The new initiative, announced during Cyber Security Awareness Month, signals a shift from the traditional “patch‑and‑train” mantra to a year‑round discipline that prioritises shrinking the window between exploitation and remediation.
Qualys’ Threat Research Unit (TRU) supplied the backdrop for the call, revealing that the volume of closed vulnerability events surged 6.5‑fold between 2022 and 2025 – from roughly 73 million to 473 million – while the average time‑to‑exploit turned negative, meaning many flaws are weaponised before they are publicly disclosed.
To capture this accelerating risk, Qualys introduced a new metric called Average Window of Exposure (AWE), which measures the elapsed time from when a vulnerability is exploited to when it is finally remediated. The metric underscores that traditional mean‑time‑to‑remediate figures no longer reflect true exposure.
Industry leaders argue that simply hiring more staff will not keep pace with “machine‑speed” attacks, especially as autonomous AI tools accelerate exploit development. Instead, they advocate consolidating fragmented security data, applying business context to prioritize critical assets, and automating safe remediation actions.
The Mathspace breach, which exposed over one million Australians and New Zealanders after a patch remained unapplied, is cited as a cautionary example of how delayed remediation can translate into a large‑scale business incident.
Experts recommend establishing a Risk Operations Centre that fuses asset intelligence, vulnerability data, threat intel and remediation workflows, allowing human analysts to focus on high‑impact decisions while automated systems handle routine correlation and patch deployment.
The overarching message for Australian organisations this Cyber Security Awareness Month is clear: move from counting closed tickets to measuring the reduction of business risk, and act fast enough that attackers never get a foothold.