detectify for at least a year, US verified domains grew about 20% in 12 months, adding more than 100,000, against 14% in the UK and 3.4% in the Nordics.
- Organizations with publicly exposed AI platforms such as Lovable and Base44 resolve critical and high flaws at less than half the rate of the wider customer base, early Detectify numbers show.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Every finding past 90 days needs a recorded decision to accept it; without one, Detectify calls the result risk tolerance drift, where age alone gets a flaw treated as accepted by default.
- exposure About 71% of US customers' verified domains are outside active monitoring, so the fastest-growing estate adds unwatched reachable systems each year unless coverage keeps pace.
- constraint UK results show wider monitoring does not by itself raise closure rates, so scan coverage cannot stand in for remediation as a program metric.
Only a small part of the backlog is recent. In the US, the best-performing of the three markets [2], fewer than one in seven open critical or high findings is under three months old [4]. In the UK the share is 8%, and in the Nordics 3% [1].
Detectify warns against reading that as slow patching. The 90-day figure describes the backlog on a single day. It does not measure how fast teams usually patch, because a few long-lived legacy problems can dominate a snapshot even where most findings close quickly [5]. The Nordic data fits that pattern. Nordic customers have closed 31.9% of all critical and high findings ever raised, the best lifetime rate of the three markets, while holding the stalest backlog [14][2]. Detectify's reading is that Nordic teams close more overall and leave a stubborn remainder to age [15].
The sector data does not rule out slow remediation either. Those rates count fixes made within 90 days of first detection, and no sector reached half [2]. Consumer packaged goods and brand companies closed the most on that measure [8]. They still posted the worst hygiene score of any sector, 56.2, largely because of their large backlogs [9]. On this evidence an ageing pile and slow fixing show up together, and a one-day count cannot say how much of the backlog each one explains [5].
Every figure comes from Detectify's scanner run against Detectify's own customers [1]. Detectify also allows that a flaw rated critical may sit on a low-value asset, behind other protections, or on a system due for retirement, and that leaving it open may be deliberate [6].
Public bodies close the least [8]. Across all severities they formally resolved 4.3% of their vulnerabilities in the Nordics and 2.3% in the US [10]. On critical and high findings within 90 days, consumer brands resolved about 5.6 times the public-sector share [4]. Rickard Carlsson, Detectify's CEO, described where public-sector fixes stall. "A security team may know exactly what needs to change, but the affected system could be owned by another department, depend on an old vendor, require a procurement process, or support a service where downtime carries real consequences," he said [11]. He went on: "Public bodies need clearer ownership of exposed assets, better prioritization based on which exposed assets matter most, and faster routes to address the small number of vulnerabilities that create the greatest risk." [12]
The AI comparison is early. Detectify did not publish the rate or the number of organizations behind it [18]. "At this stage, we'd be cautious about calling shadow AI the cause," Carlsson said [19]. He added: "The data shows an association, and one plausible explanation is that both reflect the same gap in asset visibility and governance, but that's something we're continuing to investigate." [20]
What to watch
- Time-to-fix data by market from Detectify would show how much of the 90-day backlog is slow patching and how much is a legacy remainder.
- The rate and organization count behind the exposed-AI-tooling comparison, and whether the association holds as Detectify keeps investigating.
- Whether US customers' 28.9% monitoring share rises as their verified domain count keeps growing.