USENIX Security2026Top-tier venue
Do They Get With the Program? Measuring Mitigation in a Solicited Vulnerability Notification Program
Yana Angelova, Carlos Gañán, Annebel Smit, Rolf van Wegberg, Michel van Eeten
Abstract
Attackers rapidly scan for newly-disclosed vulnerabilities across enterprise networks. In response, defenders have been running similar scans in order to notify the affected enterprise about their exposed attack surface as soon as possible. Such initiatives are becoming more institutionalized, e.g., under the EU's NIS2 directive and CISA's Ransomware Vulnerability Warning Pilot. Research on the effectiveness of vulnerability notifications has found disappointing results, where only a minor fraction of issues were fixed. This was blamed on problems in asset attribution, low trust in the sender, reachability issues, and lacking incentives of the recipient to act. A potential solution to all these problems would be a notification program where companies volunteer to sign up, register their assets, and ensure the right contact details. How much better could such a program perform? We provide the first empirical evaluation of a solicited notification program through a collaboration with a governmental Computer Security Incident Response Team (CSIRT) that offers security notifications to enterprises. We first conduct interviews with nearly half of all participating companies (n = 21) to understand why they signed up and how they act on the notifications. Next, we quantitatively study the remediation effectiveness of the program via survival analysis. We find that 27% of the security issues being resolved within one day of notification, 40% within one week, and 49% within one month. Over the entire three years of the program, the remediation rate is 75%. These findings already show higher remediation effectiveness compared to previous unsolicited experiments. This suggests that solicited notification programs can overcome challenges of reachability, trust, and motivation. We reflect on the limitations of these findings and their implications for the future.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on6
- You've Got Vulnerability: Exploring Effective Vulnerability NotificationsFrank Li, Zakir Durumeric, Jakub Czyz, Mohammad Karami et al.USENIX Security 2016 · 149 citations
- Didn't You Hear Me? - Towards More Successful Web Vulnerability NotificationsBen Stock, Giancarlo Pellegrino, Frank Li, Michael Backes et al.NDSS 2018 · 86 citations
- Exposed Infrastructures: Discovery, Attacks and Remediation of Insecure ICS Remote Management DevicesTakayuki Sasaki, Akira Fujita, Carlos Hernandez Gañán, Michel van Eeten et al.S&P 2022 · 41 citations
- Effective Notification Campaigns on the Web: A Matter of Trust, Framing, and SupportMax Maass, Alina Stöver, Henning Pridöhl, Sebastian Bretthauer et al.USENIX Security 2021 · 35 citations
- Deployment of Source Address Validation by Network Operators: A Randomized Control TrialQasim Lone, Alisa Frik, Matthew Luckie, Maciej Korczynski et al.S&P 2022 · 16 citations
Related papers
- Behind the Curtain: How Shared Hosting Providers Respond to Vulnerability NotificationsGiada Stivala, Rafael Mrowczynski, Maria Hellenthal, Giancarlo PellegrinoS&P 2026
- Hey, You Have a Problem: On the Feasibility of Large-Scale Web Vulnerability NotificationBen Stock, Giancarlo Pellegrino, Christian Rossow, Martin Johns et al.USENIX Security 2016 · 130 citations
- The Unpatchables: Why Municipalities Persist in Running Vulnerable HostsAksel Ethembabaoglu, Rolf van Wegberg, Yury Zhauniarovich, Michel van EetenUSENIX Security 2024 · 4 citations
- "Tell Them They Are a Responsible Entity, Not a Customer": Understanding Practitioner Challenges in Sector CSIRTsAksel Ethembabaoglu, Natalia I. Kadenko, Yana Angelova, Yury Zhauniarovich et al.CHI 2026 · 1 citation
- Speedrunning the Maze: Meeting Regulatory Patching Deadlines in a Large Enterprise EnvironmentGerbrand ten Napel, Michel van Eeten, Simon ParkinS&P 2025
