Vulnerability Management & Patching

Easy vs Hard — What Actually Gets You Breached vs What Can Wait

5 days
avg time-to-exploit in 2023 (down from 63)
55 days
to patch 50% of critical KEV vulns
2.3%
of CVSS 7+ seen exploited (est.)
44%
of 2024 zero-days hit enterprise tech
27yr
oldest bug found by AI (Anthropic Mythos, 2026)
Methodology: Vulnerability prioritisation (KEV + EPSS over CVSS) is detection engineering applied to the vulnerability management loop. See Detection Engineering for the full framework.
The speed gap is now negative. Average time-to-exploit dropped from 63 days (2018–19) to 32 days (2021–22) to 5 days (2023, Mandiant). 28% of KEVs added in Q1 2025 had exploitation evidence within a day of CVE publication (VulnCheck). 80% of exploits are published before CVEs are even issued. Your 30-day patch cycle is 25 days too slow for edge devices.
But only a small fraction of "critical" vulns (est. ~2.3% of CVSS 7+) are ever seen exploited. The problem isn't patching speed — it's patching the wrong things. CISA KEV (245 vulns/year = 5/week) is the real priority list. EPSS tells you which of the rest actually matter. Stop chasing CVSS scores.
April 2026: AI is now finding the vulns, not just exploiting them. Anthropic's Mythos model autonomously discovered zero-days in OpenBSD (27 years old), FFmpeg (16 years old), and FreeBSD NFS (remote root, CVE-2026-4747). It wrote working exploits including ROP chains and privilege escalation — 10 full control-flow hijacks from 7,000 targets, where previous models scored zero. Over 99% of its discoveries remain unpatched. The vulnerability pipeline just got a firehose. Your patch cadence assumptions need to account for AI-accelerated discovery — not just human researchers and scanners.

Loop 0: Foundational Controls

These three controls sit underneath every package. If they're not in place, nothing else matters. They're the floor, not a feature.
ControlWhy It's FoundationalMinimum Viable
Immutable BackupsCan't patch fast enough? You need to recover. Ransomware, failed patches, supply chain compromise — all need rollback capability. 89% of ransomware victims had backups targeted.3-2-1-1 rule: 3 copies, 2 media, 1 offsite, 1 immutable (S3 Object Lock / Wasabi / Borg append-only). Separate backup admin credentials from domain admin. Test restores monthly.
Network SegmentationUnpatched system on a flat network = everyone's problem. Segmented = that VLAN's problem. Segmentation buys time that flat networks don't give you. It's the compensating control when you can't patch fast enough.3-4 VLANs minimum: workstations, servers, backup infrastructure, management. Firewall rules between zones. Default deny. Weekend project with any managed switch.
Identity Hardening56% of breaches start with stolen credentials. Edge device exploitation + credential theft = lateral movement. If the identity layer is weak, patching the endpoint doesn't help.MFA everywhere (VPN, email, admin). Separate admin accounts. LAPS for local admin. Block legacy auth. FIDO2 for privileged accounts.

Entry Point: Vulnerability Posture Assessment

What's exposed, what's exploitable, and what do we patch first? Not a 10,000-finding scan report — a prioritized action list based on what attackers actually target.
1–2 days Entry point

Assessment Steps

  • External attack surface: Shodan/Censys search on public IPs — what's exposed? Forgotten test servers, open RDP, management interfaces.
  • Edge device inventory: List every VPN, firewall, remote access gateway. Check firmware versions against vendor advisories and CISA KEV.
  • Hypervisor & management-plane inventory: ESXi/vCenter versions, exposed management interfaces, NAS admin consoles. These can't run EDR — patch cadence and network isolation are the only controls that exist.
  • Internal vulnerability scan: OpenVAS/Greenbone CE against internal network. Filter results: KEV matches first, then EPSS > 10%, then CVSS Critical.
  • EOL inventory: Windows Server 2012/2008, Windows 7/8, unsupported Linux kernels. 62% of compromised AD servers run EOL OS.
  • Patch cadence reality check: When was the last edge device firmware update? Last OS patch cycle? Last third-party app update?

Output

Prioritized action list in three buckets: This week (KEV matches, exposed services) This month (EPSS > 10%, EOL systems) This quarter (everything else). Plus insurance gap analysis.

