// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE CLK-15DTG 0600Z
ColdRecon / Exposure Clock
Original ColdRecon Metric

The Exposure
Clock

15 VENDORS ON THE CLOCK · UPDATED DAILY FROM PUBLIC SIGNAL

For each tracked endpoint security vendor: how long since the last CVE disclosed, breach at a customer running their product, in-the-wild demonstration, lab miss above one percent, and capability launch. The clock is reset by whatever the public signal stream does last. We do not score, we do not weight, we count days.

Days since last reset

The leaderboard

Ranked by the most recent reset (smallest number across any column). Vendors at the top have had the loudest public signal lately — which is a measure of newsworthiness, not of quality.

VendorCVEBreachDemoLab missLaunchMin
Microsoft 41d 14d 3d 145d 0d 0d
Cisco 3d 145d 3d
Palo Alto Networks 59d 56d 5d 5d
CrowdStrike 154d 13d 145d 6d 6d
SentinelOne 27d 10d 10d
CyberArk 24d 24d
Fortinet 56d 56d
Check Point 56d 56d
Sophos 145d 113d 113d
ManageEngine 145d 145d
Trellix 145d 145d
K7 145d 145d
VIPRE 145d 145d
SenseOn 145d 145d
G Data 145d 145d

≤ 7 days = fresh reset · ≤ 30 = recent · ≤ 90 = current window · > 90 = cold · = no event of this type on file. "Min" is the smallest days-since across all five columns — the vendor's last public reset.

How to read it

Five resets, one timeline

The Exposure Clock isn't a score. It's five independent counters, each tracking a different kind of event that resets to zero whenever public signal documents one:

  • CVE — a vulnerability with a CVE identifier publicly attributed to the vendor's product.
  • Breach — a disclosed incident at an organization that was running the vendor's product.
  • Demo — an in-the-wild bypass, exploit proof-of-concept, or attack research targeting the vendor.
  • Lab miss — the vendor's most recent independent-lab test with a miss rate > 1%.
  • Launch — a capability, feature, or product the vendor publicly announced.

A small number is not bad; a large number is not good. A vendor with a fresh CVE counter is in the news because researchers found something — possibly because they ship a lot of code, possibly because they ship sloppy code. The clock surfaces the timing; the reader brings the judgment.

Your competitor's last reset was three days ago. Walk into the next call knowing what tripped it.

ColdRecon turns every reset into a daily intelligence brief from the seller's seat — what triggered it, who's affected, what to say in the room. Request clearance and the first lands tomorrow at 0600.

Request Clearance →