Security Debt Is Growing Faster Than Companies Can Fix It. Here Is What That Means.
Eight in ten organisations carry a backlog of unresolved security flaws older than a year. A practical framework explains how to turn that reality into a board-level conversation.

Key points
- 82% of organisations carried security debt (unresolved software flaws older than one year) as of the latest research period.
- The share of vulnerabilities rated both severe and likely to be exploited is rising year over year.
- 11.3% of discovered flaws carry both high severity and high exploitability, making them the most urgent category.
- Remediation capacity, meaning the actual ability to fix flaws, is the binding constraint, not the ability to find them.
- Security debt affects regulatory standing and the ability to release software safely, not just technical operations.
Finding problems is no longer the hard part. Eight in ten organisations, 82% by current research, now carry what analysts call "security debt": software flaws that were discovered but never fixed, sitting unresolved for more than a year. The backlog keeps growing.
Think of it like financial debt. Left unmanaged, it compounds. Costs show up as delayed product releases, emergency remediation work and the expense of responding to an actual breach.
Organisations have better tools than ever for spotting flaws in their software and the third-party code those applications depend on. They don't have the capacity to fix what those tools find.
What should an ordinary business leader take from this?
The binding constraint is remediation capacity: the engineering time and tooling budget set aside to actually close vulnerabilities once they're found. When new flaws arrive faster than teams can address them, the backlog expands and the window for criminals widens.
Not every flaw carries equal risk. Security teams use a scoring system called the Common Vulnerability Scoring System, or CVSS, which rates how serious a flaw is on a numerical scale. Useful, but incomplete. CVSS doesn't tell you whether a flaw sits inside a system that processes customer payments, or whether criminals already have a working method to exploit it. We've tracked CVSS-related developments across eight stories since June, and the scoring system's limits come up repeatedly.
Research cited in the framework puts a sharper number on the problem: 11.3% of all discovered flaws combine high severity with high exploitability. That subset deserves a disproportionate share of attention.
Layer two filters on top of standard scoring: how reachable is this flaw, and how important is the system it lives in? Most organisations end up with a short, focused list that genuinely needs immediate action.
The same logic applies to which applications get priority. Every organisation has "crown-jewel" systems: customer-facing services, revenue-critical platforms, anything handling sensitive data. Fixing flaws there first produces the biggest reduction in real-world risk.
For executives, the metrics that matter aren't counts of flaws found or patched. More informative: how many high-exploitability flaws sit open in critical systems right now, and how old are they? That's the picture CISOs are being asked to translate into business language, as we reported on 6 July.
Investment in remediation capacity can take several forms: dedicated engineering time ring-fenced for security work, automated tools that suggest or apply fixes, and policies that stop new high-risk flaws from reaching production.
If you're a customer of any large software-dependent business, none of this requires action today. But if a company you use announces a breach, check whether your credentials or payment details were involved and change passwords on any shared accounts promptly.
The real watch item here isn't the debt figure itself. It's whether organisations start measuring vulnerability age in critical systems rather than raw counts. That shift in metrics is the one that actually changes behaviour.



