Detectify analyzed exposure data from 1,293 customers in the US, the UK and the Nordics, using payload-based testing to confirm findings. At the snapshot, 97% of open critical and high-severity vulnerabilities in the Nordics had been exposed for more than 90 days, with 92% in the UK and 86% in the US. Even in the best-performing market, fewer than one in seven open critical or high findings was less than three months old.
Remediation varied sharply by sector. Public bodies formally resolved 8.3% of critical and high findings within 90 days, the lowest of five sectors, while consumer packaged goods and brands resolved 46.2%, technology 37.4%, financial and banking 30.6%, and manufacturing 23.9%. Detectify's CEO pointed to legacy infrastructure, fragmented ownership, procurement processes, limited specialist capacity, and systems that cannot easily be taken offline as likely reasons.
A 90-day backlog snapshot does not measure normal patching speed, since a few long-lived legacy issues can dominate even where most findings close quickly. The useful question, the source argues, is whether each old item was deliberately accepted; flaws left open long enough can otherwise drift into being treated as accepted by default. The UK actively monitored 72.4% of verified domains but closed the lowest lifetime share of critical and high findings (18.6%), while the Nordics closed the most (31.9%) yet held the stalest backlog. Detectify also found an association between publicly exposed AI tooling and slower fixes, but cautioned that this may reflect the same asset-visibility and governance gap rather than shadow AI. As this is a single-source report, there are no competing findings to compare.