Microsoft is warning that the window for patching vulnerabilities is rapidly shrinking, as attackers move from disclosure to exploitation faster than enterprises can safely deploy fixes, and is urging organizations to adopt network-level controls to limit exposure during that gap.
In a blog post, Igor Sakhnov, corporate vice president and general manager for Azure Networking at Microsoft, said the traditional model of vulnerability management “increasingly reflects a world that no longer exists,” as modern attack timelines compress while enterprise processes remain unchanged.
“When a vulnerability was disclosed, organizations had time to understand the issue, assess affected systems, test patches, coordinate change windows, and deploy fixes before widespread exploitation occurred,” Sakhnov wrote. “Today that timeline is rapidly shrinking.”
Attack timelines compress as patching remains complex
Microsoft said vulnerabilities are now “more visible, more widely distributed, and more rapidly weaponized than ever before,” while enterprise environments have grown more complex, spanning hybrid and multicloud infrastructure.
“Modern attack campaigns operate at internet scale. Security research, public disclosures, proof-of-concept exploits, and threat intelligence circulate globally within hours,” Sakhnov wrote, adding that “Meanwhile, the operational realities of enterprise environments have not changed.”
This mismatch creates what Microsoft described as “one of the most dangerous periods in modern cybersecurity: the window between awareness and remediation.”
Shriya Mehrotra, director analyst at Gartner, said this compression is already visible in certain environments.
“Yes, particularly for high-risk, internet-facing systems. Attackers can exploit critical vulnerabilities within hours, while many enterprises still require weeks to test and deploy patches,” Mehrotra said, adding that the dynamic “does not apply equally to every vulnerability or every organization.”
Microsoft said advances in AI and the rapid spread of exploit information are further accelerating the time from disclosure to attack.
“As these capabilities become more accessible, the timeline between disclosure and exploitation continues to compress,” Sakhnov wrote, describing the result as a “structural imbalance” between attackers and defenders.
Network-level controls as a control plane
To address this gap, Microsoft is proposing a shift toward what it describes as a new security “control plane” centered on the network.
“When a workload cannot immediately defend itself, another layer must help provide protection,” Sakhnov wrote, adding that organizations are “increasingly looking to the network” as that layer.
Unlike endpoint-based controls, network-level protections “operate around workloads rather than inside them,” allowing defenses to be applied without waiting for patches to be deployed or applications to be modified.
“The objective is not to avoid patching,” Sakhnov wrote. “The objective is to create a meaningful layer of defense during the period when patching has not yet been completed.”
Mehrotra said the approach reflects a continuation of existing security practices rather than a complete departure.
“Security teams should prioritize vulnerabilities that are actively exploited and externally exposed, then use segmentation, traffic controls, WAF/IPS policies, or temporary isolation until patches can be deployed safely,” she said. “While the control plane advances automation, it is largely an evolution of established segmentation, compensating-control, and Zero Trust approaches.”
Practical challenges in real-world environments
While the model emphasizes faster, network-level containment, analysts said implementation remains uneven across enterprises.
Mehrotra noted that the approach is more feasible in mature environments.
“This model is practical for mature cloud environments, but many enterprises still face challenges implementing it consistently,” she said. “Effective real-time containment depends on accurate asset inventories, exposure mapping, traffic visibility, application context, and centralized policy enforcement.”
Bhupendra Chopra, co-founder and CRO at Kanerika, said many organizations still lack the foundational visibility needed to make such a model work.
“Realistically, not yet,” Chopra said. “Most large enterprises don’t have one accurate view of their own systems. Asset records sit in different tools that don’t talk to each other, and ownership of a given application changes hands without anyone updating who’s responsible for it.”
Limits of containment before patching
Microsoft said the goal of the control plane is to reduce exposure during the period between disclosure and remediation, not to replace patching.
“In this new reality, organizations cannot rely on patching alone,” Sakhnov wrote, adding that security strategies must combine “strong patch management practices with compensating controls capable of responding at machine speed.”
Analysts said relying on containment introduces its own risks if not managed carefully.
“Network-based containment can miss unmanaged, encrypted, identity-based, or alternative attack paths,” Mehrotra said, adding that overly broad controls can disrupt legitimate business services. “Organizations should view containment as a way to reduce immediate exposure and buy time, not as a replacement for permanent patching.”
Chopra said there is also a risk that temporary controls become permanent.
“A network rule blocks a risky path, nobody circles back to patch the underlying system, and eighteen months later that workaround is its own liability nobody remembers approving,” he said.
The shift outlined by Microsoft places new emphasis on managing risk during the period when vulnerabilities are known but not yet fixed. “The future of cybersecurity will depend on an organization’s ability to reduce risk during the time between disclosure and remediation,” Sakhnov wrote.
No Responses