{"id":8917,"date":"2026-07-29T09:00:00","date_gmt":"2026-07-29T09:00:00","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=8917"},"modified":"2026-07-29T09:00:00","modified_gmt":"2026-07-29T09:00:00","slug":"risk-based-patching-is-the-future-ai-made-it-table-stakes","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=8917","title":{"rendered":"Risk-based patching is the future. AI made it table stakes"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">CISA\u2019s new <a href=\"https:\/\/www.cisa.gov\/news-events\/directives\/bod-26-04-prioritizing-security-updates-based-risk\">Binding Operational Directive (BOD) 26-04<\/a> marks one of the most important changes to federal vulnerability management in years. Rather than requiring agencies to patch every critical vulnerability on the same timetable, the directive prioritizes remediation based on risk, with patch deadlines ranging from three days for the highest-risk vulnerabilities to deferral for those posing minimal risk. It\u2019s a welcome evolution, but it brings us to the starting blocks, not the finish line.<\/p>\n<p class=\"wp-block-paragraph\">Security teams have long known that severity alone doesn\u2019t determine risk. A CVSS score says little about whether a vulnerability is reachable from the Internet, is being actively exploited, can be automated or provides the attacker with control of the asset. BOD 26-04 acknowledges the contextual nature of risk by directing organizations to focus first on the exposures most likely to be exploited.<\/p>\n<p class=\"wp-block-paragraph\">However, AI is compressing every stage of the attack lifecycle, changing the threat landscape faster than vulnerability management practices can adapt. <a href=\"https:\/\/www.crowdstrike.com\/en-us\/blog\/crowdstrike-2026-global-threat-report-findings\/\">CrowdStrike reports <\/a>that the average eCrime breakout (Initial Lateral Movement)\u00a0 time has fallen to just 29 minutes, with the fastest observed breakout taking <strong><em>27 seconds<\/em><\/strong>. Once attackers establish a foothold, <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/m-trends-2026\">Mandiant found<\/a> they hand off access between operators in a median of 22 seconds.<\/p>\n<p class=\"wp-block-paragraph\">At the same time, AI itself is <a href=\"https:\/\/genai.owasp.org\/initiatives\/agentic-security-initiative\/\">growing as an attack surface<\/a>. Organizations are rapidly deploying copilots, browser agents, autonomous workflows and other AI-powered systems, introducing prompts, plugins, connectors and integrations that require protection.<\/p>\n<p class=\"wp-block-paragraph\">Against this backdrop, the directive\u2019s three-day remediation window for the riskiest exposures looks less like an aggressive target and more like a luxury.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Today\u2019s attackers don\u2019t simply exploit CVEs. They combine vulnerabilities with stolen identities, cloud misconfigurations, exposed APIs, SaaS weaknesses and increasingly AI systems to construct attack paths into critical assets. BOD 26-04 moves us forward, but AI requires defenders not simply to accelerate existing processes, but to rethink them.<\/p>\n<h2 class=\"wp-block-heading\">AI has changed the tempo and economics of cyberattacks<\/h2>\n<p class=\"wp-block-paragraph\">One of AI\u2019s biggest advantages for attackers is its ability to automate work that previously required teams of human operators. Reconnaissance, vulnerability research, exploit generation, phishing, credential harvesting and even portions of lateral movement can now be accelerated or, in some cases, largely orchestrated by AI.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.anthropic.com\/news\/disrupting-AI-espionage\">Recent research<\/a> has demonstrated autonomous agents carrying out much of the operational work in sophisticated cyber campaigns while humans supervise the broader objectives. As a result, campaigns become easier and less expensive to scale, more targets can be pursued simultaneously and attackers can test far more paths into an environment before defenders realize they\u2019re being probed.<\/p>\n<p class=\"wp-block-paragraph\">For years, vulnerability management assumed that organizations had weeks, or even months, to identify, prioritize and remediate security issues. That assumption no longer reflects reality. Attackers routinely move from initial access to lateral movement in less than an hour, and vulnerabilities are increasingly exploited shortly after disclosure, and in some cases <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/2025-zero-day-review\">are weaponized<\/a> before defenders have even begun evaluating them.<\/p>\n<p class=\"wp-block-paragraph\">This is why CISA\u2019s move toward risk-based remediation matters. Prioritizing vulnerabilities based on exploitability and operational risk gives defenders a much better chance of addressing the issues most likely to be used against them. But vulnerabilities represent only one piece of today\u2019s exposure landscape.<\/p>\n<h2 class=\"wp-block-heading\">Modern attacks follow paths, not findings<\/h2>\n<p class=\"wp-block-paragraph\">Most security organizations still divide responsibilities across specialized teams. Vulnerability management focuses on CVEs. Identity teams concentrate on authentication and privilege. Cloud security addresses configuration. Application security reviews code.<\/p>\n<p class=\"wp-block-paragraph\">Attackers don\u2019t encounter those same boundaries. Their objective is to reach valuable assets using whatever route is available. A campaign may begin with an exposed vulnerability, stolen credentials, excessive cloud permissions, a misconfigured SaaS application or a compromised AI agent. More often than not, several of those conditions are combined. For example, the 2026 Verizon Breach report found that while 31% of initial exploitation last year was a vulnerability, 39% of attack chains involved identity issues. In every notable breach, attackers chain together various types of exposures to advance inside networks.