Spokes.wiki Search About
Defined Term metric updated Wed Jul 29 2026 00:00:00 GMT+0000 (Coordinated Universal Time)

Mean Time to Adapt (MTTA)

Visa’s replacement for mean-time-to-detect and CVE-closure counts: elapsed time from an AI-discovered exploitability to a validated fix in production (visa-vulnerability-agentic-harness). Tracked along three dimensions in the Project Glasswing white paper:

  • Inventory freshness — how current and complete the view of code, configuration and runtime deployment is.
  • Exploitable paths per release — how many end-to-end attack chains remain possible after each release, rather than how many findings were closed.
  • Validation cycle time — how long to produce repeatable, evidence-backed proof that a fix works and keeps working.

The argument against the metrics it replaces

Legacy measures “can look better on paper while actual exposure keeps growing underneath them” (visa-mythos-glasswing). An organisation can close hundreds of findings a month and still leave viable exploit chains open, because nobody tested whether the patches break the attack. Counting closed findings measures work done; counting remaining exploitable paths measures the thing an attacker cares about.

This is the same critique security-benchmark raises about compliance scoring — a number that is easy to move and only loosely coupled to whether you are safe — arriving from the vulnerability- management side. Both are instances of the spoke’s recurring problem: security keeps producing metrics that measure the security programme rather than the security.

What it assumes

MTTA presumes you can tell an exploitable path from a theoretical one, which is precisely the judgment visa-vulnerability-agentic-harness admits it makes without published precision or recall. The metric is only as good as the exploitability verdict underneath it, and that verdict is currently an LLM panel’s. Visa’s supporting argument — fewer than 1% of CVEs are ever actively exploited (CISA KEV) — is a strong case for prioritising by exploitability and says nothing about whether this pipeline identifies it correctly.

visa-vulnerability-agentic-harness · visa-mythos-glasswing · project-glasswing · security-benchmark · coordinated-vulnerability-disclosure · synthesis