October is Cyber Security Awareness Month. This is the second article in a series throughout October that will call attention to the importance of cyber security awareness.
Attackers and remediation teams operate on different schedules. Leaders need to know which weaknesses threaten critical operations now, what reduces exposure while a fix is pending, and who can authorize faster action.
The objective is risk-based vulnerability management: direct limited resources toward the exposures most likely to cause consequential harm. Treating every patch as an emergency is impractical. Treating every patch as routine maintenance can be dangerous.
The numbers show two different clocks
The 2026 Verizon Data Breach Investigations Report found:
Mandiant’s M-Trends 2026 separately reported exploits as the leading initial infection vector for the sixth consecutive year, at 32% of intrusions. It also found the median interval between initial access and hand-off to a second threat group fell from more than eight hours in 2022 to 22 seconds in 2025.
These measure different stages. The 22-second figure measures hand-off after access, not time to exploit a newly disclosed vulnerability. Together, the findings show slow remediation alongside rapid attacker activity once access is established.
Exploitation’s rise does not mean social engineering has eased. As our first article explained, attackers have moved beyond email.
An organization may have thousands of high or critical findings. They do not create comparable risk. Consider this illustrative comparison:
| Risk factor | Internal application | Internet-facing remote access appliance |
| Technical severity | Very high | Moderate |
| Reachable from the internet | No | Yes |
| Known active exploitation | No | Yes |
| Access required to exploit | Significant existing internal access | None |
| Illustrative business priority | Scheduled remediation | Immediate risk response |
The Common Vulnerability Scoring System, or CVSS, describes technical severity. Prioritization also needs business context: internet exposure, known exploitation, authentication requirements, sensitive data, connected systems and the operations depending on the asset.
Patch management deploys updates. Vulnerability management determines which weaknesses matter most, then selects and verifies an appropriate response. A spreadsheet sorted by severity alone gives leadership an incomplete picture.
Start with a current asset inventory. Forgotten test servers, departmental cloud accounts and vendor-installed remote access tools can escape normal processes. Leadership should ask whether the inventory is maintained continuously or rebuilt annually for an audit. Unknown assets cannot be assessed or prioritized reliably and can be a significant risk.
CISA’s Known Exploited Vulnerabilities catalog identifies weaknesses with evidence of real-world exploitation. It is a practical input to prioritization, distinct from the much larger population of vulnerabilities attackers could theoretically exploit.
The 26% remediation figure is uncomfortable because these are validated attack opportunities. The executive question is why a known exploited weakness remains exposed and what reduces the risk in the meantime.
Internet-facing VPN appliances, firewalls, web applications, file transfer systems, cloud management interfaces and remote access tools deserve particular attention. Attackers can reach them without first gaining an internal foothold.
Faster action does not always mean immediate patching. Restricting access, disabling an exposed service, changing configuration or adding network controls may reduce risk while a patch is tested and deployed. Confirm the response works rather than assuming an added control resolves the exposure.
In June 2026, CISA issued Binding Operational Directive 26-04, replacing earlier directives with a model built around public exposure, known exploitation, exploit automation and technical impact.
Its tiered approach sets different remediation expectations for different risks and pairs urgent remediation with forensic triage where required. Patching closes a weakness; investigation helps determine whether attackers already used it.
FedRAMP’s implementation notice identifies December 7, 2026, as the date agencies must begin evaluating and remediating under the directive’s timelines. Private organizations are not directly bound by the directive, although government contracts or other obligations may create related requirements.
The broader lesson is useful now: remediation targets should reflect exposure and threat activity, with a clear path for urgent decisions.
Testing, vendor certification and production availability can justify a delay. NIST’s enterprise patch management guidance recognizes responses beyond patching, including compensating controls, risk acceptance, risk transfer and eliminating vulnerable technology.
If a critical system cannot be patched for 30 days, leadership should understand the exposure during those 30 days and the measures reducing it. Document an accountable owner, the rationale, interim controls, an expiration date and conditions requiring escalation.
Two situations need explicit planning:
Temporary exceptions can quietly become permanent. Six months later, the original justification may no longer apply, the approver may have changed roles, or the weakness may be actively exploited. Review exceptions against current conditions and retire them when the reason for deferral disappears.
The full 16-question set for all four topics in this series will be available at the end of October.
A decline from 20,000 vulnerabilities to 10,000 sounds like progress. If the remainder includes five actively exploited weaknesses on internet-facing systems, the most consequential exposure may persist.
Leadership needs evidence the right risks are being reduced. Ask about unresolved known exploited exposures, critical systems beyond their targets and overdue exceptions alongside total findings. A smaller backlog is useful only when it represents a safer business.
When the next maintenance window is three weeks away, the decision is how much risk the organization will carry until then, who accepts it and what action can reduce it today.
If a vulnerability cannot be addressed in time, the next question is whether the organization can recover from what follows. Next in this series: Beyond Backups.
The RubinBrown Cyber Security Services and Technology Consulting teams help organizations identify risks, strengthen defenses, and build lasting cybersecurity resilience through proactive strategy, education, and technical expertise. Learn more about RubinBrown Cyber Security Services.
Published: 10/07/2026
Readers should not act upon information presented without individual professional consultation.
Any federal tax advice contained in this communication (including any attachments): (i) is intended for your use only; (ii) is based on the accuracy and completeness of the facts you have provided us; and (iii) may not be relied upon to avoid penalties.