Evident Research

The Hidden Cost Explosion

AI is exploding the volume of security findings and fixes. But every one still has to become proof: reviewed, approved, evidenced, and defensible to customers, suppliers, auditors, regulators, and insurers. The security back office was never built to scale manually at this speed.

2022202320242025202620272028
2022 baseline3.4x admin burden by 20284 proof channels
Findings to triage5.4x
Supplier and customer proof2.3x
Regulatory evidence work2.4x
Insurance evidence work2.0x
interactive dataset

See why security admin work is compounding.

evidence behind the model
263%

CVE submission growth

NIST reported CVE submissions increased 263% from 2020 to 2025.
37.4h

vendor assessment work each week

Whistic 2025 TPRM survey: average weekly vendor-assessment work.
84%

initial assessments needing follow-up

Whistic 2025 TPRM survey: initial supplier assessments requiring follow-up.
24/72h

reporting clocks

NIS2 and Cyber Resilience Act reporting sequences include 24-hour early warning and 72-hour notification windows.
view

Security admin work is compounding.

Every new finding can now trigger triage, customer proof, supplier review, regulatory evidence, and insurance documentation at the same time.

Download CSV
Evidence behind the curve.The index is built from four dated pressure lines: vulnerability growth, supplier assessment workload, reporting clocks, and cyber insurance proof demand.
3.4x

Indexed admin burden growth from 2022 to 2028.

One security issue no longer creates one task. It can create several proof obligations at once.

2022202320242025202620272028
Findings to triage5.4xMore discovered vulnerabilities and AI-assisted findings that still need local relevance, ownership, and remediation decisions.
Supplier and customer proof2.3xVendor reviews, customer assurance requests, questionnaires, follow-up, and documentation delays.
Regulatory evidence work2.4xMore regimes and shorter reporting clocks create more classification, approval, and evidence work.
Insurance evidence work2.0xUnderwriting controls, renewal evidence, representations, and proof-of-loss readiness.

The curve is an indexed scenario. The pressure signals behind it are public evidence: vulnerability growth, supplier proof workload, reporting clocks, and insurance proof demand.

drilldown

What is driving the curve

2028 pressure snapshot. Compared with 2022, every major proof channel is materially heavier.

year
2028
Findings to triageMore discovered vulnerabilities and AI-assisted findings that still need local relevance, ownership, and remediation decisions.
↑5.4x
Supplier and customer proofVendor reviews, customer assurance requests, questionnaires, follow-up, and response lag.
↑2.3x
Regulatory evidence workMore regimes and shorter reporting clocks create more classification, approval, and evidence work.
↑2.4x
Insurance evidence workUnderwriting controls, renewal evidence, representations, proof-of-loss readiness, and insurer-facing documentation.
↑2.0x
one level above compliance

Optimization target: economic impact, not just passing proof.

Evident's trust graph should not stop when proof exists. It should ask whether proof was rejected, whether an incident created real cost, whether admin cost missed its target, and where reusable evidence can reduce the next cycle.

triggerobligationworkproofeconomic impact
evidence sources

Sources behind the public numbers.

Public claims stay attached to the reports, regulator materials, and standards references used for the figures and clocks above.

PublisherSourceUsed for
AI Incident DatabaseAI Incident Database Snapshotspublic-number evidence
CISAKnown Exploited Vulnerabilities Catalogpublic-number evidence
Cloud Security AllianceSTAR Level 1 Security Questionnaire CAIQ v4public-number evidence
CVE ProgramCVE List V5public-number evidence
European CommissionCyber Resilience Act Reporting Obligationspublic-number evidence
European UnionDigital Operational Resilience Actpublic-number evidence
European UnionNIS2 Directivepublic-number evidence
FIRSTEPSS Current Scorespublic-number evidence
HHS OCRBreach Portal Notice to the Secretary of HHS Breach of Unsecured Protected Health Informationpublic-number evidence
MITRECWE Listpublic-number evidence
MITREMITRE ATLAS Datapublic-number evidence
NAICCyber Insurance Reportpublic-number evidence
NAICReport on the Cybersecurity Insurance Marketpublic-number evidence
NISTNVD CVE API 2.0public-number evidence
OMB/OIRAOMB/OIRA Paperwork Burden Inventorypublic-number evidence
OWASP FoundationOWASP Top 10 for LLM Applicationspublic-number evidence
SECCybersecurity Risk Management, Strategy, Governance, and Incident Disclosurepublic-number evidence
Shared AssessmentsWhat's New in the 2025 SIG Updatepublic-number evidence
WhisticThird-Party Risk Management 2025 Impact Reportpublic-number evidence