AI & ML

Rethinking Cybersecurity: The Imperative of Risk-Based Patching in an AI-Driven Landscape

CISA’s new directive prioritizes vulnerability remediation based on risk, but with AI accelerating attacks, organizations must adapt their security strategies.

Jul 29, 2026 3 min read
Sign in to save

CISA’s Binding Operational Directive (BOD) 26-04 introduces a significant shift in how federal agencies are expected to handle vulnerabilities. Instead of a standardized requirement to patch all critical vulnerabilities, the directive advocates for a risk-centric approach, allowing organizations to set patching deadlines ranging from three days for the most severe vulnerabilities to potentially deferring patches for those considered minimally risky. While this is a positive step towards a more effective remediation strategy, it merely marks the beginning of necessary transformations in security practices.

Security teams have long understood that a vulnerability's severity isn't the only factor to consider when assessing risk. A vulnerability’s Common Vulnerability Scoring System (CVSS) score doesn’t provide a complete picture regarding accessibility from external threats or active exploitation. BOD 26-04 smartly recognizes the need for a nuanced view of risk, pressing organizations to concentrate on the vulnerabilities that are most likely to be targeted.

However, the rapid evolution of cyber attacks fueled by AI presents challenges that outpace traditional vulnerability management approaches. According to CrowdStrike, the average time for eCrime to breach initial defenses has dropped to a mere 29 minutes, with some cases recorded at lightning speed—just 27 seconds. Once attackers gain entry, organizations like Mandiant have observed a swift transfer of access between attackers within a median time of 22 seconds.

Compounding the risk, AI systems themselves are becoming significant targets. With organizations rolling out a range of AI applications—from copilots and browser agents to fully autonomous workflows—this expansion increases the attack surface and highlights the urgent need for robust protective measures.

Given these dynamics, the directive's three-day window for addressing high-risk vulnerabilities starts to look less like a stringent benchmark and more like an impractical luxury. Today's adversaries exploit a mix of vulnerabilities, stolen identities, misconfigured cloud environments, exposed APIs, and SaaS shortcomings to create multifaceted attack vectors targeting vital assets. While BOD 26-04 marks progress, AI necessitates a broader reevaluation of defensive strategies.

AI's Impact on the Cyber Threat Landscape

The rise of AI has fundamentally altered the tactics employed by cybercriminals, allowing them to automate processes that once required extensive human involvement. Tasks such as reconnaissance, phishing, vulnerability research, and even lateral movement are now achievable in significantly less time through automation.

Research shows autonomous agents can manage a substantial portion of operational responsibilities within advanced cyber campaigns, with human operators overseeing strategic goals. Consequently, campaigns are easier and cheaper to scale, enabling attackers to target multiple systems simultaneously and explore various infiltration paths before defenders recognize an incursion.

For years, vulnerability management has operated under the assumption that organizations had sufficient time—often weeks or months—to confront and remediate security concerns. Recent trends illustrate that this is increasingly outdated thinking. Attackers can quickly escalate from first access to lateral movement in under an hour, with new vulnerabilities frequently being exploited almost immediately upon disclosure.

This underscores the importance of CISA's shift towards risk-based patching. By prioritizing vulnerabilities based on their potential for exploitation and operational risk, defenses can be more effectively aligned with the threats they face. Yet, vulnerabilities are only one aspect of today's complex exposure landscape.

Rethinking Attack Strategies: Going Beyond Vulnerabilities

Security teams often operate in silos, with separate focus areas for vulnerability management, identity, cloud, and application security. Yet attackers do not confine their efforts to predefined categories; their end goal is straightforward: to exploit any available weakness to access sensitive systems.

Modern attack campaigns often initiate from a combination of factors, including exposed vulnerabilities, compromised identities, and misconfigured applications. The 2026 Verizon Breach report notes that while 31% of initial attacks exploited vulnerabilities, 39% involved identity-related issues. This blending of vulnerabilities creates complex attack paths that can lead to significant breaches.

For instance, gaining control of a low-privilege account might enable an attacker to traverse to an over-permissioned identity, pivoting through cloud resources and exploiting vulnerabilities in applications to ultimately access sensitive data. Viewed in isolation, each vulnerability might not seem critical, but collectively, these exposures create a strong path for an attack.

With breaches arising from various types of vulnerabilities, a purely vulnerability-centric security model is inadequate. CrowdStrike’s findings highlight that 42% of vulnerabilities are exploited even before vendor announcements. Organizations overly focused on meeting vulnerability reduction targets will likely find themselves vulnerable when attackers take unexplored paths to penetrate their networks.

Organizations must adopt the mindset that a breach is not a question of "if," but "when," necessitating a proactive and segmented security architecture to limit the lateral movement of attackers once an entry point has been compromised. Continuous assessment and real-time validation of security measures are no longer optional.

Adapting to Modern Threats: The Role of Continuous Assessment

One effective strategy for adaptation is implementing a Continuous Threat Exposure Management (CTEM) program, establishing an ongoing framework for exposure management. This should begin with maintaining a current understanding of the organization’s environment, including assets, identities, cloud systems, and AI applications.

From this foundational knowledge, security teams can better identify and assess exposures, prioritize them based on risk, and validate their exploitability, creating a clear path for remediation across operational lines.

These ongoing processes contribute to what Mandiant refers to as the Defender's Advantage. Attackers must first understand an environment before they can exploit it, which is a distinct advantage for defenders who can leverage their in-depth knowledge of their system architectures and functions.

Validation: Integrating Defense Mechanisms

Another essential element is embedding validation into the remediation process. Security teams must confirm that identified vulnerabilities can indeed be exploited and that remediation efforts effectively mitigate risks.

Adversary-aware exposure validation is a critical component of this process, employing techniques like attack path analysis, automated penetration testing, and breach-and-attack simulations. Rather than simply determining if a vulnerability exists, this approach addresses whether attackers could realistically exploit these vulnerabilities and access high-value business systems.

Aligning Defense with Business Impact

Organizations should prioritize vulnerabilities based on their potential business impact rather than solely on severity ratings. A medium-severity vulnerability affecting a critical operational system could pose a higher risk than multiple high-severity vulnerabilities confined to isolated environments.

This business-aligned perspective is crucial for security leaders when strategizing remediation efforts and helps in communicating risks to executives in a manner that resonates beyond technical jargon. It aligns cybersecurity efforts with the threats most likely to affect the organization’s core operations.

While BOD 26-04 signifies positive progress in cybersecurity governance, the impact of AI has made risk-based patching a necessity rather than a choice. Moving forward, organizations that excel will not solely be those that patch vulnerabilities quickly; they will be the ones that maintain a deep understanding of their own exposures, ultimately staying one step ahead of the attackers.

This article is published as part of the Foundry Expert Contributor Network.
Want to join?

Source: David Martinez · www.csoonline.com

Comments

Sign in to join the discussion.