
We Automated the Wrong Half of Vulnerability Triage
The problem
NIST reports that CVE submissions grew 263% between 2020 and 2025, and that the first three months of 2026 ran nearly one-third higher than the same period a year earlier. It does not expect the trend to let up.1
Our team did not grow 263%. It did not grow at all. Every one of those findings still has to be read by someone, scored, checked against what we actually run, and either acted on or set aside with a reason we can defend later.
For a long time we kept up by working faster. We tuned filters, tightened the alerting, and got better at recognising which findings mattered. None of that changes the shape of the problem, because the queue grows on its own and our capacity does not.
This is what we did about it, including the part we got wrong for a year.

