Key Insights:
Security Debt Is Now a Board-Level Governance Emergency
Critical security debt means vulnerabilities that are both high
severity and high exploitability. 60% of organizations carried it in
2026 – a 20-point surge driven by detection programs that are
outpacing fix capacity.
60% of organizations now carry critical security debt. A year ago
it was 40%.
AI-Generated Code Is Accelerating the Compliance Gap
AI-assisted coding is outpacing security governance. The liability
load that creates will surface in audits, breaches, and
enforcement actions – and no compliance framework explicitly
governs it yet.
85% of AI-generated code failed security tests for cross-site
scripting in controlled test cases.
Two-Thirds of Critical Security Debt Comes from Vendors
SBOM mandates are active across automotive, government,
healthcare, and defense. Most organizations don’t have the SCA
programs to meet them. Third-party flaws also take the longest
to fix – 358 days on average.
66% of critical security debt traces to third-party supply chain
components, with a 358-day SCA fix half-life.