# Wednesday Signals : The Acceleration Gap: Why Risk Now Moves Faster Than Governance Can Keep Up
By 

## Article Content
I’m speaking today at the 2026 Governance, Risk and Control Conference, jointly presented by ISACA and The Institute of Internal Auditors. My message is built around a simple idea: the defining challenge of 2026 isn’t simply that risk is increasing. It’s that risk is accelerating faster than our ability to understand, assess, and govern it. Cyber threats now move in minutes — sometimes seconds. Vulnerabilities pile up faster than they can be analyzed. New attack methods emerge before controls can catch up. That growing mismatch is what I call the Acceleration Gap. What's that? The central issue is no longer simply change — it is the growing gap between the speed of change and our ability to respond to it. Technology, threats, vulnerabilities and new forms of risk are accelerating far faster than most governance structures, policies and organizations can adapt. That gap is where tomorrow’s biggest risks are emerging. What's going on? Let's dive into some numbers and my slides! 263% — Vulnerability Growth The volume problem is exploding. Reported vulnerabilities increased dramatically from 2020–2025. More systems, more code, more APIs, more cloud infrastructure and more interconnected devices inevitably create a larger attack surface. The risk landscape isn't merely becoming more complicated — it is becoming exponentially larger. 100,000+ — The Analysis Backlog Finding vulnerabilities isn't enough. We increasingly face a capacity problem: enormous numbers of vulnerabilities exist faster than they can be analyzed, prioritized and remediated. Knowledge itself becomes a bottleneck. The challenge shifts from finding risk to figuring out which risks matter before somebody exploits them. 48 Minutes — Average Breakout Time Attackers no longer think in days or weeks. Once inside an organization, lateral movement can occur in under an hour. That creates a profound mismatch with governance systems that still operate on monthly meetings, quarterly reviews and annual assessments. Risk now moves on a completely different clock. 51 Seconds — Fastest Breakout And averages hide the extremes. The fastest recorded breakout was measured in seconds. Think about what that means: by the time a human understands that an incident has begun, the attacker may already have moved elsewhere. Human-speed reaction is increasingly inadequate against machine-speed events. 79% — No Malware at All The threat itself has changed. Many attacks no longer need malicious software; attackers can operate with valid stolen credentials and appear to be legitimate users. Traditional controls built around detecting “bad software” struggle when the attacker simply walks through the front door using someone else's keys. 63 Days → 5 Days → Negative Time The exploitation window has collapsed. What once took attackers months eventually took days — and now some vulnerabilities are being exploited before patches are even publicly available. We've moved from a race against time to something more unsettling: sometimes the defenders start the race behind the attackers. 8 Hours → 22 Seconds — Attacker Hand-Off Cybercrime has industrialized. Specialized groups can discover access, sell it, transfer it and weaponize it almost instantly. What used to resemble individual hacking increasingly resembles a highly optimized supply chain. The bad guys have figured out workflow automation too. Zero Days to Attack. 32 Days to Patch. This may be the clearest expression of the acceleration gap. Exploitation can begin immediately while remediation still takes weeks. The problem isn't that organizations aren't trying — it's that the traditional remediation model operates on a timescale the threat environment no longer respects. This is what makes the story real. While I was preparing this material, another supply-chain incident was unfolding, reportedly affecting hundreds of packages with enormous downstream exposure. The lesson isn't simply that another attack occurred. It's that the risk landscape can materially change while you're still preparing the presentation about the risk landscape. So what does it all mean? The biggest risk today Is the speed at which risk arrives! That's the broader conclusion. The greatest risks aren't simply the things already sitting on today's risk register. They are the threats, technologies and combinations of technologies we haven't properly categorized yet — arriving faster than our institutions can understand them, much less govern them. I shared this in a post a few years back. And get this - just last night, while finalizing my deck, I came across this post. Now the attack surface is expanding into the tools people increasingly trust for everyday answers. Malicious actors are looking for ways to exploit AI-assisted search, recommendations and generated instructions. The disturbing implication is that the interface we use to obtain trusted knowledge can itself become part of the threat vector. Taken together, these numbers describe something bigger than cybersecurity. They describe velocity risk: a world in which the lifecycle of the threat is becoming shorter than the lifecycle of the governance process designed to manage it. You can't slow risk down. The only viable response is to speed governance up. It's going to be a wild keynote!

---
Source: https://jimcarroll.com/2026/08/wednesday-signals-the-acceleration-gap-why-risk-now-moves-faster-than-governance-can-keep-up/