Security scoring usually answers how bad is this? It rarely answers how soon? — which is the question that decides whether anyone acts.
The Exposure Window exists because the interval between a weakness becoming known and being exploited has collapsed from years to days, and that collapse is measurable rather than rhetorical.
How long the weakness is likely to sit there before someone uses it. Measured in days, banded, and driven by the strongest single piece of evidence on the company.
What it costs if the window closes — expressed by mechanism rather than a single dollar figure, because the mechanisms differ enormously in severity.
The two readings are published together and never blended into one number. This is the standard decomposition of risk into likelihood and consequence used by NIST SP 800-30 and ISO 27005, and it aligns with FAIR (Factor Analysis of Information Risk, The Open Group), which separates Loss Event Frequency from Loss Magnitude. Multiplying them into a single figure would destroy the ability to name the driver — and the driver is the only part a buyer can act on.
It was an observation. Gordon Moore counted components on a chip in 1965, saw a doubling roughly every year, and said so. In 1975 he revised the period to roughly two years.
It became a planning instrument for an entire industry not because it was exact, but because it was simple, checkable, and revised in public when the data moved.
That precedent matters here in two ways. First, it legitimises stating a rate constant and re-fitting it as evidence accumulates: a versioned constant is normal practice for an empirical law, not a weakness in one. Second, it sets the bar for adoption. A number people cite has to be auditable.
The fastest way to kill a measure like this is to hide its arithmetic.
Components per integrated circuit doubling roughly every year. Published as a counted trend, not a theory.
Period revised to roughly two years. Revised in public, with the data that forced it.
The interval between a vulnerability becoming known and being exploited in the wild is cut in half approximately every 24 months — until it reaches zero, after which exploitation begins to precede disclosure.
The second clause is not a refinement — it is a terminus. An exponential approaching zero never arrives, so the curve needs an arbitrary floor to stay sensible. The observed series did arrive, in 2026, and then continued: the average vulnerability is now exploited before it is disclosed. Past that point the curve stops describing anything, because the quantity it models — days of window remaining — no longer exists. The law is retained for the interval it governed and is not extrapolated beyond it. See §6.
The published series on time-to-exploit — average days from disclosure to observed exploitation, on one consistent measure.
| Period | Time-to-exploit | |
|---|---|---|
| 2018–19 | ~63 days | |
| 2020–21 | ~44 days | |
| 2021–22 | ~32 days | |
| 2023 | ~5 days | |
| 2026 | ~24 hours | |
| 2026 · the inversion | before disclosure | |
| 2026 · AI capability measured exploit build time | 11 min |
Sources, row by row. 2018–19 through 2023: Mandiant time-to-exploit research. 2026 observed: Zero Day Clock, with Mandiant M-Trends 2026 reporting 28.3% of vulnerabilities exploited inside 24 hours of disclosure. The inversion row is that same distribution once its tail is included — the average crosses zero because a growing share is exploited before the advisory exists. The bar grows leftward for that reason: it is not a very short window, it is the absence of one.
The final row is a capability measurement and is deliberately set apart. 11 minutes and $2.83 is the median cost and time for autonomous agents to produce a verified working exploit from a disclosed vulnerability in a controlled harness — 72% success across 3,029 CVEs. It is not an observed attack time, and reading it as one merges two different metrics. It explains why the window is not reopening; it is not a point on the series above it.
On the 2023 figure. Mandiant published ~5 days after excluding 15 statistical outliers; the same dataset, untrimmed, averages ~47 days. Same authors, same study — one is the trimmed headline, the other the raw mean. This paper quotes the ~5 days Mandiant led with, and records the untrimmed figure here rather than in the chart, so the series stays one consistent measure while a reader who knows the ~47 finds it acknowledged rather than omitted.
Mandiant does not attribute the 2023 shift to AI. Their stated cause is a change in sample composition: 97 of the 138 vulnerabilities exploited in 2023 — 70.3% — were used as zero-days, moving the n-day/zero-day ratio from roughly 4:6 to 3:7. A zero-day is exploited before a patch exists, so as its share of the sample grows, measured time-to-exploit falls toward zero regardless of how fast exploits are written. They further note that improved zero-day detection may mean 2023 reflects earlier years more accurately rather than a real acceleration. See §10, Limitations.
These readings are not the same measurement as the series above and are deliberately not plotted on the same curve. They count different things, and conflating them is the single easiest way to lose a technical audience. Each is named with what it measures.
| Reading | What it measures | Source |
|---|---|---|
| 28.3% | Share of CVEs exploited within 24 hours of disclosure. Time-to-exploit has effectively gone negative. | Mandiant, M-Trends 2026 |
| ~24 hours | Average disclosure-to-exploitation in 2026, down from ~53 days in 2024. | Zero Day Clock |
| 80 days | CVE publication to CISA KEV inclusion, H1 2026 — down from 120 days in 2025. A much larger number because it counts catalogue entry, not exploitation. | VulnCheck, H1 2026 |
| 11 min · $2.83 | Capability, not observed timing. Median cost and time for autonomous AI agents to turn a disclosed vulnerability into a verified working exploit in a controlled harness — 72% success across 3,029 CVEs. Work that took a skilled researcher days or weeks. | Controlled study, July 2026 |
The first three measure exploitation as observed in the wild. The fourth measures what an attacker can build, in a harness, and says nothing about how quickly attacks occur. Stating it as “attacks now happen in 11 minutes” merges two different metrics and is the one error a technical reader will catch. Stated as capability it is unarguable — and it is the reason the window is not reopening, not the reason it closed.
