Why Patching Is Still the Most Important Control

Despite decades of emphasis, unpatched vulnerabilities remain the most commonly exploited attack vector in external network compromises. The Verizon 2025 Data Breach Investigations Report found a significant rise in breaches caused by exploited vulnerabilities, particularly in perimeter devices and VPNs. CISA's Known Exploited Vulnerabilities (KEV) catalog lists over 1,000 vulnerabilities that are actively being used in real-world attacks, the vast majority of which have been patched by vendors and are only exploitable because organizations have not applied the patch.

The Patch Priority Problem

Large organizations receive thousands of vulnerability notifications monthly. Not all of them require immediate action, treating every vulnerability as critical creates patch fatigue and prevents teams from focusing on what matters. An effective patch management process prioritizes based on actual exploitation risk, not just CVSS score:

  • Critical priority (24-48 hours): Internet-facing systems with vulnerabilities on CISA's KEV catalog, or with public exploits available
  • High priority (7 days): Internet-facing systems with high-severity vulnerabilities, internal systems with critical vulnerabilities
  • Standard priority (30 days): Internal systems with high-severity vulnerabilities, lower-risk systems
  • Routine (90 days): Medium and low severity vulnerabilities in lower-risk environments

The Patch vs. Compensating Control Decision

Not every system can be patched immediately. Legacy systems, critical production environments, and systems requiring extensive testing before patching may not be patchable on the emergency timeline a critical vulnerability demands. In these cases, compensating controls, network isolation, additional monitoring, disabling specific features, can reduce risk while a patching path is developed. The key is that these decisions are documented and reviewed, not simply ignored.

Validate Your Patching with Penetration Testing

A penetration test validates whether your patching program is actually working. External penetration tests consistently find unpatched internet-facing systems, systems that IT believed were patched but were not, systems that were missed by asset management tools, or systems where patches were applied but did not successfully address the vulnerability. These findings are not criticisms; they are the intelligence needed to close real gaps before attackers find them.

When You Cannot Patch

Some systems genuinely cannot be patched on schedule: legacy applications, medical or industrial devices, or systems tied to a vendor's release cycle. The answer is compensating controls, not acceptance. Isolate the system with segmentation, restrict who and what can reach it, add monitoring, and disable the vulnerable feature where possible. Penetration testing then confirms whether those controls meaningfully reduce the exposure the missing patch would otherwise leave open.

Frequently Asked Questions

What are patch management best practices?

Maintain an accurate asset inventory, prioritize patches by real exploitability and exposure rather than raw severity, patch internet-facing and critical systems fastest, use compensating controls when you cannot patch immediately, and validate patch state with testing. Unpatched systems remain a leading breach cause.

How should I prioritize which patches to apply first?

Prioritize vulnerabilities that are internet-facing, actively exploited, and on critical systems. A known-exploited flaw on an exposed server matters far more than a high-severity issue on an isolated internal host, so context should drive the order.

What if I cannot patch a system immediately?

When patching must wait, apply compensating controls such as restricting access, segmenting the system, adding monitoring, or disabling the vulnerable feature. Penetration testing helps confirm those controls actually reduce the exposure.

Validate your patching is actually working.

Grid32's external network tests find the unpatched systems that got missed, before attackers scan for them. Our findings give you a prioritized remediation list that goes beyond what scanners see.

Get a Quote →