The Hidden Cost Explosion
AI is exploding the volume of security findings and fixes. But every one still has to become proof: reviewed, approved, evidenced, and defensible to customers, suppliers, auditors, regulators, and insurers. The security back office was never built to scale manually at this speed.
See why security admin work is compounding.
CVE submission growth
NIST reported CVE submissions increased 263% from 2020 to 2025.vendor assessment work each week
Whistic 2025 TPRM survey: average weekly vendor-assessment work.initial assessments needing follow-up
Whistic 2025 TPRM survey: initial supplier assessments requiring follow-up.reporting clocks
NIS2 and Cyber Resilience Act reporting sequences include 24-hour early warning and 72-hour notification windows.Security admin work is compounding.
Every new finding can now trigger triage, customer proof, supplier review, regulatory evidence, and insurance documentation at the same time.
Indexed admin burden growth from 2022 to 2028.
One security issue no longer creates one task. It can create several proof obligations at once.
The curve is an indexed scenario. The pressure signals behind it are public evidence: vulnerability growth, supplier proof workload, reporting clocks, and insurance proof demand.
What is driving the curve
2028 pressure snapshot. Compared with 2022, every major proof channel is materially heavier.
- year
- 2028
- Findings to triageMore discovered vulnerabilities and AI-assisted findings that still need local relevance, ownership, and remediation decisions.
- ↑5.4x
- Supplier and customer proofVendor reviews, customer assurance requests, questionnaires, follow-up, and response lag.
- ↑2.3x
- Regulatory evidence workMore regimes and shorter reporting clocks create more classification, approval, and evidence work.
- ↑2.4x
- Insurance evidence workUnderwriting controls, renewal evidence, representations, proof-of-loss readiness, and insurer-facing documentation.
- ↑2.0x
Optimization target: economic impact, not just passing proof.
Evident's trust graph should not stop when proof exists. It should ask whether proof was rejected, whether an incident created real cost, whether admin cost missed its target, and where reusable evidence can reduce the next cycle.
Sources behind the public numbers.
Public claims stay attached to the reports, regulator materials, and standards references used for the figures and clocks above.