About Partners Contact Client Portal
LinkedIn Twitter
Services Industries Insights & Events Careers & Culture
Insights & Events

Services

RubinBrown specializes in providing a comprehensive range of services to meet business and personal needs. Whether you require expert tax, strategic business consulting, audit services or more, RubinBrown's team of experienced professionals are here to support you.

View All Our Services
Assurance Services
Benefit Plan Audit Services Public Company Services SOC Examinations, IT Audit, & Third-Party Risk
Consulting Services
AI & Data Consulting Services Business Process Improvement Services Business Restructuring & Bankruptcy Services Cyber Security Services Independent ERP Selection Consultants Fraud & Forensics Healthcare Consulting Services SOC Examinations, IT Audit, & Third-Party Risk Information Technology Services Litigation Services Mergers & Acquisitions Services Risk & Internal Audit Services Valuation Services
Entrepreneurial Services
Outsourced Accounting & Advisory Services
Tax Services
Federal Tax Services Private Client Services Credits & Incentives Services State & Local Tax Services
Wealth Management Services by RubinBrown Advisors RubinBrown Corporate Finance

Industries

At RubinBrown, we bring experience across a range of industries. Our experience enables our professionals to offer tailored solutions catering to the intricacies of each sector. Our professionals have years of focused engagement and skills, allowing them to navigate industry-specific challenges to benefit our clients.

View All Our Industries
Colleges & Universities Construction Financial Institutions Gaming Healthcare Law Firms Life Sciences & Technology Manufacturing & Distribution Not-For-Profit Private Equity Public Sector Real Estate Transportation & Dealerships

Careers & Culture

At RubinBrown, we are inspired team members, working as one firm, living our core values, and Being Our Best for Others while delivering totally satisfied clients. We invite you to learn more about the Firm's culture, the Be Your Best for Others mentality, and explore the available opportunities at RubinBrown.

Discover Our Culture
Baker Tilly International Campus Recruiting Diversity & Inclusion Experienced Recruiting RubinBrown Charitable Foundation Join The Team
Back to Insights

Why the Shrinking Patch Window Makes Vulnerability Management a Business Risk Decision

Contact Us

Why the Shrinking Patch Window Makes Vulnerability Management a Business Risk Decision

Contact Us

October is Cyber Security Awareness Month. This is the second article in a series throughout October that will call attention to the importance of cyber security awareness.


Why this matters

Attackers and remediation teams operate on different schedules. Leaders need to know which weaknesses threaten critical operations now, what reduces exposure while a fix is pending, and who can authorize faster action.

The objective is risk-based vulnerability management: direct limited resources toward the exposures most likely to cause consequential harm. Treating every patch as an emergency is impractical. Treating every patch as routine maintenance can be dangerous.

The numbers show two different clocks

The 2026 Verizon Data Breach Investigations Report found:

  • 43 days was the median time to fully remediate a vulnerability, up from 32 days.
  • 26% of vulnerabilities in CISA’s Known Exploited Vulnerabilities catalog were fully remediated in the report’s data.
  • 31% of breaches involved software vulnerability exploitation, overtaking stolen credentials as the leading entry point.

Mandiant’s M-Trends 2026 separately reported exploits as the leading initial infection vector for the sixth consecutive year, at 32% of intrusions. It also found the median interval between initial access and hand-off to a second threat group fell from more than eight hours in 2022 to 22 seconds in 2025.

These measure different stages. The 22-second figure measures hand-off after access, not time to exploit a newly disclosed vulnerability. Together, the findings show slow remediation alongside rapid attacker activity once access is established.

Exploitation’s rise does not mean social engineering has eased. As our first article explained, attackers have moved beyond email.

Severity scores do not determine business priority

An organization may have thousands of high or critical findings. They do not create comparable risk. Consider this illustrative comparison:
 

Risk factor   Internal application   Internet-facing remote access appliance
Technical severity  Very high   Moderate
Reachable from the internet No    Yes
Known active exploitation    No    Yes
Access required to exploit    Significant existing internal access   None
Illustrative business priority  Scheduled remediation  Immediate risk response


The Common Vulnerability Scoring System, or CVSS, describes technical severity. Prioritization also needs business context: internet exposure, known exploitation, authentication requirements, sensitive data, connected systems and the operations depending on the asset.

Patch management deploys updates. Vulnerability management determines which weaknesses matter most, then selects and verifies an appropriate response. A spreadsheet sorted by severity alone gives leadership an incomplete picture.

Start with a current asset inventory. Forgotten test servers, departmental cloud accounts and vendor-installed remote access tools can escape normal processes. Leadership should ask whether the inventory is maintained continuously or rebuilt annually for an audit. Unknown assets cannot be assessed or prioritized reliably and can be a significant risk.

Known exploitation and internet exposure change the urgency

CISA’s Known Exploited Vulnerabilities catalog identifies weaknesses with evidence of real-world exploitation. It is a practical input to prioritization, distinct from the much larger population of vulnerabilities attackers could theoretically exploit.

The 26% remediation figure is uncomfortable because these are validated attack opportunities. The executive question is why a known exploited weakness remains exposed and what reduces the risk in the meantime.

