Embracing Risk-Based Patching: The New Standard in Cybersecurity

Jul 29, 2026 835 views

CISA’s recent Binding Operational Directive, BOD 26-04, represents a significant shift in how federal agencies are expected to manage vulnerabilities. Departing from the traditional model that mandates immediate attention to all critical vulnerabilities, this directive introduces a more nuanced approach centered on risk prioritization. Agencies are now directed to address vulnerabilities based on their potential impact, with timelines ranging from three days for the highest-risk vulnerabilities to deferrals for those deemed low risk. While this change is a step in the right direction, it marks only the beginning of a much-needed transformation in vulnerability management practices.

Historically, security teams have recognized that a vulnerability's severity score alone isn’t sufficient to assess its risk. A low CVSS score might not reflect critical factors such as whether the vulnerability is accessible from the internet, currently being exploited, or results in significant control by an attacker. BOD 26-04 addresses this by encouraging organizations to prioritize their efforts on the vulnerabilities most likely to be exploited.

However, the landscape is evolving at a rapid pace due to advancements in AI, which is streamlining every phase of cyberattacks and frequently outpacing traditional vulnerability management strategies. As reported by CrowdStrike, the average time for attackers to move laterally within a compromised network has plummeted to just 29 minutes, with some incidents recorded at a staggering 27 seconds. Once inside, the handoff of access among cybercriminals occurs in a median of 22 seconds, indicating a new era of speed and sophistication in breaches.

Simultaneously, AI is becoming a target for attacks as organizations increasingly deploy AI tools. This influx of AI-driven solutions, which can include copilots and autonomous workflows, introduces new vulnerabilities that require careful management and security measures.

Reassessing Defensive Strategies

In this fast-paced environment, the urgency associated with a three-day remediation timeline for high-risk vulnerabilities may seem insufficient. Modern attackers do not merely exploit known vulnerabilities (CVEs); they take advantage of a broader array of weaknesses, including compromised identities, cloud misconfigurations, exposed APIs, and even AI systems, to construct complex pathways into critical assets. While BOD 26-04 is a commendable advancement, the escalating role of AI in cyber threats necessitates a thorough rethink of existing security protocols rather than mere acceleration of remediation efforts.

The Evolving Dynamics of Cyberattacks

AI offers considerable advantages for attackers by automating tasks such as reconnaissance, phishing, and lateral movement, which were previously manual processes reliant on teams of skilled professionals. Recent findings reveal that autonomous agents can manage much of the operational work involved in sophisticated cyber attacks under human supervision. This paradigm shift means that attackers can scale campaigns more effortlessly, targeting numerous vulnerabilities simultaneously while continuously probing for security weaknesses.

Organizations have traditionally operated under the assumption that they have sufficient time to identify and address security concerns, often taking weeks or months to resolve issues. This is increasingly inaccurate as attackers are now capable of exploiting vulnerabilities almost immediately upon their disclosure, sometimes even weaponizing them before defenders have a chance to react.

Understanding Attack Paths

Security organizations often compartmentalize their efforts across separate teams—vulnerability management handles CVEs, identity teams focus on authentication, and application security deals with individual code reviews. However, attackers do not regard these divisions. Their goal is to exploit valuable assets and they will utilize any available means, which may involve integrating multiple forms of vulnerabilities. The Verizon Breach report from 2026 illustrates this point, noting that while 31% of breaches involved direct exploitation of vulnerabilities, a significant 39% were linked to identity compromises.

An attacker may start their campaign by compromising a low-privilege account before exploiting overly permissive access elsewhere, thus creating an effective attack path comprised of various types of exposures. When vulnerabilities are examined in isolation, their cumulative risk may be underestimated, leading to ineffective defensive strategies. CrowdStrike's findings show a 42% year-over-year surge in exploited vulnerabilities, many of which were targeted even before they were publicly disclosed. Organizations too focused on resolving high-severity issues without considering the context may find themselves vulnerable due to a lack of understanding of the most direct attacks.

Adopting Continuous Threat Exposure Management

To effectively respond to this evolving threat landscape, organizations should adopt Continuous Threat Exposure Management (CTEM) as a core part of their strategy. This approach emphasizes ongoing evaluation of the entirety of the organization’s exposure. It begins with an accurate, real-time inventory of all elements, including assets, identities, cloud infrastructures, and relationships between systems. From there, security teams can identify exposures, prioritize them based on their exploitability and potential impact, and validate these risks through ongoing testing.

Mandiant’s concept of the “Defender’s Advantage” highlights that while attackers need to familiarize themselves with an organization’s environment to exploit it, defenders already possess that knowledge—they just need to keep it up to date. With cloud systems and business technology shifting rapidly, constant mapping and assessment are essential for effective defense.

Integrating Validation Processes

Beyond merely identifying exposures, security teams must also confirm the exploitable nature of reported vulnerabilities as well as the effectiveness of remediation efforts. To achieve this, adversary-aware exposure validation becomes vital. Utilizing techniques like breach-and-attack simulation and automated penetration testing, organizations can continuously evaluate their defenses against tactics similar to those used by real attackers.

Rather than just checking for the presence of vulnerabilities, exposure validation should seek to answer critical questions: Can an attacker access the vulnerability? Can they exploit it to reach more valuable assets? Have remediation actions genuinely mitigated the risks associated with those vulnerabilities?

Focusing on Business Impact

The true value of effective validation lies in its alignment with business objectives. A medium-severity vulnerability impacting a revenue-generating application may pose a greater risk to the organization than numerous critical vulnerabilities in less central systems. By focusing on the business implications of vulnerabilities, security leaders can articulate their remediation strategies in terms that resonate with executives and align defensive measures with the pathways attackers are likely to exploit.

In summary, while CISA's BOD 26-04 is a pivotal advancement towards more strategic vulnerability management, the rapid evolution of AI has effectively made risk-based patching a necessity rather than a choice. Organizations that will thrive in this new landscape are those that can outsmart attackers by comprehensively understanding their own exposure and ensuring their defenses are as responsive as the threats they face.

This article is published as part of the Foundry Expert Contributor Network.
Want to join?

Source: James Rodriguez · www.csoonline.com

Comments

Sign in to comment.
No comments yet. Be the first to comment.

Related Articles

Risk-based patching is the future. AI made it table stakes