1 Containment — Active Exploitation Response
A vulnerability you own is being actively exploited in the wild (CISA KEV alert, vendor emergency advisory, or your scan found it). What do you do in the next 4 hours?
Quick Wins (Day 0, Free)
  • Subscribe to CISA KEV alerts — email notifications when new vulns are added. 5 per week on average.
    5 minFree
  • Subscribe to your VPN/firewall vendor's security advisory feed (Fortinet PSIRT, Palo Alto Security Advisories, Ivanti Security Advisories, Cisco PSIRT)
    10 minFree
  • Document who can emergency-patch edge devices and how (credentials, access method, change authorization). Before the crisis.
    30 minFree
  • Pre-write firewall rules to isolate edge devices if patching isn't immediately possible — block inbound to the vulnerable service while maintaining management access
    1 hourFree
Core Engagement (1 day)
  • Emergency patch playbook: KEV alert received → check if affected → patch or isolate within 48 hours. Named roles, pre-authorized change windows, rollback plan.
  • Compensating control library: For each edge device type, pre-documented temporary mitigations (disable vulnerable feature, restrict source IPs, enable WAF rule) when patching requires a maintenance window.
  • Segmentation as emergency containment: Pre-configured VLAN rules that isolate a compromised segment. The firewall rules are ready; execution takes minutes, not hours.
Target State

KEV alert to patch/isolation in under 48 hours. Edge devices patchable without waiting for change windows. Compensating controls pre-documented for every critical system. Segmentation rules ready for instant activation.

2 Detection — Know What's Vulnerable
You can't patch what you can't see. Continuous visibility into what's running, what's exposed, and what's exploitable.
Quick Wins (Day 0, Free)
  • Run a Shodan search on your public IP range — see what the internet sees. $49 lifetime membership for monitoring.
    30 min$49 one-time
  • Enroll in CISA Cyber Hygiene Services — free external vulnerability scanning, weekly reports
    15 min emailFree (US orgs)
  • Run Nuclei against web-facing assets — thousands of community templates for CVE detection, exposed panels, default creds
    2 hoursFree / OSS
  • Cross-reference your edge device firmware versions against CISA KEV JSON — any match = patch this week
    1 hourFree
  • Enable Windows Update for Business with deferral rings — pilot group gets updates immediately, broad deployment 7–14 days later. Free with Windows Pro/Enterprise.
    2 hoursFree (built-in)
Core Engagement (2–3 days)
  • Deploy OpenVAS/Greenbone CE for authenticated internal vulnerability scanning — schedule monthly scans
  • Deploy Wazuh agents on all endpoints — vulnerability detection module cross-references installed packages against NVD
  • Deploy Trivy in CI/CD pipeline — block vulnerable container images from deploying
  • Build prioritization workflow: scan results → filter by KEV (immediate) → filter by EPSS > 10% (this week) → CVSS Critical remainder (this month) → everything else (quarterly)
  • Set up asset inventory — Wazuh agent inventory + network scan results + cloud API asset lists. Even a spreadsheet beats nothing.
Target State

Complete asset inventory. Monthly internal scans. Continuous external monitoring. Every vulnerability prioritized by actual exploitation risk (KEV + EPSS), not CVSS alone. Zero KEV matches older than 48 hours.

3 Posture — Close the Speed Gap
Attackers exploit in 5 days. You patch in 55. Close the gap where it matters most: edge devices, browsers, OS, and the things on the KEV list.
Quick Wins (Day 0, Free)
  • Enable browser auto-update (Chrome, Edge, Firefox) org-wide via GPO — browsers are consistently in the top exploited categories
    30 minFree
  • Enable automatic security updates on Linux servers: apt install unattended-upgrades (Debian/Ubuntu) or equivalent
    30 min/serverFree
  • Enable Office auto-update — Microsoft led all vendors with 39 KEV additions in 2025
    30 minFree
  • Deploy winget upgrade via GPO scheduled task for third-party apps: winget upgrade --all --silent --accept-package-agreements
    1 hourFree
  • Patch your VPN/firewall firmware right now if it's more than one version behind
    1–2 hoursFree
  • Patch VMware vCenter/ESXi right now — CVE-2026-59310 (vCenter directory-traversal RCE, CVSS 9.8, patched Jul 29 2026) was under active exploitation within 5 days of disclosure; CVE-2024-37085 (AD-group ESXi auth bypass) remains a live ransomware entry point
    1–2 hoursFree
  • Disable or remove EOL systems that aren't actively needed (Windows 2008/2012 test boxes, forgotten dev servers)
    VariesFree
Core Engagement (2–3 days)
  • Patch SLA definition:
CategorySLARationale
CISA KEV match48 hoursConfirmed actively exploited
Edge device critical48 hours20 of 33 enterprise zero-days in 2024 hit security & networking products
EPSS > 10%7 daysHigh exploitation probability
CVSS Critical (EPSS low)14 daysSevere but unlikely to be exploited
CVSS High30 daysStandard remediation
CVSS Medium/Low90 daysScheduled maintenance
  • Exposure-tiered SLA: the table above ranks by exploitation signal. This one ranks by where the asset sits. Apply both — whichever SLA is shorter wins.
SeverityIsolated LANInternal LANPartner-facingInternet-facing
Critical7 days2 days1 day1 day
High7 days5 days3 days3 days
Medium14 days7 days5 days5 days
Low21 days7 days14 days14 days
Source: Berlin, Brotherston & Reyor, Defensive Security Handbook, 2nd ed. (O'Reilly, 2024), Table 18-1, reproduced as published — the authors present it as an example to adapt, not a standard. Adapt the columns to the client's real zones. Note the Low row as printed gives the internal LAN a shorter deadline than internet-facing; most clients will want to flip that.
  • Edge device patching process: dedicated maintenance windows, pre-tested in lab/staging where possible, rollback plan documented
  • Segmentation for unpatchable systems: legacy systems that can't be patched get isolated into their own VLAN with strict firewall rules. Segmentation buys time when patching isn't possible.
  • Third-party patching automation: WUfB (OS) + winget (third-party) + unattended-upgrades (Linux) + Renovate/Dependabot (code dependencies)
  • Immutable backups verified before major patches: if the patch breaks production, you need a known-good restore point. Test backup integrity before applying changes to critical systems.
Target State

