Loop 0: Foundational Controls
| Control | Why It's Foundational | Minimum Viable |
|---|---|---|
| Immutable Backups | Can't patch fast enough? You need to recover. Ransomware, failed patches, supply chain compromise — all need rollback capability. 89% of ransomware victims had backups targeted. | 3-2-1-1 rule: 3 copies, 2 media, 1 offsite, 1 immutable (S3 Object Lock / Wasabi / Borg append-only). Separate backup admin credentials from domain admin. Test restores monthly. |
| Network Segmentation | Unpatched system on a flat network = everyone's problem. Segmented = that VLAN's problem. Segmentation buys time that flat networks don't give you. It's the compensating control when you can't patch fast enough. | 3-4 VLANs minimum: workstations, servers, backup infrastructure, management. Firewall rules between zones. Default deny. Weekend project with any managed switch. |
| Identity Hardening | 56% of breaches start with stolen credentials. Edge device exploitation + credential theft = lateral movement. If the identity layer is weak, patching the endpoint doesn't help. | MFA everywhere (VPN, email, admin). Separate admin accounts. LAPS for local admin. Block legacy auth. FIDO2 for privileged accounts. |
Entry Point: Vulnerability Posture Assessment
Assessment Steps
- External attack surface: Shodan/Censys search on public IPs — what's exposed? Forgotten test servers, open RDP, management interfaces.
- Edge device inventory: List every VPN, firewall, remote access gateway. Check firmware versions against vendor advisories and CISA KEV.
- Hypervisor & management-plane inventory: ESXi/vCenter versions, exposed management interfaces, NAS admin consoles. These can't run EDR — patch cadence and network isolation are the only controls that exist.
- Internal vulnerability scan: OpenVAS/Greenbone CE against internal network. Filter results: KEV matches first, then EPSS > 10%, then CVSS Critical.
- EOL inventory: Windows Server 2012/2008, Windows 7/8, unsupported Linux kernels. 62% of compromised AD servers run EOL OS.
- Patch cadence reality check: When was the last edge device firmware update? Last OS patch cycle? Last third-party app update?
Output
Prioritized action list in three buckets: This week (KEV matches, exposed services) This month (EPSS > 10%, EOL systems) This quarter (everything else). Plus insurance gap analysis.
- Subscribe to CISA KEV alerts — email notifications when new vulns are added. 5 per week on average.
- Subscribe to your VPN/firewall vendor's security advisory feed (Fortinet PSIRT, Palo Alto Security Advisories, Ivanti Security Advisories, Cisco PSIRT)
- Document who can emergency-patch edge devices and how (credentials, access method, change authorization). Before the crisis.
- Pre-write firewall rules to isolate edge devices if patching isn't immediately possible — block inbound to the vulnerable service while maintaining management access
- Emergency patch playbook: KEV alert received → check if affected → patch or isolate within 48 hours. Named roles, pre-authorized change windows, rollback plan.
- Compensating control library: For each edge device type, pre-documented temporary mitigations (disable vulnerable feature, restrict source IPs, enable WAF rule) when patching requires a maintenance window.
- Segmentation as emergency containment: Pre-configured VLAN rules that isolate a compromised segment. The firewall rules are ready; execution takes minutes, not hours.
KEV alert to patch/isolation in under 48 hours. Edge devices patchable without waiting for change windows. Compensating controls pre-documented for every critical system. Segmentation rules ready for instant activation.
- Run a Shodan search on your public IP range — see what the internet sees. $49 lifetime membership for monitoring.
- Enroll in CISA Cyber Hygiene Services — free external vulnerability scanning, weekly reports
- Run Nuclei against web-facing assets — thousands of community templates for CVE detection, exposed panels, default creds
- Cross-reference your edge device firmware versions against CISA KEV JSON — any match = patch this week
- Enable Windows Update for Business with deferral rings — pilot group gets updates immediately, broad deployment 7–14 days later. Free with Windows Pro/Enterprise.
- Deploy OpenVAS/Greenbone CE for authenticated internal vulnerability scanning — schedule monthly scans
- Deploy Wazuh agents on all endpoints — vulnerability detection module cross-references installed packages against NVD
- Deploy Trivy in CI/CD pipeline — block vulnerable container images from deploying
- Build prioritization workflow: scan results → filter by KEV (immediate) → filter by EPSS > 10% (this week) → CVSS Critical remainder (this month) → everything else (quarterly)
- Set up asset inventory — Wazuh agent inventory + network scan results + cloud API asset lists. Even a spreadsheet beats nothing.
