By Garrett Hamilton, Founder and CEO, Reach Security

Security teams spend enormous amounts of time looking for exploitable weaknesses across their environment, from vulnerable software and exposed services to compromised credentials and misconfigured infrastructure. Yet some of the weaknesses attackers can take advantage of are introduced inside the very security controls that are supposed to stop those attackers.

That can happen through completely routine work. A firewall rule is changed so a new application can communicate. An endpoint policy is adjusted during troubleshooting. An access exception is granted to a vendor. A product update changes the way a control behaves. Each change may be legitimate, but it can also alter the protection that control provides.

em360tech image

Over time, those changes create configuration drift, where a security control moves away from the state the organization originally intended. Our research shows that this is happening continuously, while most organizations are still checking for it periodically.

Security Controls Are Changing Faster Than Teams Can Verify Them

In our first configuration drift study, 250 U.S. cybersecurity professionals told us their organizations use an average of 35 security tools. Popular security products receive around 20 feature updates a year, which means a typical organization could be dealing with roughly 700 new security-tool features annually before accounting for its own infrastructure changes, policy updates, exceptions and workarounds.

That level of change creates plenty of opportunity for defensive controls to move away from their intended state. Ninety-seven percent (97%) of respondents said they had experienced a breach or near miss caused by a security tool misconfiguration during the previous year, and 74% reported a confirmed breach.

We followed that research with an analysis of 12 months of Reach telemetry across more than 50 production environments. The average environment generated 13 drift alerts every day, with 12 associated with genuine, risk-prioritized security exposure.

The frequency of this exposes a weakness in the way configuration risk is managed today.

Periodic Reviews Leave A Long Window Of Exposure

The same practitioners told us they review security-tool configurations an average of 6.5 times per month. Only one in twenty organizations reviews them every day, and once a misconfiguration is identified, remediation takes an average of 8.3 days.

Meanwhile, the telemetry shows drift events happening every day, multiple times a day. It also shows that drift tends to increase around the normal rhythms of operating a technology environment. Some of the largest spikes followed vendor updates and patch cycles, drift increased later in the work week, and the two largest spikes recorded during the year occurred during the second half of December.

In terms of a configuration review, it tells you what was true when you performed the review. But the protection can change again as soon as someone modifies a rule, rolls out an update or makes an operational exception. When risky drift is occurring daily, checking several times a month leaves a substantial period in which a defensive weakness can exist without the security team knowing it is there.

AI Is Making That Exposure Window Harder To Tolerate

That window becomes much more dangerous as attackers gain access to AI.

AI can help adversaries probe environments, identify weaknesses and move laterally faster than traditional manual methods.

Consider what that means for a firewall rule that becomes overly permissive during troubleshooting. If the change creates a path to a sensitive system, it may be days before the security team’s normal review process catches it. An AI-assisted attacker has new ways to search for that weakness far more quickly.

The response window is being compressed from both sides. Security controls continue to change as part of normal operations, while attackers are getting faster at discovering the opportunities those changes create. An average remediation time of 8.3 days is increasingly difficult to reconcile with that threat environment.

Firewalls Are Where Configuration Drift Becomes Especially Dangerous

The firewall data across both studies stands out.

In the survey, 42% of respondents said they had experienced a configuration-related incident or near miss originating in the firewall, making it the most frequently cited source.

The production data showed an even greater concentration of material exposure. Firewalls accounted for 47% of drift alerts but nearly 88% of material security findings. EDR produced another 23% of drift alerts and roughly 10% of material findings.

Are you enjoying the content so far?

Firewalls are particularly susceptible because they sit at the center of network enforcement and often contain years of accumulated rules shaped by application changes, troubleshooting, acquisitions and temporary exceptions. A single rule change can affect what traffic is permitted, which systems are reachable and where an attacker may be able to move.

The telemetry also shows why simply tracking every change is not enough. IAM generated 15% of drift alerts but only about 0.3% of priority security findings. Teams need enough context to identify which configuration changes have actually weakened protection and prioritize those exposures first.

Security Spending Still Favors Response Over Prevention

There is a striking disconnect between this risk and where security budgets have traditionally been spent. Our survey found that 72% of security spending is directed toward detection, response and recovery, while only 28% goes toward preventive security.

TDIR (threat detection, investigation, and response) capabilities are essential, but the telemetry shows significant preventable exposure developing inside controls organizations already own. Keeping those controls configured correctly, finding dangerous drift as it happens and fixing it before an attacker can exploit it is another way to reduce the number of incidents teams eventually have to investigate and respond to.

Security Assurance Must Keep Pace With The Threat

Configuration drift is not going away because control change is not going away. Security and IT teams will continue to update products, support new applications, change policies and make exceptions as the business evolves.

What has changed – and reduced dramatically – is the amount of time defenders can afford to leave a weakness undiscovered.

Continuous security assurance gives teams a way to see when controls change, understand whether the change created meaningful exposure and move the highest-risk issues to the front of the remediation queue. As AI accelerates the attacker, that ability to find and close defensive weaknesses quickly becomes a much more important part of prevention.

Read The Research

Configure → Drift → Breach → Repeat  Understanding the cycle of cybersecurity control configuration risk.

Security Intent vs. Security Reality: Configuration Drift in the Age of AI
What a year of production telemetry reveals about configuration drift and hidden exposure.