Edge devices patched within 48 hours of advisory. Browsers and OS auto-updated. KEV matches cleared within 48 hours. Unpatchable systems segmented. Backup integrity verified before critical patches. The speed gap is closed for everything that matters.

4 Vulnerability Management — Continuous Cycle
Not a project — a cadence. Scan, prioritize, patch, verify, repeat. The cadence matters more than the tools.
Quick Wins (Day 0, Free)
  • Download CISA KEV JSON and build a simple cross-reference against your software inventory
    1 hourFree
  • Bookmark EPSS API — query any CVE for 30-day exploitation probability. Free, daily updates, no API key.
    10 minFree
  • Set up monthly scan calendar: Week 1 = scan, Week 2 = triage + prioritize, Week 3-4 = remediate
    15 minFree
Core Engagement (1 day + cadence)
  • Vulnerability management cadence:
CadenceActionTool
ContinuousKEV alert monitoringCISA email alerts
ContinuousEndpoint vulnerability detectionWazuh agents
WeeklyExternal attack surface checkShodan / CISA Cyber Hygiene
MonthlyInternal vulnerability scanOpenVAS / Greenbone CE
MonthlyEdge device firmware version checkVendor advisories + KEV cross-ref
MonthlyPatch compliance reportWUfB / Wazuh / WSUS
QuarterlyEOL system reviewAD query + manual inventory
QuarterlyThird-party app auditwinget + manual review
AnnuallyFull penetration test (external + internal)Hired / internal
Target State

Zero KEV matches in the environment older than 48 hours. Monthly scan cadence with documented remediation. Patch compliance tracking dashboard for management and insurance evidence. EOL systems on a funded migration timeline.

5 Structural — Architecture That Survives Unpatched Vulns
You will never be fully patched. The question is: when the next zero-day drops on your VPN at 2 AM Friday, does your architecture limit the blast radius or amplify it?
Quick Wins (Day 0, Free)
  • Classify systems into tiers by criticality: Tier 0 (AD/identity), Tier 1 (revenue-generating), Tier 2 (supporting), Tier 3 (nice-to-have). Patch priority follows tier order.
    1 hourFree
  • Document your actual patch cadence (not the policy — what really happens). This is your insurance evidence.
    1 hourFree
Core Engagement (3–5 days)
  • Network segmentation implementation: VLANs for workstations, servers, backup infra, management, guests. Firewall rules between zones. Default deny. Unpatchable/legacy systems get their own restricted segment.
  • Immutable backup architecture: 3-2-1-1 with WORM storage. Isolated backup VLAN. Separate credentials. Tested monthly restores. This is the control that makes "failed to patch in time" survivable.
  • Zero-day response architecture: Pre-built isolation rules per segment. When a zero-day drops on your edge device, you can isolate the affected segment within minutes while the vendor prepares a patch.
  • EOL migration roadmap: Funded timeline for replacing out-of-support systems. Compensating controls (segmentation, monitoring, WAF) documented for each EOL system until migration.
  • Insurance evidence package: documented patch management process, scan cadence evidence, SLA compliance metrics, EOL migration plan. Insurers want proof of process, not perfection.
  • NIS2 alignment: "Vulnerability handling and disclosure" is one of 10 mandatory NIS2 measures. Documented VM process + patch SLAs + scan evidence = compliance artifact.
Why structural controls matter more now: Anthropic's Frontier Red Team expects that mitigations whose value comes mainly from friction — controls that make exploitation tedious rather than impossible — “may become considerably weaker against model-assisted adversaries,” while hard barriers like KASLR and W^X remain important (Mythos Preview assessment, April 2026). Segmentation, FIDO2 and WORM backups are our application of that principle: they refuse the attacker's action instead of slowing it down. See the barrier test in the Foundation.
Target State