Internet-facing VPN appliances, firewalls, web applications, file transfer systems, cloud management interfaces and remote access tools deserve particular attention. Attackers can reach them without first gaining an internal foothold.

Faster action does not always mean immediate patching. Restricting access, disabling an exposed service, changing configuration or adding network controls may reduce risk while a patch is tested and deployed. Confirm the response works rather than assuming an added control resolves the exposure.

Federal guidance reinforces risk-based remediation

In June 2026, CISA issued Binding Operational Directive 26-04, replacing earlier directives with a model built around public exposure, known exploitation, exploit automation and technical impact.

Its tiered approach sets different remediation expectations for different risks and pairs urgent remediation with forensic triage where required. Patching closes a weakness; investigation helps determine whether attackers already used it.

FedRAMP’s implementation notice identifies December 7, 2026, as the date agencies must begin evaluating and remediating under the directive’s timelines. Private organizations are not directly bound by the directive, although government contracts or other obligations may create related requirements.

The broader lesson is useful now: remediation targets should reflect exposure and threat activity, with a clear path for urgent decisions.

A delayed patch still requires a risk decision

Testing, vendor certification and production availability can justify a delay. NIST’s enterprise patch management guidance recognizes responses beyond patching, including compensating controls, risk acceptance, risk transfer and eliminating vulnerable technology.

If a critical system cannot be patched for 30 days, leadership should understand the exposure during those 30 days and the measures reducing it. Document an accountable owner, the rationale, interim controls, an expiration date and conditions requiring escalation.

Two situations need explicit planning:

  • Vendor-controlled systems. SaaS platforms, managed infrastructure and embedded systems may leave remediation in someone else’s hands. Establish the vendor’s responsibilities, escalation path and available protections before an incident.
  • End-of-life systems. Routine security updates stop when support ends. Isolation may reduce exposure, but replacement or extended support needs funding and a schedule. Repeated exceptions are not a sustainable replacement plan.

Temporary exceptions can quietly become permanent. Six months later, the original justification may no longer apply, the approver may have changed roles, or the weakness may be actively exploited. Review exceptions against current conditions and retire them when the reason for deferral disappears.

Four questions for your leadership team

  1. Do we prioritize known exploited vulnerabilities and internet-facing systems, rather than relying on severity scores alone?
  2. Which critical vulnerabilities sit outside our remediation targets, and what reduces the risk while they remain unresolved?
  3. Do unsupported systems have a funded replacement or support plan?
  4. Are exceptions formally approved, periodically reviewed and eventually retired?


The full 16-question set for all four topics in this series will be available at the end of October.

Measure the risk reduced

A decline from 20,000 vulnerabilities to 10,000 sounds like progress. If the remainder includes five actively exploited weaknesses on internet-facing systems, the most consequential exposure may persist.

Leadership needs evidence the right risks are being reduced. Ask about unresolved known exploited exposures, critical systems beyond their targets and overdue exceptions alongside total findings. A smaller backlog is useful only when it represents a safer business.

When the next maintenance window is three weeks away, the decision is how much risk the organization will carry until then, who accepts it and what action can reduce it today.

If a vulnerability cannot be addressed in time, the next question is whether the organization can recover from what follows. Next in this series: Beyond Backups.

The RubinBrown Cyber Security Services and Technology Consulting teams help organizations identify risks, strengthen defenses, and build lasting cybersecurity resilience through proactive strategy, education, and technical expertise.  Learn more about RubinBrown Cyber Security Services.


 

Published: 10/07/2026

Readers should not act upon information presented without individual professional consultation.

Any federal tax advice contained in this communication (including any attachments): (i) is intended for your use only; (ii) is based on the accuracy and completeness of the facts you have provided us; and (iii) may not be relied upon to avoid penalties.

 

Contact Us:

Talk to Our Experts

Audrey Katcher, CPA, CISA, CITP, CGMA Partner audrey.katcher@rubinbrown.com 314-290-3420
Robert Rudloff, CISSP, CISA, QSA, CMMC RPA Partner rob.rudloff@rubinbrown.com 303-952-1220

Be Your Best for Others at RubinBrown

At RubinBrown, our firm fosters a culture built upon five vision points, and are guided by our philosophy of Being Our Best for Others. Discover how you can be your best at RubinBrown today by visiting our Careers & Culture Overview for available opportunities and more.

Discover Our Culture

Join Our Mailing List

RubinBrown periodically sends breaking regulatory updates, technical summaries, industry-specific information and event (in-person and virtual) invitations through electronic newsletters.

Sign Up for Our Communications

Certified Public Accountants & Business Consultants

Ranked a Top 50 Accounting Firm by Inside Public Accounting

1-800-678-3134
  • Services
  • Industries
  • Insights & Events
  • Careers & Culture
  • Contact
  • RubinBrown Advisors
  • RubinBrown Corporate Finance
  • RubinBrown Executive Recruiting
  • Firm News
  • Disclaimers
  • Privacy Policy
  • Client Payment
© 2026 RubinBrown LLP