Here's what bothers me about how the security industry handles vulnerability disclosure: we've created a system where companies profit most when vulnerabilities stay hidden the longest.
Look at the incentive structure. When a vendor patches a critical flaw, they issue a CVE, customers scramble to update, and the vulnerability becomes public knowledge. This creates immediate operational headaches. But when a vendor quietly patches something without fanfare? When they bundle fixes into routine updates that few people notice? The money keeps flowing.
The market rewards silence.
This isn't a conspiracy theory. It's basic economics. A vendor that announces a major authentication bypass in their RMM platform faces customer anger, potential lawsuits, and pressure to provide free patches. A vendor that silently fixes the same flaw in a Tuesday afternoon update faces nothing. Customers install it anyway because it's routine maintenance. No headlines. No reproach. No impact on quarterly earnings.
The recent string of high-impact vulnerability stories tells this story implicitly. Critical flaws in widely used tools. Authentication gaps in collaboration platforms. Patch bypasses in remote management software. These weren't mysterious discoveries. Someone found them. Someone fixed them. But the real question is: how many similar vulnerabilities never make headlines at all?
We should care about this as an industry because we're essentially subsidizing opacity.
Security researchers who find flaws have two paths. They can responsibly disclose and face an often-glacial vendor response. Or they can sell to brokers who pay cash to keep quiet. Which path gets rewarded financially? The second one. We've created a market where responsible disclosure pays worse than silence.
Customers, meanwhile, face a false choice. We're told to trust vendors, apply patches promptly, and stay informed about threats. But vendors have no structural incentive to tell us about all the threats they've fixed. We're working from an incomplete picture, trusting vendors to disclose what they think we should know.
The security conferences and analyst firms play their role too. They celebrate vendors who achieve "patch Tuesday" consistency or announce disclosure policies. But they rarely ask the uncomfortable question: why did this vulnerability exist for so long? What about the ones we don't know about? The industry celebrates the performance of disclosure rather than the prevention of flaws.
I'm not suggesting vendors intentionally hide vulnerabilities out of malice. Most security teams want to do right by customers. But they're working within a system that doesn't reward them for it. A CISO who aggressively finds and patches internal vulnerabilities doesn't get a bonus or a promotion. They get treated as normal. A CISO who experiences a public breach faces career consequences.
The asymmetry is brutal.
Here's what needs to change: the industry needs to create real incentives for transparency. Not just policies, but mechanisms that actually cost companies something for hidden vulnerabilities discovered later. Not penalty boxes, but alignment. If a vulnerability found externally six months after a patch would have caught it creates liability, suddenly finding vulnerabilities becomes profitable.
We also need to stop celebrating vendors for moving fast. Move fast means mistakes go unnoticed longer. We should celebrate vendors for moving thoroughly.
Finally, we need to stop pretending that CVE counts and patch consistency are proxies for security. A vendor with five disclosed vulnerabilities might actually be more secure than a vendor with one. That vendor might be finding problems, fixing them, and reporting them instead of burying them.
The current system works well for companies that are good at public relations and patch management. It works terribly for organizations that depend on understanding actual risk.
Until we change the incentives, we're all just hoping our vendors are more transparent than the market encourages them to be.