Organizations are increasingly recognizing the need to reevaluate their long-standing practices regarding patch management, especially in the fast-evolving landscape shaped by artificial intelligence (AI). The traditional methods employed to prioritize, remediate, and manage cyber-risk are now deemed insufficient, necessitating a fundamental shift in approach.
Since 2019, the gap between the disclosure of vulnerabilities and their exploitation has notably diminished, collapsing from periods measured in months or weeks to a matter of hours. This accelerated timeline poses a significant challenge for Chief Information Security Officers (CISOs) and their teams, who now have considerably less time to assess risks, prioritize remediation efforts, and safeguard vital assets. Notably, the Common Vulnerability Scoring System (CVSS)—historically used to assess vulnerabilities—has proven to be less effective in providing a reliable measure of actual risk in the absence of supplementary metrics, such as exploitability and the criticality of assets.
### Beyond Patch Deployment
In the current cybersecurity climate, effective vulnerability management extends beyond mere patch deployment. Organizations are encouraged to adopt a mindset focused on continuously identifying and mitigating the vulnerabilities most likely to be exploited by attackers. Nicole Carignan, the senior vice president of security and AI strategy at Darktrace, asserts that organizations should abandon the notion of vulnerability management as a closed-loop process ending with a patch. Instead, security leaders must prioritize responses by evaluating factors such as exploitability, exposure, asset importance, and the organization’s capability to detect and control exploitation when patching is delayed. She emphasizes the importance of understanding existing vulnerabilities, recognizing normal behavior patterns, and having the capability to autonomously respond or contain breaches before they escalate into larger incidents.
### Adopting Federal Guidelines
The change in perspective regarding vulnerability management is already occurring within U.S. federal agencies. The Cybersecurity and Infrastructure Security Agency (CISA) recently issued binding operational directive 26-04 in response to the challenges posed by AI-driven vulnerability discovery. This directive marks a transition from traditional severity-driven patch management to a risk-based approach, compelling agencies to consider factors that include active exploitation, internet exposure, the potential for automated exploitation, and the impact of potential attacks.
Agencies are mandated to remediate high-risk vulnerabilities within a stringent timeframe of three days, while lower-priority concerns can be deferred. Additionally, federal entities are required to conduct comprehensive forensic evaluations after addressing significant vulnerabilities to ascertain whether their systems have already been compromised. This directive underscores a growing consensus that assessing vulnerabilities solely based on technical severity is no longer sufficient; organizations must weigh the potential likelihood of exploitation against the operational and business ramifications of a successful breach.
### Contextualizing CVSS
Despite the evolution of vulnerability management strategies, CVSS can still serve as an initial tool for assessing risk. Jeffrey Wheatman, senior vice president and cyber-risk strategist at Black Kite, acknowledges the utility of CVSS but notes that context-driven insights are crucial. Metrics indicating the likelihood of a vulnerability being exploited within a specific timeframe can guide decision-making around patching. Organizations are urged to gather comprehensive context about the operational and financial ramifications of a vulnerability specific to their environment.
Wheatman advocates for a shift from a universal approach to patching toward a more nuanced strategy focused on addressing the vulnerabilities that pose the most immediate threat. He insists that businesses focus on potential risks to operations before considering the severity or technical aspects of vulnerabilities and explore alternative mitigation strategies. “Architect your program as patch intelligence, not patch management,” he advises.
### Emphasizing Behavioral Analytics
With the rapid advancements in AI, traditional detection and mitigation methodologies reliant on recognized attack signatures have become increasingly inadequate. AI enables attackers to generate diverse payloads at a pace that outstrips the development of detection techniques. Consequently, organizations are encouraged to adopt behavioral detection strategies that focus on identifying anomalies in user and system activity. This includes monitoring unusual authentication patterns, abnormal process behavior, and atypical data access flows.
Employing compensating controls, such as network segmentation and stringent enforcement of least-privilege access, is becoming essential. Darktrace’s Carignan emphasizes the need for investments in extensive visibility, behavioral analytics, and anomaly detection across various platforms. Organizations now face security challenges that extend beyond software vulnerabilities to include issues like identity theft, human error, and insider threats. Quick detection and containment of exploitation attempts are vital for maintaining security even in situations where immediate patching is unfeasible.
### Continuous Vulnerability Management
Douglas José Pereira dos Santos, a senior director at FortiGuard Labs, underscores the necessity of reshaping the perception of patch management into a continuous process of managing vulnerability exposure. This transition demands several strategic changes, including adjusting remediation service level agreements (SLAs) to account for layered risk signals and ensuring that threat intelligence informs vulnerability assessments from the outset. It’s also crucial to formalize compensating controls as integral components of risk mitigation, rather than viewing them as temporary solutions.
In essence, organizations must evolve from a rigid reliance on prevention as the primary security measure to adopting resilience as the foundational principle of their cybersecurity strategies. They should anticipate potential exploitations and design their environments to enable rapid detection and containment of attacks.
As exemplified by various insights shared by industry leaders, the contemporary cybersecurity landscape necessitates a holistic and proactive approach to vulnerability management, steering clear of outdated practices to enhance organizational resilience and security.

