NuHarbor Security
  • Solutions
    Solutions
    Custom cybersecurity solutions that meet you where you are.
    • Overview
    • Our Approach
    • Data Icon Resources
    • Consultation Icon Consult with an expert
    • By Business Need
      • Identify Gaps in My Cybersecurity Plan
      • Detect and Respond to Threats in My Environment
      • Fulfill Compliance Assessments and Requirements
      • Verify Security With Expert-Led Testing
      • Manage Complex Cybersecurity Technologies
      • Realize the Full Value of Microsoft Security
      • Security Monitoring With Splunk
    • By Industry
      • State & Local Government
      • Higher Education
      • Federal
      • Finance
      • Healthcare
      • Insurance
    Guide Defining Whole-of-State Security: Building Resilient States Through Unified Cybersecurity
    Defining Whole-of-State Security: Building Resilient States Through Unified Cybersecurity
    Read Guide
  • Services
    Services
    Outcomes you want from a team of experts you can trust.
    • Overview
    • Data Icon Resources
    • Consultation Icon Consult with an expert
    • Security Testing
      • Penetration Testing
      • Application Penetration Testing
      • Vulnerability Scanning
      • Wireless Penetration Testing
      • Internal Penetration Testing
      • External Penetration Testing
    • Assessment & Compliance
      • ARC-AMPE Compliance
      • CJIS Compliance
      • NIST 800-53
      • HIPAA Security Standards
      • ISO 27001
      • MARS-E Security Standards
      • New York Cybersecurity (23 NYCRR 500)
      • Payment Card Industry (PCI)
    • Advisory & Planning
      • Security Strategy
      • Incident Response Planning
      • Security Program Reviews
      • Security Risk Assessments
      • Virtual CISO
      • Policy Review
    • Managed Services
      • SOC as a Service
      • Microsoft Security Managed Services
      • Splunk Managed Services
      • Tenable Managed Services
      • CrowdStrike Managed Detection and Response (MDR)
      • Vendor Security Assessments
      • Curated Threat Intelligence
      • Vulnerability Management
    Guide Defining Whole-of-State Security: Building Resilient States Through Unified Cybersecurity
    Defining Whole-of-State Security: Building Resilient States Through Unified Cybersecurity
    Read Guide
  • Partners
  • Resources
    Resources
    Explore reports, webinars, case studies, and more.
    • Browse Resources
    • Consultation Icon Consult with an expert
    • Blog icon Blog
    • Podcast icon Podcast
    • Downloadable Assets icon Downloadable Assets
    Guide Defining Whole-of-State Security: Building Resilient States Through Unified Cybersecurity
    Defining Whole-of-State Security: Building Resilient States Through Unified Cybersecurity
    Read Guide
  • Company
    Company
    We do cybersecurity differently – the right way.
    • Overview
    • Data Icon Resources
    • Consultation Icon Consult with an expert
    • Leadership
    • News
    • Careers
    • Contact
    Guide Defining Whole-of-State Security: Building Resilient States Through Unified Cybersecurity
    Defining Whole-of-State Security: Building Resilient States Through Unified Cybersecurity
    Read Guide
  • Consult with an expert
  • Client support
  • Careers
  • Contact
1.800.917.5719
NuHarbor Security Blog
    • Industry Insights
    • Security Operations
    • Compliance
    • Advisory and Planning
    • Cybersecurity Technology
    • Security Testing
    • Threat Intelligence
    • Application Security
    • Cyber Talent
    • Managed Detection and Response
    • Managed Services
    • NuHarbor
June 30, 2026

You Can Only Defend What You Can See

Jack Danahy Jack Danahy

In our last two installments, we’ve learned how two new, AI-enabled forces are working together against defenders. Machine-speed exploit development has collapsed the cost of building an attack, and that collapse has enabled attackers to generate a list of vulnerable targets simply by looking for known vulnerable code. Either force, alone, would strain a security program, but together they capitalize on a weakness that organizations have never been able to solve, and the pressure on that weak spot makes this moment different from the steady escalation in threat that security leaders have managed for years.

Simply, enterprise technology teams cannot provide a current and complete list of all the applications running in their environments. The configuration databases meant to track deployed systems consistently lag operational reality, shadow applications appear faster than governance can catalog them, and acquisitions absorb entire application portfolios that nobody ever inventoried during diligence. Even more troublingly, users are downloading apps and development teams are standing up cloud services that never enter any formal registry. The high-level inventory assumption and the facts on the ground quickly drift apart, and the gap in awareness grows in the dark.

None of this is negligence, but the accumulated result of decades of reasonable decisions made when application visibility was an important control, not an existential requirement. When cost compression shrinks the time to vulnerability exploitation, and scale of attacks is driven at machine speed, the enterprise visibility gap becomes the precise opening that AI-assisted adversaries are optimized to exploit.

The Gap Is Measurable

 Vanta, whose platform tracks application usage across its enterprise customer base, found that 55% of the average enterprise's applications operate outside formal IT governance. . These are not the common trope of abandoned test systems. They are production applications that process business data, carry vulnerable components, sit reachable from networks, but are invisible and unaccountable to the teams responsible for protecting them. They include new and leading technologies from @anthropic, @openAI, and @cursor, to name a few.

