Back

Rethinking threat exposure in 2025: CISO takeaways from Verizon's DBIR

¨

Romy Haik

July 2, 2025
Insight
Share

Verizon's 2025 Data Breach Investigations Report (DBIR) contains stark data on the growing role of vulnerability exploitation in breaches, with direct implications for how security leaders should approach exposure management.

Key findings from the 2025 DBIR

  • 34% increase in breaches via vulnerability exploitation year-over-year; vulnerability exploitation now accounts for 1 in 5 breaches

  • Edge devices and VPNs represent 22% of exploited assets — an 8x increase from the prior year

  • 70% of espionage-motivated breaches involved vulnerability exploitation as the initial access method

  • Median time to patch remains 32 days across organizations

  • Only 54% of edge device vulnerabilities are patched — nearly half remain unpatched

  • Application and API critical vulnerabilities average 74.3 days to remediate

The pattern is clear: attackers are increasingly targeting known vulnerabilities in internet-facing infrastructure, particularly edge devices and VPN appliances, and organizations are not patching fast enough to keep up.

CISO takeaways

Detection alone is not enough. The gap between vulnerability disclosure and patch deployment gives attackers a window of 30-75 days on average. Organizations need to know which vulnerabilities are actually being exploited in the wild (using EPSS data and threat intelligence) and which of those are present in their specific environment.

Validation-first prioritization is essential. With limited patching capacity, security teams must prioritize the vulnerabilities that represent the greatest real-world risk — not just the highest CVSS scores. Validation-first CTEM confirms which vulnerabilities are actually exploitable in your environment, enabling smarter prioritization.

Edge device and API security requires continuous monitoring. The 8x increase in edge device exploitation means these assets need to be continuously scanned, not just assessed periodically.

¨

Romy Haik