Counter-evidence held on the record: VulnCheck’s H1 2026 report found that of 1,061 vulnerabilities attributed to AI-assisted discovery, only 14 — 1.3% — were confirmed exploited in the wild, roughly the baseline rate. That measures AI-discovered bugs, not AI-written exploits, so it does not contradict the capability figure above. It is recorded here because a reader who knows it should find it already answered.
This is the constraint that keeps the model honest, and the one most easily got wrong.
Time-to-exploit measures the gap between disclosure and exploitation. A spoofable domain has no disclosure date — nobody publishes an advisory saying a company left DMARC at p=none. Applying exponential compression to it is a category error.
The cost of getting this wrong is measurable. Run the compression across every class and, at three years elapsed, the factor of roughly 0.35 drags a hygiene-only company from a 180-day baseline to about 64 days. Every company scored becomes critical — and a measure that says “critical” about everyone is ignored by everyone.
Exposure with a disclosure date behind it. The underlying interval genuinely is compressing, so the law applies.
Exposure with no disclosure event. Governed by attacker volume rather than disclosure cycles, so bands stay flat.
p=none), vulnerabilities present but all scoring below 0.01 on EPSS, or weak transport security.The curve needs a floor of 1 day, or it predicts sub-hour windows and becomes absurd. On the curve that floor arrives around 2030. In reality it arrived in 2026, four years early — and the measure did not stop there.
More than a quarter of vulnerabilities — 28.3% — are now exploited within 24 hours of disclosure, and across the full distribution the average has gone past zero: the typical vulnerability is exploited before it is disclosed. When exploitation precedes disclosure, “days of window remaining” is no longer a quantity that exists. The thing being counted changed sign.
That is the substantive conclusion of this method rather than a footnote to it, and it is now measured rather than projected. Once exploitation arrives before disclosure, no patch cycle operated by people can be fast enough in principle — the defender is not late, the defender is behind at t = 0. The only remaining levers are continuous monitoring, managed response, and reducing what is externally visible in the first place.
This is also why the window is not reopening. Autonomous agents now produce a verified working exploit from a disclosed vulnerability at a median of 11 minutes and $2.83, work that took a skilled researcher days or weeks. That is a capability measurement, not an observed attack time — but capability of that cost does not un-happen. See §3.
The backbone is the Compliance Gap: a count of detected findings that map to controls the company is actually required to meet, produced by cross-referencing each finding's standards against the regimes governing its industry.
It is countable and auditable rather than rhetorical. Consequence is then expressed by mechanism, not as a single dollar figure — because the mechanisms differ enormously in severity.
The sharpest exposure is not a fine. A contractor without the required certification cannot be awarded work — and an inaccurate self-attestation carries False Claims Act exposure.
Enforced by the card brands through the acquiring bank rather than by government. Losing the ability to accept cards is existential for a retail or hospitality business.
Where the regime is licensure-based, the consequence mechanism is suspension or revocation of the authority to operate — not a penalty that can be absorbed.
Observed on the public internet.
This regime governs this company's industry — inferred from the industry classification.
The statutory or contractual maximum if a breach occurs. Always cited, never a prediction.
We do not generate company-specific loss estimates. Penalties are quoted as published maxima; averages are quoted as industry averages and named as such. Where no exploitable path is found, the report says so rather than manufacturing urgency — a measure that alarms on every prospect has no information content.
All collection is passive. Nothing here involves authentication, intrusion, or any interaction beyond what an ordinary visitor or a public database already sees.
The date each vulnerability became public — t0 in the law.
Archived responses retain the origin's original headers, so a missing security header can be dated to the oldest capture that also lacked it.
First-seen dates for SPF and DMARC records, which live DNS cannot provide — a TXT record carries no creation timestamp.
Catalogue of vulnerabilities confirmed exploited in the wild.
Probability a given vulnerability is exploited within the next 30 days.
Vulnerability records for software fingerprinted from public responses.
Internet-facing ports, hostnames and reported vulnerabilities.
Whether the company's own domain appears in a public breach corpus.
Subdomains disclosed in public certificate logs.
Every standard this product can cite on a finding — who issues it, who it binds, what it requires, and what non-conformance actually costs. 16 of the 53 carry a caveat, and the caveat says which kind. Varies by state means no single maximum exists — that is a permanent property of the statute, not outstanding work. Adjusts annually means a real published figure that moves each January under the Federal Civil Penalties Inflation Adjustment Act; those are pinned with a date. Only unverified would mean not yet checked against a primary source.