<\/p>\n<p class=\"wp-block-paragraph\">An attacker who compromises a low-privilege account may discover an over-permissioned identity, pivot through a cloud workload, exploit a vulnerable application and eventually gain access to sensitive business systems. None of those individual exposures may appear catastrophic when viewed independently. Together, they form a viable attack path.<\/p>\n<p class=\"wp-block-paragraph\">With breaches always a chain of various exposures, and vulnerabilities representing only part of the story of how breaches actually occur, this is where vulnerability-centric security begins to break down. CrowdStrike also reported a 42% year-over-year increase in vulnerabilities exploited, <em>before<\/em> vendors even announced them. That means organizations that are nose-to-the-grindstone closing\u00a0\u00a0 hundreds of high-severity findings will get breached because they lack the context needed to close off the most practical route an attacker would take to their critical assets.<\/p>\n<p class=\"wp-block-paragraph\">Organizations should assume breach and plan for the possibility that an attacker will eventually gain an initial foothold. Security architecture should be as segmented as possible and limit how far an adversary, or a compromised AI agent, can move after that initial compromise. And security controls should be validated continuously rather than assumed effective because they were successfully deployed.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">These principles shift attention away from individual findings and toward the conditions that enable successful attacks.<\/p>\n<h2 class=\"wp-block-heading\">How defenders can adapt: Continuous assessment and validation<\/h2>\n<p class=\"wp-block-paragraph\">One practical way to make this transition is to get serious about implementing a <a href=\"https:\/\/ctem.org\/docs\/what-is-continuous-threat-exposure-management\">Continuous Threat Exposure Management (CTEM) program<\/a>, which establishes an ongoing process for understanding and reducing exposure.<\/p>\n<p class=\"wp-block-paragraph\">It starts with something many organizations still struggle to maintain: a current understanding of the environment. That means continuously mapping assets, identities, cloud infrastructure, SaaS applications, AI systems and the relationships between them. From there, security teams can identify exposures, prioritize them according to exploitability and business impact, validate whether they are actually reachable, and drive remediation across operational teams.<\/p>\n<p class=\"wp-block-paragraph\">This continuous cycle restores what Mandiant calls the <a href=\"https:\/\/services.google.com\/fh\/files\/misc\/the-defenders-advantage-two-solutions-guide.pdf\">Defender\u2019s Advantage.<\/a> Attackers must first discover an unfamiliar environment before they can exploit it. Defenders already have that knowledge \u2013 or should. The challenge is keeping it current as cloud services, identities, AI applications and business systems evolve daily.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Embed validation into the process<\/h2>\n<p class=\"wp-block-paragraph\">Security teams also need to verify that the exposures they\u2019ve identified can actually be exploited and that remediation efforts have eliminated meaningful risk.<\/p>\n<p class=\"wp-block-paragraph\">That\u2019s where adversary-aware exposure validation becomes an essential part of the process. Technologies such as breach-and-attack simulation, automated penetration testing and attack path analysis allow organizations to continuously test their environments using techniques that resemble real adversaries.<\/p>\n<p class=\"wp-block-paragraph\">Instead of asking whether a vulnerability exists, exposure validation answers more practical questions: Can an attacker reach it? Can they exploit it? Can they pivot from it to something the business actually cares about? Just as important, validation confirms whether remediation efforts have truly closed the door rather than simply reducing the number of findings on a dashboard.<\/p>\n<h2 class=\"wp-block-heading\">Prioritize the business, not the dashboard<\/h2>\n<p class=\"wp-block-paragraph\">Validation becomes even more valuable when combined with business context. A medium-severity weakness affecting a revenue-generating application, regulated data or critical operational system may represent greater organizational risk than multiple critical vulnerabilities affecting isolated development environments.<\/p>\n<p class=\"wp-block-paragraph\">Prioritizing validated exposures according to business impact gives security leaders a remediation strategy they can explain to executives in operational terms rather than technical ones. More importantly, it aligns defensive efforts with the attack paths most likely to affect the organization.<\/p>\n<p class=\"wp-block-paragraph\">BOD 26-04 is an important step forward. But AI has already made risk-based patching table stakes. In the AI era, the organizations that succeed won\u2019t necessarily be those that patch the fastest. They\u2019ll be the ones that understand their exposure better than the attackers trying to exploit it.<\/p>\n<p class=\"wp-block-paragraph\"><strong>This article is published as part of the Foundry Expert Contributor Network.<\/strong><br \/><a href=\"https:\/\/www.cio.com\/expert-contributor-network\/\"><strong>Want to join?<\/strong><\/a><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>CISA\u2019s new Binding Operational Directive (BOD) 26-04 marks one of the most important changes to federal vulnerability management in years. Rather than requiring agencies to patch every critical vulnerability on the same timetable, the directive prioritizes remediation based on risk, with patch deadlines ranging from three days for the highest-risk vulnerabilities to deferral for those [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":8918,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-8917","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8917"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8917"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8917\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/8918"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8917"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8917"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8917"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}