Even when applications are being tracked, they carry exposure that isn’t seen. The Black Duck 2025 Open Source Security and Risk Analysis Report found that 97% of commercial codebases contained at least one open-source component, and 81% contained a vulnerability rated high or critical. Nearly half of those high and critical flaws arrived through transitive dependencies, components no developer explicitly chose, pulled in automatically by other parts of the application. Of all the open-source components in a typical codebase, only one-third were deliberately included; the rest arrived the same way.

Layers No Developer Chose

Sonatype's analysis shows that the average enterprise application carries more than 180 third-party open-source components, and that 75% of vulnerable dependencies go unpatched for over a year, despite a fix being available for nearly all of them. Even when the fix is available, the enterprise awareness that it’s needed is not.

Log4Shell, in 2021, showed this mismatch at full scale. More than 80% of the packages affected by the Log4j vulnerability depended on the compromised component indirectly, and the exposure was invisible to every defender who had never had reason to look that deeply. That was a single event in 2021. The new potentially AI-accelerated campaigns will be built to find exactly that kind of invisible dependency across any application that touches a public network.

Four Commitments to Real Change

A compounding problem resists any single fix, so an appropriate response will need to be explained, championed, and sustained beyond the reach of the security team.

The enterprise, first, must understand and acknowledge the technical estate is larger than the documentation. This is a leadership call, because chief information and security officers need to stop measuring risk against the easy and known subset of applications in their records and deliver visibility into the full environment as it actually exists. The exercise will uncomfortably expose scope that governance never accounted for, but that visibility is now a table stake because adversaries can act against that full attack surface.

Defense against vulnerable applications must move upstream, not downstream. Official advisories commonly arrive well after the security community has described a vulnerability. The reality of that is described in detail in my recent post on AI acceleration. Security commits in public repositories are the canary in the coal mine, and an organization watching the upstream sources recovers time that downstream advisory monitoring has already given away.

Application visibility and transparency must become part of application and service procurement, now. Requiring a Software Bill of Materials (SBOM), a comprehensive inventory of every application component, as a condition of each new contract and renewal costs nothing to mandate. Paired with clear contractual terms for patching and disclosure, it stops new blind spots from forming, and while it may not fix the legacy of transparency debt, it also tells vendors exactly what the organization now expects.

Exposure and interoperability between applications and services must be audited and rationalized. Every application pulled back from direct internet reachability, or isolated from unrelated systems, raises the attacker difficulty and expense to find and attack it. For most organizations this is the highest-leverage action available while the deeper visibility work proceeds.

Information asymmetry is the attacker’s advantage. An AI-assisted adversary scanning public repositories does not need to understand your application inventory, it only needs to read the public code, identify the exploitable conditions, and target whoever has pulled that software down. The weakness is obvious to the attacker and invisible to the defender. Organizations that close that gap, that build current visibility into their real application estate, watch the upstream signals that precede published advisories, and treat component transparency as a governance requirement rather than a compliance checkbox, will have something to work with when the next wave arrives. The rest will keep learning about their vulnerable applications when someone else shows them.

 

Included Topics

  • Threat Intelligence,
  • Advisory and Planning,
  • Security Operations
Jack Danahy
Jack Danahy

Jack (he/him) is the Executive Vice President of Strategy and Operations at NuHarbor Security where he leads the creation and delivery of NuHarbor's leading cybersecurity services and platforms, simplifying cybersecurity for all organizations. Prior to joining NuHarbor, Jack founded three successful security software companies that were acquired by Watchguard Technologies, IBM, and Alert Logic. Following these acquisitions, Jack continued as a senior executive entrusted with strategy, messaging, and corporate development. In addition to business leadership, Jack has received 12 patents for his security innovations. Jack is a sought-after cybersecurity speaker, writer, and Pwned podcast co-host. His insights and opinions are regularly featured in leading online, broadcast, and print media, like CBS, NBC, Forbes, the New York Times, and the Washington Post.

Related Posts

Industry Insights 2 min read
Chevron Doctrine’s Fall: The Catalyst Cybersecurity Needed?
Read More
2 min read
Mastering the Art of Cybersecurity Communication: 6 Questions Every Leader Must Answer
Read More
Application Security 4 min read
The Path to Improve Your Application Security Posture Read More

Subscribe via Email

Subscribe to our blog to get insights sent directly to your inbox.

Subscribe Here!

Latest Pwned episodes

Breach of the Week -- Log4j vulnerability
May 12, 2026
Breach of the Week -- Log4j vulnerability
Listen Now
Episode 200 - Reflections of Pwned...Until Next Time
April 03, 2024
Episode 200 - Reflections of Pwned...Until Next Time
Listen Now
Episode 199 - When a BlackCat Crosses Your Path...
March 21, 2024
Episode 199 - When a BlackCat Crosses Your Path...
Listen Now
NuHarbor Security logo
NuHarbor Security

553 Roosevelt Highway
Colchester, VT 05446

1.800.917.5719

  • Solutions
  • Services
  • Partners
  • Resources
  • Company
  • Contact
  • Privacy Policy
Connect
  • Twitter
  • Linkedin
  • YouTube
©2026 NuHarbor Security. All rights reserved.