Companies disclose every dollar they owe, but not how many flaws sit in their software. Machines have cut the time to exploit a bug from years to hours. Insurers, lenders and index investors are still pricing the old world.
By Dhirendra Pratap Singh | ICTpost USA | October 9, 2026
In 2018, the average disclosed software flaw took more than two years to be exploited. In 2026, it takes roughly ten hours, according to data in a Gallagher Re report. Over the same period, the median time companies take to patch has gone the other way, rising from 32 to 43 days in Verizon’s latest breach report, per Tenable’s analysis.
That gap is the story. When Anthropic unveiled its Mythos model in April, it offered a vivid illustration: a 27-year-old flaw in OpenBSD, an operating system built for security, and a 16-year-old bug in video software that testing tools had run past five million times without noticing. These were flaws that decades of human review had not caught.
The question for WSJ readers is not which AI lab built what. It is what happens to earnings, credit and insurance prices when finding a serious flaw becomes cheap.
The clock flipped
Patch volumes already show the answer. Microsoft’s September Patch Tuesday covered roughly 966 CVEs, the catalog numbers for known software flaws, by Brinqa’s count, against a 2025 monthly average of 103. Counts vary by method, and another tally reaches 974. The direction is not in dispute.
The capability is spreading. The UK’s AI Security Institute found OpenAI’s GPT-5.5 performed comparably to Mythos on offensive cyber tests, Gallagher Re reports. Restricting one model buys time, not safety.
Who holds the exposure
Microsoft is the clearest case of concentration. Its patch queue is effectively the market’s patch queue. When one vendor ships nine times its usual monthly load, every large customer inherits the testing and deployment work. Microsoft is also a launch partner in the defensive effort, which makes it both a source of the flood and a fighter of it.
UnitedHealth shows what the tail looks like when it hits a balance sheet. The Change Healthcare attack cost the company $3.1 billion and exposed about 190 million people. During the response, UnitedHealth also advanced more than $8.9 billion to providers disrupted by the outage. That is a liquidity call on top of a loss, and it fell on one company in one quarter.
JPMorganChase sits on both sides. It is a launch partner in the AI defense effort and said it would take a rigorous, independent approach to deciding how to proceed. As a bank, it is also a lender to every other exposed company. A bank’s credit risk now includes its borrowers’ patch queues, though I found no public bank-level disclosure that quantifies it. Verizon found third-party involvement in breaches doubled to 30% in its 2025 report, which means the flaws that matter may sit in a vendor’s code, not the borrower’s.
The price signal: insurance
Cyber insurance is where this risk is supposed to get a price, and so far the price has not moved.
Fitch reported that U.S. cyber premiums grew 11% in 2025, driven by a 35% rise in policies in force against soft pricing. It also said vulnerabilities will probably outnumber patches in the short to medium term. Willis Towers Watson told risk managers there was no evidence of immediate pricing changes and that AI involvement does not currently trigger exclusions. That is more coverage at roughly the old price, in a market whose own analysts say the underlying risk is growing.
The adjustment may come through coverage, not price. One London broker expects AI-enabled attacks to start being excluded. Another commentator argues insurers move from pricing risk to policing behavior when losses become correlated, as they do when one flaw hits thousands of firms at once. Gallagher Re adds that opaque, restricted models leave insurers pricing uncertainty rather than risk.
For a CFO, the implication is direct. A company may find that its cyber policy is cheaper than expected, until a claim reveals what it excludes. Remediation speed is becoming the thing insurers underwrite, which turns patch metrics into a cost-of-capital variable.
Sizing it for the index
Nobody can total the backlog from filings, so I built a stress test from public inputs. This is my model, not a measurement.
The 2026 Fortune 500 earned $2.1 trillion on $21 trillion in revenue. It is a proxy for the S&P 500, not an identical list, but index investors own most of the same exposure. IBM puts the average U.S. breach at $10.22 million, though that average blends in small firms. I assume about 400 of the 500 carry exposed, AI-findable flaws, including in third-party software, and that a material event costs a large enterprise far more than average.
| Scenario | Chance of material event (24 months) | Cost per event | Expected loss |
|---|---|---|---|
| Low | 5% | $100M | ~$2B |
| Central | 12% | $250M | ~$12B |
| Stress | 25% | $500M | ~$50B |
Debt is the larger liability on corporate balance sheets. It is also the best measured one, with maturities, coupons and ratings attached. This exposure is the opposite: it has no schedule, no rating and no line item.
The valuation point is dispersion, not the mean. The central case works out to about 0.3% of annual Fortune 500 profit, which no index would notice. But the loss does not spread evenly. One UnitedHealth-sized event exceeds my entire low case. Index valuations price the average and ignore the tail, which is the definition of a mispriced risk. The model also leaves out remediation labor, which will appear in operating costs, and correlation. A single flaw in a ubiquitous product could hit hundreds of firms in one week.
The disclosure gap
Since December 2023, public companies must file an 8-K within four business days of deciding a cyber incident is material, and describe their cyber risk processes annually under Regulation S-K Item 106. Both rules cover incidents and processes. Neither requires an inventory, an aging report or a remediation rate, so a company can file an accurate 10-K describing a sound process while carrying months-old critical flaws.
The regulatory mood runs the other way. Under Chair Paul Atkins the SEC has emphasized materiality and kept the 2023 rules, though lawyers expect lighter enforcement. New disclosure may arrive through insurers, lenders and analysts before it arrives through rulemaking.
Three questions for the next earnings call
- What is your median time to fix actively exploited flaws on internet-facing systems, and how has it moved since April? The industry median is 43 days.
- Have you run AI-assisted discovery against your own code and critical vendors, and what share of findings is still open?
- Did your cyber insurer change your terms, exclusions or retention at the last renewal? The answer shows whether the market is repricing.
Debt is the liability everyone can read. Unpatched code is the one nobody is pricing, and the clock that prices it now runs in hours.
editor@ictpost.com