Architecture where an unpatched vulnerability in one system cannot cascade to compromise the entire environment. Segmentation limits blast radius. Immutable backups guarantee recovery. Patch cadence is documented, measured, and evidence-ready for insurers and regulators.

Program Economics (200-seat reference)

EngagementDurationInvestment
Assessment + prioritized action list1–2 days€1,250 – 2,500
1 Containment1 day€1,250
2 Detection2–3 days€2,500 – 3,750
3 Posture2–3 days€2,500 – 3,750
4 Vuln Mgmt1 day + monthly€1,250 + €5,000/yr
5 Structural3–5 days€3,750 – 6,250
Full program10–15 days€12,500 – 18,750 + retainer
Scanning stack cost: $49 (Shodan membership). Everything else is free. The investment is the expertise to prioritize, not the tools to scan.

Easy to Do (This Week, Free)

  • Subscribe to CISA KEV alerts + vendor advisories
  • Patch your VPN/firewall firmware right now
  • Enable browser auto-update org-wide
  • Enable OS auto-update (WUfB / unattended-upgrades)
  • Enable Office auto-update
  • Deploy winget upgrade via GPO
  • Run Shodan/Censys on your public IPs
  • Enroll in CISA Cyber Hygiene (US)
  • Run Nuclei against web assets
  • Disable/remove EOL systems not in use
  • Cross-reference edge device versions vs KEV
  • Document who can emergency-patch edge devices
Impact: Closes the gap on the #1 exploitation target (edge devices) and automates patching for the top 3 categories (browsers, OS, Office). Handles 80% of the risk.

Hard to Do (Needs Architecture)

  • Complete asset inventory — can't patch what you don't know exists. Shadow IT, forgotten servers, IoT.
  • Risk-based prioritization — needs business context that no scanner provides. Which servers matter? Which are internet-facing?
  • Legacy system migration — the Windows 2012 server that "can't be updated because the app breaks." Needs budget, testing, and a migration plan.
  • Network segmentation — VLAN design, firewall rules, testing. One-time effort but requires network access and change windows.
  • Immutable backup infrastructure — separate VLAN, separate credentials, WORM storage, tested restores. Real architecture work.
  • Cross-platform patching — Windows + Linux + macOS + network devices + OT. No single tool covers all. Requires orchestration.
  • OT/IoT patching — vendor-dependent, change windows, operational impact. Often requires vendor involvement.
  • Firmware patching — BIOS, BMC, network device firmware. Vendor-specific, often manual, high risk of bricking.
Impact: The remaining 20% of risk. Each item is high-effort but addresses structural gaps that accumulate over years. This is what separates "we patch things" from "we have a vulnerability management program."

Free / Open-Source Tools

  • OpenVAS / Greenbone CE — Network vuln scanner
  • Nuclei — Template-based web/infra scanner
  • Wazuh — XDR + vuln detection agents
  • Trivy — Container/code scanning
  • CISA KEV — Exploited vuln catalog (JSON)
  • EPSS — Exploitation probability API
  • Shodan — External attack surface ($49)
  • Censys — Internet asset discovery
  • Renovate — Automated dependency updates
  • Lynis — Linux hardening audit

Prioritization Cheat Sheet

SignalActionSLA
On CISA KEVPatch immediately48 hours
Edge device + criticalPatch immediately48 hours
EPSS > 10%Patch this week7 days
CVSS Critical, EPSS lowPatch this sprint14 days
CVSS HighSchedule30 days
CVSS Medium/LowMaintenance window90 days
Not on KEV, EPSS < 1%Batch quarterly90 days
The 2.3% rule: By one estimate, only ~2.3% of CVSS 7+ vulns are ever seen exploited. KEV + EPSS tells you which ones. Stop patching by CVSS score alone.