[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83817-en":3,"doc-seo-83817-105":29,"detail-sidebar-cat-0-en-105":90},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":13,"seo_description":14,"update_tm":27,"read_time":28},83817,5909877438554,"Maeve","https://ap-avatar.wpscdn.com/avatar/5600025385ad2bf12a7?_k=1778553567797529272",8,"Research & Report","Mean Time to Remediate Is Not a Fielding Model: A Cadence Audit for Enterprise Vulnerability Management","Enterprise security teams often summarize remediation with MTTR, SLA compliance, dwell time, or detection delay, yet these metrics can obscure how fixes actually reach the environment—through maintenance windows, deployment rings, or emergency bypass paths. The paper proposes a remediation-cadence audit that records routine mean lag, release cadence parameters, cohort geometry, emergency/routine splits, and non-fielding delays. It quantifies a local capacity verdict and a calendar discount, showing when MTTR/SLA alone is insufficient evidence. Deployment-ring and cohort-geometry checks reveal conditions where cadence can help or harm near capacity.","arXiv :2607 .045 1 1v 1 [ cs .CR] 5 Jul 2026  \nMean Time to Remediate Is Not a Fielding Model: A Cadence Audit for Enterprise Vulnerability Management  \nAlexander Omelchenko  \nConstructor University Bremen gGmbH, Campus Ring 1, 28759 Bremen, Germany  \nAbstract  \nEnterprise security teams commonly summarize remediation through mean time to remediate (MTTR), SLA compliance, dwell time, or detection delay. These metrics are useful, but they can hide how fixes actually reach the estate: continuously, through scheduled maintenance windows, in deployment rings, or through emergency bypass paths. This paper introducesa remediation-cadence audit for enterprise vulnerability management. The audit records routine mean lag, release period, release fraction, cohort geometry, emergency/routine split, non-fielding delay, local residual-pressure evidence, and declared rate scenario. It comparesa continuous same-mean shortcut with the recorded release calendar and reports a local capacity verdict plus a calendar discount: the fraction of mean-only local capacity consumed by calendarized fielding. Worked notional packets with the same 30-day mean lag show why this matters. Under the normalized screening scenario, a two-month release train consumes 17.4% of mean-only capacity, a monthly train 5.2%, and a two-week screen 1.3%; across a 16-fold attacker-adjustment rate band, the two-month discount remains at least about 12% and the monthly discount stays in the resolution-sensitive 3–8% range. The audit therefore turns cadence assessment into an evidence-resolution question: when the discount is material relative to residual-pressure uncertainty or claimed headroom, MTTR/SLA should not be used alone as fielding evidence. Release-geometry checks show that deployment rings do not automatically recover the continuous benchmark, and cohort staggering can help or hurt near capacity. The result is a reproducible governance diagnostic, not a breach predictor or CVE prioritizer.  \nKeywords: Cybersecurity operations, vulnerability management, patch management, remediation metrics, MTTR, release cadence, security governance, control validation  \n1. Introduction  \nA vulnerability-management dashboard can improve while the underlying fielding process becomes less safe to summarize. An enterprise security team may report lower mean time toremediate (MTTR), better SLA compliance, and shorter detection delay, while at the sametime changing how defensive updates reach the estate: routine fixes are held for scheduled maintenance windows, assets move through deployment rings, and high-severity issues bypass  \nEmail address: [aomelchenko@constructor.university](aomelchenko@constructor.university) (Alexander Omelchenko)  \nthe ordinary process. From a dashboard perspective the program looks healthier. From a security-operations perspective, however, the relevant question is different: is the reported mean lag still a safe representation of how defensive changes are actually fielded?  \nThis paper studies that question as a remediation-cadence audit. The audit addresses a narrow but important reporting failure: MTTR, SLA compliance, MTTD, and dwell-time measures are useful governance indicators, but they are not fielding models. Two remediation processes can have the same reported mean lag while exposing the estate to different release geometry. One process may field changes continuously; another may wait for monthly, sixweek, bimonthly, or quarterly release windows; another may clear only part of the eligible backlog at each window; and another may split emergency and routine fixes into different channels. The mean lag summarizes average timing. It does not say whether the release calendar itself changes the local security-governance conclusion.  \nThe operational setting is familiar. Enterprise patch-management guidance treats remediation as a process of identifying, prioritizing, acquiring, installing, and verifying updates [24] . Public vendor and cloud documentatio","cbCaigJ1BREPCBic","https://ap.wps.com/l/cbCaigJ1BREPCBic","pdf",763236,1,38,"English","en",105,"# Introduction\n## Remediation-cadence audit overview\n## Evidence types: timing vs local residual pressure\n## Local capacity verdict and calendar discount\n## Worked screening scenarios and implications","[{\"question\":\"Why are MTTR and SLA compliance not sufficient as evidence for enterprise vulnerability management fielding?\",\"answer\":\"They can match the same reported mean lag while hiding differences in release geometry, emergency vs routine channels, and non-fielding delays. As a result, MTTR/SLA alone may not represent how defensive changes are actually deployed and accepted on the audited channel.\"},{\"question\":\"What does the proposed remediation-cadence audit record?\",\"answer\":\"It records routine mean lag, release-window period and release fractions, cohort or deployment-ring geometry, emergency/routine split rules, and a non-fielding delay budget covering detection, validation, approval, testing, packaging, and other hard delays.\"},{\"question\":\"How does the audit evaluate whether a channel is within or outside capacity?\",\"answer\":\"It derives a local capacity verdict by checking whether small disturbances decay under the recorded remediation process. If attacker adjustment outpaces fielding of defensive changes from release window to release window, the channel is outside capacity.\"}]",1784190602,96,{"code":4,"msg":30,"data":31},"ok",{"site_id":24,"language":23,"slug":32,"title":13,"keywords":33,"description":14,"schema_data":34,"social_meta":85,"head_meta":87,"extra_data":89,"updated_unix":27},"mean-time-to-remediate-is-not-a-fielding-model-a-cadence-audit-for-enterprise-vulnerability-management","",{"@graph":35,"@context":84},[36,53,67],{"@type":37,"itemListElement":38},"BreadcrumbList",[39,43,47,50],{"item":40,"name":41,"@type":42,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":44,"name":45,"@type":42,"position":46},"https://docshare.wps.com/document/","Document",2,{"item":48,"name":12,"@type":42,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":42,"position":52},"https://docshare.wps.com/document/mean-time-to-remediate-is-not-a-fielding-model-a-cadence-audit-for-enterprise-vulnerability-management/83817/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":23,"description":14,"dateModified":61,"datePublished":61,"encodingFormat":60,"isAccessibleForFree":62,"interactionStatistic":63},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":40,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-16",true,{"@type":64,"interactionType":65,"userInteractionCount":4},"InteractionCounter",{"@type":66},"ViewAction",{"@type":68,"mainEntity":69},"FAQPage",[70,76,80],{"name":71,"@type":72,"acceptedAnswer":73},"Why are MTTR and SLA compliance not sufficient as evidence for enterprise vulnerability management fielding?","Question",{"text":74,"@type":75},"They can match the same reported mean lag while hiding differences in release geometry, emergency vs routine channels, and non-fielding delays. As a result, MTTR/SLA alone may not represent how defensive changes are actually deployed and accepted on the audited channel.","Answer",{"name":77,"@type":72,"acceptedAnswer":78},"What does the proposed remediation-cadence audit record?",{"text":79,"@type":75},"It records routine mean lag, release-window period and release fractions, cohort or deployment-ring geometry, emergency/routine split rules, and a non-fielding delay budget covering detection, validation, approval, testing, packaging, and other hard delays.",{"name":81,"@type":72,"acceptedAnswer":82},"How does the audit evaluate whether a channel is within or outside capacity?",{"text":83,"@type":75},"It derives a local capacity verdict by checking whether small disturbances decay under the recorded remediation process. If attacker adjustment outpaces fielding of defensive changes from release window to release window, the channel is outside capacity.","https://schema.org",{"og:url":51,"og:type":86,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":88,"canonical":51},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":91},[92,96,100,104,109,114,119,122,127,130,134],{"id":20,"doc_module":4,"doc_module_name":45,"category_name":93,"show_sort_weight":94,"slug":95},"Story & Novel",90,"story-novel",{"id":46,"doc_module":4,"doc_module_name":45,"category_name":97,"show_sort_weight":98,"slug":99},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":45,"category_name":101,"show_sort_weight":102,"slug":103},"Exam",70,"exam",{"id":105,"doc_module":4,"doc_module_name":45,"category_name":106,"show_sort_weight":107,"slug":108},5,"Comic",60,"comic",{"id":110,"doc_module":4,"doc_module_name":45,"category_name":111,"show_sort_weight":112,"slug":113},6,"Technology",50,"technology",{"id":115,"doc_module":4,"doc_module_name":45,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":45,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":45,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":45,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":45,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":45,"category_name":136,"show_sort_weight":105,"slug":137},19,"General","general"]