Complete asset inventory. Monthly internal scans. Continuous external monitoring. Every vulnerability prioritized by actual exploitation risk (KEV + EPSS), not CVSS alone. Zero KEV matches older than 48 hours.
- Enable browser auto-update (Chrome, Edge, Firefox) org-wide via GPO — browsers are consistently in the top exploited categories
- Enable automatic security updates on Linux servers:
apt install unattended-upgrades(Debian/Ubuntu) or equivalent - Enable Office auto-update — Microsoft led all vendors with 39 KEV additions in 2025
- Deploy winget upgrade via GPO scheduled task for third-party apps:
winget upgrade --all --silent --accept-package-agreements - Patch your VPN/firewall firmware right now if it's more than one version behind
- Patch VMware vCenter/ESXi right now — CVE-2026-59310 (vCenter directory-traversal RCE, CVSS 9.8, patched Jul 29 2026) was under active exploitation within 5 days of disclosure; CVE-2024-37085 (AD-group ESXi auth bypass) remains a live ransomware entry point
- Disable or remove EOL systems that aren't actively needed (Windows 2008/2012 test boxes, forgotten dev servers)
- Patch SLA definition:
| Category | SLA | Rationale |
|---|---|---|
| CISA KEV match | 48 hours | Confirmed actively exploited |
| Edge device critical | 48 hours | 20 of 33 enterprise zero-days in 2024 hit security & networking products |
| EPSS > 10% | 7 days | High exploitation probability |
| CVSS Critical (EPSS low) | 14 days | Severe but unlikely to be exploited |
| CVSS High | 30 days | Standard remediation |
| CVSS Medium/Low | 90 days | Scheduled maintenance |
- Exposure-tiered SLA: the table above ranks by exploitation signal. This one ranks by where the asset sits. Apply both — whichever SLA is shorter wins.
| Severity | Isolated LAN | Internal LAN | Partner-facing | Internet-facing |
|---|---|---|---|---|
| Critical | 7 days | 2 days | 1 day | 1 day |
| High | 7 days | 5 days | 3 days | 3 days |
| Medium | 14 days | 7 days | 5 days | 5 days |
| Low | 21 days | 7 days | 14 days | 14 days |
- Edge device patching process: dedicated maintenance windows, pre-tested in lab/staging where possible, rollback plan documented
- Segmentation for unpatchable systems: legacy systems that can't be patched get isolated into their own VLAN with strict firewall rules. Segmentation buys time when patching isn't possible.
- Third-party patching automation: WUfB (OS) + winget (third-party) + unattended-upgrades (Linux) + Renovate/Dependabot (code dependencies)
- Immutable backups verified before major patches: if the patch breaks production, you need a known-good restore point. Test backup integrity before applying changes to critical systems.
Edge devices patched within 48 hours of advisory. Browsers and OS auto-updated. KEV matches cleared within 48 hours. Unpatchable systems segmented. Backup integrity verified before critical patches. The speed gap is closed for everything that matters.
- Download CISA KEV JSON and build a simple cross-reference against your software inventory
- Bookmark EPSS API — query any CVE for 30-day exploitation probability. Free, daily updates, no API key.
- Set up monthly scan calendar: Week 1 = scan, Week 2 = triage + prioritize, Week 3-4 = remediate
- Vulnerability management cadence:
| Cadence | Action | Tool |
|---|---|---|
| Continuous | KEV alert monitoring | CISA email alerts |
| Continuous | Endpoint vulnerability detection | Wazuh agents |
| Weekly | External attack surface check | Shodan / CISA Cyber Hygiene |
| Monthly | Internal vulnerability scan | OpenVAS / Greenbone CE |
| Monthly | Edge device firmware version check | Vendor advisories + KEV cross-ref |
| Monthly | Patch compliance report | WUfB / Wazuh / WSUS |
| Quarterly | EOL system review | AD query + manual inventory |
| Quarterly | Third-party app audit | winget + manual review |
| Annually | Full penetration test (external + internal) | Hired / internal |
Zero KEV matches in the environment older than 48 hours. Monthly scan cadence with documented remediation. Patch compliance tracking dashboard for management and insurance evidence. EOL systems on a funded migration timeline.
- Classify systems into tiers by criticality: Tier 0 (AD/identity), Tier 1 (revenue-generating), Tier 2 (supporting), Tier 3 (nice-to-have). Patch priority follows tier order.
