Dr Deepak Kumar, Founder and CEO, Adaptiva: “Even with partial automation, organizations are leaving too much on the table.”

The past decade in cybersecurity has seen organizations focus on building visibility and automation into the tools used in their IT and security environments. The next challenge is addressing execution across remediation processes, such as patch management. 

In an era of AI-driven attacks, cybersecurity success is increasingly determined not by whether organizations can identify vulnerabilities, but by how effectively they can coordinate and execute remediation at machine speed.

Deepak Kumar, Founder and CEO of Adaptiva, believes the industry’s next challenge is execution rather than visibility. With over two decades in endpoint management and cybersecurity, Kumar has observed organizations improve in identifying vulnerabilities, automating tasks, and enhancing security visibility. However, many still struggle to consistently remediate risk at scale. This experience has led him to conclude that the future of cybersecurity will depend less on detecting vulnerabilities and more on the autonomous coordination and execution of remediation across complex IT environments.

In this interview, Kumar discusses the widening gap between visibility and remediation, the operational barriers to achieving autonomy, and the steps security leaders should take to reduce risk amid AI-driven attacks.

Third-party software remains one of the biggest sources of risk for enterprises. Why does this challenge persist despite years of investment in cybersecurity tools?

Historically, cybersecurity tools have not kept pace with the breadth of third-party software that is available on the market. As we’ve established, organizations today need complete coverage, not only fast remediation. The problem is that tools are not yet able to integrate with all available applications, and organizations require multiple tools to do the same job.

While investment is on the rise, if tools only support 300 or even 1,000 applications in environments, they still do not provide complete coverage. Complete coverage would require manpower and resources that organizations simply cannot provide. Patching must match the machine-speed threats attackers are leveraging against organizations today, and coverage consistency must also expand to all levels of application vulnerabilities.

Organizations have spent years investing in patch automation. Why isn’t automation enough anymore?

The problem is that many organizations are implementing partial automation, meaning they’ve automated parts of their workflows, but steps requiring manual administration remain. Most IT and security processes, such as patch management, involve many steps. So, if only 20% of a 50-step patch management process is automated, that’s still a lot of manual work.

Partially automated workflows can also create room for error and holes that require manual inspection and remediation. Ultimately, this is why, although today’s organizations are successfully leveraging automation for individual tasks, they still experience delays and perceive risk across operations.

Your recent research found that many organizations still feel exposed to known vulnerabilities despite patching faster than ever before. What is driving that disconnect?

That’s a great question, and the cause of this disconnect is the fact that although organizations are patching faster, they’re not addressing the entire vulnerability landscape. While critical vulnerabilities are patched and remediated more quickly today, many vulnerabilities fall outside routine automated patching cycles. These are the weak points attackers are exposing.

Even with partial automation, organizations are leaving too much on the table. They don’t have the time or resources to keep up with the 44,000 vulnerabilities that came out last year, so while critical exploits get patched, the rest remain exposed in their environments. Threat actors today are also using automation to identify exploits and execute attacks within minutes of a vulnerability being disclosed. 

By automating the search for exploits, attackers’ focus has shifted from primarily targeting critical vulnerabilities to evaluating vulnerabilities at every level. As such, defense tactics must also change, and patching cycles measured in weeks or even days are too slow for today’s threat landscape.

The cybersecurity industry has historically focused on visibility. Why do you believe coordination is becoming the bigger challenge?

Visibility is crucial for any organization to say, “Yes, we are taking steps to eliminate risk in our environment and close exposures as much as possible.” As threats evolve and accelerate, security audits have come into sharper focus, and visibility is at the core of successfully completing them.

In the early days, if your organization could not demonstrate to auditors that it was scanning its own vulnerabilities, someone would be brought in to do it, and the organization would also be required to remediate any vulnerabilities found. However, this is where coordination became a problem, with security teams sending IT teams spreadsheets filled with thousands of vulnerabilities. Without context on correlations among vulnerabilities, whether patches were available, or an indication of whether remediation was required, a wall began to form between IT and security teams.

What we’ve seen in the past few years is a concerted effort to bring the two sides together, so it is crucial that the tools and automation used by IT and security teams integrate without requiring manual coordination. Today’s coordination issues will be resolved once organizations figure out how to automate actions between individual tasks, moving seamlessly from vulnerability detection to remediation.

Many organizations are adopting autonomous security capabilities, but only a small percentage have reached full autonomy. What separates leaders from organizations stuck in the middle?

The organizations making the most progress toward autonomy are the ones willing to eliminate manual decision points, which slow execution across IT and security operations. Our research found that while 44% of organizations report partially automating patching workflows, more than 60% still rely on manual processes at some point in the patch lifecycle. Only 8% are implementing full autonomous execution today.

Often, what separates leaders from organizations stuck in the middle is not expanding technology, but furthering operational commitment. Investment in automated tools continues to rise, but the operations remain dependent on human approvals, coordination, or intervention at critical stages of the process. As a result, individual tasks are automated, while the overall workflow remains dependent on people.

We also observe that organizations hesitate to automate actions that may create immediate disruption, such as deploying patches broadly or rebooting systems after critical updates. As such, leaders differentiate by recognizing the inconveniences caused by remediation outweigh the risks associated with leaving vulnerabilities unaddressed.

Furthermore, leaders align IT and security teams on risk tolerance and enable automatic remediation by establishing clear policies and guardrails. Instead of treating automation as a set of individual tools, they apply an autonomy-based operational model to connect detection, prioritization, and remediation.

How is AI changing the balance between attackers and defenders, particularly when it comes to vulnerability exploitation and remediation?

As we touched on earlier, AI is on the attackers’ side right now. And while AI is integrated into defense tools, organizations remain hesitant to implement AI-connected systems due to concerns about potential risks and exposures introduced into the environment. This means that AI tools must be carefully tested before being implemented.

Attackers are also operating their offensive AI at a much higher level than defenders, as they’ve been implementing the technology longer than we have. Again, it is important to understand that AI is weighted towards attackers in our current environment and will remain so for some time, as defenders develop guardrails for AI safety.

Looking ahead, how will endpoint management and vulnerability remediation continue to move forward in their maturity in three to five years from now?

Organizations will continue to advance in their maturity, working towards building autonomous platforms that incorporate AI to help teams make even more decisions without waiting for manual coordination. As more organizations grow comfortable with and overcome the initial fear around AI, they will understand that they can use it to their advantage by assigning agents and tools that help speed things up even more.

The bigger shift, however, will be how organizations think about cybersecurity. For years, success was measured by visibility: how many vulnerabilities could be identified, tracked, and reported. Over the next three to five years, success will increasingly be measured by execution. In a machine-speed threat environment, the ability to act will matter more than the ability to see.

More interviews worth a read

About The Author

Avatar photo
Ricardo Oliveira

Ricardo Oliveira is a Senior Director at TechFinitive, where he frequently collaborates with TechFinitive's editorial team to write and produce content. He's based in Sydney, Australia.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.