By Mark Fetches | September 24, 2026

The future of enterprise security advisory is not automated vulnerability prediction. It is AI-accelerated, human-validated exposure control.

The alert nobody acted on

More than 48,000 vulnerabilities were publicly disclosed in 2025 alone. Security teams across the enterprise received alerts, reports, advisories, dashboards, and an unrelenting flood of signals demanding attention.

And yet, VulnCheck’s 2026 Exploit Intelligence Report found that only 422 vulnerabilities, roughly 1% of newly published vulnerabilities, were ever exploited in the wild.

Which means that for every real threat that required urgent action, there were 99 others consuming analyst time, board attention, and budget cycles that could have been spent elsewhere.

This is not a detection problem. Enterprise security tooling has never been more capable of finding vulnerabilities. The problem is something far harder to automate:

Knowing which vulnerabilities actually matter inside your environment.

That distinction is the difference between a security program and a security theater.

The AI gold rush and what it’s missing

The third-party enterprise software support market is in the middle of an AI gold rush.

Every vendor is racing to plant a flag. “AI-powered vulnerability detection.” “Predictive threat intelligence.” “Machine learning-driven prioritization.” The language is everywhere. The proof is not.

Here is what is happening beneath the marketing:

  • Most AI security tools are trained on generalized threat data, CVE databases, public exploit repositories, broad industry patterns
  • They are exceptionally good at identifying what exists
  • They are far less effective at interpreting what those findings mean inside a complex enterprise environment unless they are grounded in configuration, access, operational, and business-process context and validated by experts who understand the platform.

An AI model does not know that your Oracle EBS instance has a custom configuration built over 12 years of business-specific modifications. It does not know that your change freeze runs through Q4 earnings. It does not know that your compliance posture means a particular remediation path is off the table regardless of CVSS score.

Your environment is not a generalization. Your risk is not a dataset.

AI without that context does not reduce noise. It amplifies it with the veneer of algorithmic authority.

The human layer still matters.

The human layer is not the bottleneck. It is the differentiator.

There is a prevailing assumption in the market right now that human expertise is the bottleneck to be engineered away. That the goal is full automation: an AI that ingests threat feeds, scores vulnerabilities and issues remediation guidance without a human in the loop.

This assumption is wrong. And it is dangerous.

The most consequential security decisions are not ones where the answer is obvious. They are the ones where:

  • A vulnerability scores a 9.8 CVSS but your specific implementation is not exposed
  • A low-severity finding maps directly to a custom integration that creates a critical attack path
  • A remediation recommendation conflicts with a regulatory requirement specific to your industry
  • The “correct” patch breaks a business-critical process that your vendor has long since stopped supporting

These are not edge cases. For enterprises running complex, mature, modified ERP environments like Oracle, SAP and JD Edwards, these are the norm.

The organizations that get this right are not the ones with the most sophisticated AI. They are the ones with the most contextually intelligent humans, augmented by AI to work faster and cover more ground.

That is a meaningful distinction. It changes the product entirely.

What “Human-Validated” means in practice

At Spinnaker Support, we have spent years building security advisory capability around a core belief: the expert is irreplaceable and technology should serve the expert, not replace them.

In practice, this means:

AI does the heavy lifting on signal identification. Predictive analytics scan threat intelligence feeds, correlate CVE data, and surface candidates for review from public disclosures, vendor advisories, exploit activity, threat intelligence, and early-warning signals where available. The volume problem is an AI problem. Let AI solve it.

Human experts do the work that requires judgment. Experienced security engineers with deep expertise across Oracle, SAP, and JD Edwards environments validate every prioritized finding against the customer’s actual configuration. They do not issue generic guidance. They issue your guidance.

The output is a decision, not a report. The goal is not to tell you how many vulnerabilities exist. It is to tell you: here are the three things that require action this week, here is why, here is how, and here is what you can safely deprioritise. That is what a trusted advisor looks like.

The decision must also translate into control: which compensating controls should be applied, which access paths should be restricted, which configurations need hardening, what evidence should be retained, and what belongs on the governed improvement roadmap. That is the difference between prioritization and exposure management.

This model scales differently. AI expands coverage and speed; expert validation preserves accuracy and trust. The objective is not infinite automated output. It is high-confidence guidance customers can act on.

The question CISOs are not asking, but should be

When evaluating any security advisory service, there is one question that cuts through the noise faster than any benchmark or feature comparison:

“When your AI flags something as critical, who validates that before it reaches me?”

If the answer is “the algorithm scores it and delivers it,” you have a detection tool.

If the answer is “a senior security engineer who knows your environment reviews it first,” you have an advisory program.

The difference in outcome, in reduced false positives, in faster genuine remediation, in audit-ready documentation, in CISO confidence, is not marginal. It is structural.

The enterprises that will navigate the next three years of escalating vulnerability disclosure most effectively are not the ones who bought the most AI. They are the ones who bought the right combination of AI speed and human judgment.

A note on independence

There is one more dimension worth naming directly.

The vendors who originally built your enterprise software have a commercial interest in how your vulnerability posture is communicated to you. Their security advisories exist within a context: patches drive upgrades, upgrades drive licensing, and licensing drives revenue.

Independent security advisory, by definition, has no such interest. The guidance is calibrated entirely to your environment, operational reality, and risk profile. Not to a vendor roadmap.

For the thousands of enterprises running mature, stable versions of Oracle, SAP, and JD Edwards that are no longer on active vendor support, this independence is not a nice-to-have. It is the entire point.

The signal worth acting on

The market will consolidate around this question over the next 12–18 months: is AI security advisory a feature bundled into support, or is it a discipline in its own right?

Our position is clear.

It is a discipline. It requires expertise, independence, and the kind of contextual intelligence that cannot be productised into a portal or automated into a feed.

The enterprises that treat it as a discipline and invest in human-validated, AI-augmented, environment-specific advisory will spend less time chasing alerts and more time running their business.

That is the signal worth acting on.

Mark Fetches
Written By Mark Fetches
Mark Fetches Mark Fetches is Chief Technology Officer, EMEA, at Spinnaker Support. With more than 30 years of technology consulting and leadership experience, he advises enterprise organizations on technology strategy, modernization, cloud, AI, and digital transformation initiatives. Prior to joining Spinnaker Support, Mark held leadership roles at Accenture, Deloitte, and PwC, where he worked closely with C-suite executives and boards on large-scale transformation programs. Mark is based in the UK and holds a Bachelor of Technology in Graphic Communications Management from Toronto Metropolitan University. He is TOGAF and ITIL certified.