- Document your actual patch cadence (not the policy — what really happens). This is your insurance evidence.
- Network segmentation implementation: VLANs for workstations, servers, backup infra, management, guests. Firewall rules between zones. Default deny. Unpatchable/legacy systems get their own restricted segment.
- Immutable backup architecture: 3-2-1-1 with WORM storage. Isolated backup VLAN. Separate credentials. Tested monthly restores. This is the control that makes "failed to patch in time" survivable.
- Zero-day response architecture: Pre-built isolation rules per segment. When a zero-day drops on your edge device, you can isolate the affected segment within minutes while the vendor prepares a patch.
- EOL migration roadmap: Funded timeline for replacing out-of-support systems. Compensating controls (segmentation, monitoring, WAF) documented for each EOL system until migration.
- Insurance evidence package: documented patch management process, scan cadence evidence, SLA compliance metrics, EOL migration plan. Insurers want proof of process, not perfection.
- NIS2 alignment: "Vulnerability handling and disclosure" is one of 10 mandatory NIS2 measures. Documented VM process + patch SLAs + scan evidence = compliance artifact.
Architecture where an unpatched vulnerability in one system cannot cascade to compromise the entire environment. Segmentation limits blast radius. Immutable backups guarantee recovery. Patch cadence is documented, measured, and evidence-ready for insurers and regulators.
Program Economics (200-seat reference)
| Engagement | Duration | Investment |
|---|---|---|
| Assessment + prioritized action list | 1–2 days | €1,250 – 2,500 |
| 1 Containment | 1 day | €1,250 |
| 2 Detection | 2–3 days | €2,500 – 3,750 |
| 3 Posture | 2–3 days | €2,500 – 3,750 |
| 4 Vuln Mgmt | 1 day + monthly | €1,250 + €5,000/yr |
| 5 Structural | 3–5 days | €3,750 – 6,250 |
| Full program | 10–15 days | €12,500 – 18,750 + retainer |
Easy to Do (This Week, Free)
- Subscribe to CISA KEV alerts + vendor advisories
- Patch your VPN/firewall firmware right now
- Enable browser auto-update org-wide
- Enable OS auto-update (WUfB / unattended-upgrades)
- Enable Office auto-update
- Deploy winget upgrade via GPO
- Run Shodan/Censys on your public IPs
- Enroll in CISA Cyber Hygiene (US)
- Run Nuclei against web assets
- Disable/remove EOL systems not in use
- Cross-reference edge device versions vs KEV
- Document who can emergency-patch edge devices
Hard to Do (Needs Architecture)
- Complete asset inventory — can't patch what you don't know exists. Shadow IT, forgotten servers, IoT.
- Risk-based prioritization — needs business context that no scanner provides. Which servers matter? Which are internet-facing?
- Legacy system migration — the Windows 2012 server that "can't be updated because the app breaks." Needs budget, testing, and a migration plan.
- Network segmentation — VLAN design, firewall rules, testing. One-time effort but requires network access and change windows.
- Immutable backup infrastructure — separate VLAN, separate credentials, WORM storage, tested restores. Real architecture work.
- Cross-platform patching — Windows + Linux + macOS + network devices + OT. No single tool covers all. Requires orchestration.
- OT/IoT patching — vendor-dependent, change windows, operational impact. Often requires vendor involvement.
- Firmware patching — BIOS, BMC, network device firmware. Vendor-specific, often manual, high risk of bricking.
Free / Open-Source Tools
- OpenVAS / Greenbone CE — Network vuln scanner
- Nuclei — Template-based web/infra scanner
- Wazuh — XDR + vuln detection agents
- Trivy — Container/code scanning
- CISA KEV — Exploited vuln catalog (JSON)
- EPSS — Exploitation probability API
- Shodan — External attack surface ($49)
- Censys — Internet asset discovery
- Renovate — Automated dependency updates
- Lynis — Linux hardening audit
Prioritization Cheat Sheet
| Signal | Action | SLA |
|---|---|---|
| On CISA KEV | Patch immediately | 48 hours |
| Edge device + critical | Patch immediately | 48 hours |
| EPSS > 10% | Patch this week | 7 days |
| CVSS Critical, EPSS low | Patch this sprint | 14 days |
| CVSS High | Schedule | 30 days |
| CVSS Medium/Low | Maintenance window | 90 days |
| Not on KEV, EPSS < 1% | Batch quarterly | 90 days |