We recently measured remediation behavior across anonymized customer fleets. Customer accounts running Vulnerability Response closed more of their critical vulnerabilities, and closed them faster. The pattern held across every customer cohort.
To see how our Vulnerability Response affects remediation, we compared critical- and high-severity vulnerabilities across two groups of customer fleets: those with Vulnerability Response enabled and those without.
Customer accounts running Vulnerability Response, on top of Iru Endpoint Management, remediated 85.4% of those vulnerabilities. The accounts with only Iru Endpoint Management reached 64.8%. That is a 31.7% improvement in coverage, before counting speed.

On speed, the gap widens. Median time to remediate dropped from 2.58 days to 1.21 days, 53% faster. The window between a Common Vulnerabilities and Exposures (CVE) record landing and a patch reaching the device closed by more than half.

The gap is structural, and it is widening
Public vulnerability counts climb every year, and the teams managing them are not growing at the same pace. AI-assisted attackers compress the time from disclosure to exploit, while the patch queue keeps filling.
The math is unforgiving. Verizon's 2024 Data Breach Investigations Report (DBIR) found that even well-resourced organizations take around 55 days to remediate half of their critical vulnerabilities once patches are available. Every day in that window is a day the vulnerability stays exploitable.
Most patching workflows were built for a slower era. Security scans for vulnerabilities, files a ticket, and hands it to IT. IT coordinates the patch across tools, then waits on users to restart. Detection and remediation live in separate systems, so the handoff is where the time disappears.
What Vulnerability Response actually does
Vulnerability Response patches vulnerable applications in the Auto Apps catalog automatically, based on CVE severity and the rules the admin sets. The Iru Agent caches files and installs when an app is closed, or prompts the user ahead of a deadline when action is required. The admin sets the response once, and Iru manages the patching itself. As a result, end users work safely without needing to act on updates.
Detection and remediation sit in the same platform, so there is no second tool to reconcile. The Vulnerabilities view tracks remediation progress alongside the CVEs themselves. On Mac, this runs end to end without manual intervention.
Why it scales when teams don't
When a team manages hundreds of devices and applications, manual patching breaks down. Triaging CVEs by hand, mapping them to affected apps, and chasing restarts costs hours per cycle, multiplied across every new disclosure.
Vulnerability Response removes the per-patch labor. The cost of closing a vulnerability stops scaling with the size of the fleet. Teams keep pace with the volume because the tooling absorbs the work, not because they added headcount.
"Iru VM has simplified our entire vulnerability strategy. Combined with automatic Vulnerability Remediation and Auto-Apps, our support team of 7 can easily keep over 90 tenants compliant while we spend our time on client requests."
— Nick Reese, Sr. Engineer at Foojee
Getting started
Vulnerability Response is available to every customer running Iru Vulnerability Management on Mac. Configure it, add it to a Blueprint with an Assignment Map, and the catalog stays patched against critical CVEs without manual follow-up.
Book a demo to see it close the gap on your own fleet.