Open critical and high flaws exposed for over 90 days, Nordics: 97% (Source: Detectify customer exposure data, reported by Help Net Security (September 30, 2026))
The data cannot say why these flaws are old
Detectify's report cannot explain why serious flaws stay open. It does raise a question that every security program should be able to answer. Did someone choose to leave this open?
That is our argument, not Detectify's finding. The figures reported here are counts. They say nothing about who owns each flaw or who decided to leave it open.
Detectify is a security vendor. Its report draws on 1,293 customer accounts across the US, the UK and the Nordic countries. It counts flaws rated critical or high on systems that anyone on the internet can reach.
The UK figure was 92% and the US figure was 86%. The report's coverage says these organizations already know about the flaws. Detectify says it confirms findings with real test requests: it sends a working attack request and checks the reply. So the open items are ones the scanner judged exploitable.
What the 90-day figure can and cannot show
The number is a photo of one day. It does not show how fast teams usually patch. A handful of very old problems can skew the picture even when most findings close quickly.
So the data cannot separate slow fixes from stalled ones.
Some old flaws may be fine to leave. The affected system might matter little, sit behind other protections, or be due for retirement. In those cases, the delay could be a reasoned call. The sample also covers one vendor's customers, not every organization.
Detectify names the poor version of this risk tolerance drift. A flaw sits open so long that the organization ends up accepting it without ever saying so. Detectify offers this as a lens for reviewing a vulnerability program. It is not a finding about these customers.
Public bodies close the fewest
Detectify counted critical and high findings resolved within 90 days of first detection. Public-sector organizations resolved 8.3%, the lowest of five sectors. Manufacturing managed 23.9% and financial and banking 30.6%. Technology reached 37.4%, and consumer goods and brands 46.2%.
Detectify CEO Rickard Carlsson told Help Net Security that public bodies rarely face a single obstacle. He described a mix: aging technology, responsibility split across departments, slow buying and approval cycles, thin specialist staffing, and systems that are hard to switch off.
Consider a team that knows exactly what to change. The system may still belong to another department, rely on an old supplier, need a purchase order, or run a service where an outage hurts people. Carlsson's remedy starts with clearer ownership of exposed assets.
Watching and fixing are separate measures
Coverage differs sharply by market. UK customers keep active watch over 72.4% of their verified public domains. Nordic customers watch 31.9%, and US customers fall below 30%, at 28.9%.
The UK's closure record is the lowest of the three markets. Counting every finding since accounts opened, UK customers have closed 18.6% of critical and high items. The US has closed 20.7% and the Nordics 31.9%.
The Nordics also carry the oldest backlog. The pattern suggests Nordic teams clear many findings but leave a hard core untouched, and those items age. Visibility helps, but it does not close anything by itself. The two measures differ: one is the share of domains watched, the other is the share of all findings ever closed. Three markets are too few to show a relationship between them.
US customers have the widest set of systems reachable from outside, yet they watch the smallest share of them. Among accounts a year old or more, the count of verified US domains rose roughly a fifth in twelve months. That is over 100,000 added. The UK count rose 14% and the Nordic count 3.4%.
Exposed AI tools: an association, not a cause
Detectify's researchers report more AI platforms, such as Lovable and Base44, sitting openly on the internet inside customer environments. Early figures suggest these organizations close critical and high flaws at under half the pace of the wider customer group. Detectify did not publish the exact rate or say how many organizations were compared.
Carlsson urged caution. A public AI tool, he said, is not proof of shadow AI, since many may be known and approved. One plausible explanation is that both patterns come from the same weak asset visibility and governance. Detectify is still investigating.
His example was Open WebUI or LibreChat. One team can stand these up fast and may skip the inventory, ownership and security checks that older systems face. His worry is experiments that quietly become infrastructure nobody can see.
Questions to put to your team
First, ask for the list of critical and high findings older than 90 days. For each, ask who owns the asset and whether anyone signed off on leaving it open. An item with no owner and no sign-off is a candidate for drift.
Second, ask how many of those items sit on systems owned outside the security team. Ask what path exists to get them changed. Third, ask for an inventory of AI tools reachable from the internet, with the data and credentials each one can access.
An old flaw should have two things beside it: an owner and a reason. Without them, its age is the only record.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Help Net Security.





