
Risk-based patching is the future. AI made it table stakes
CISA’s new Binding Operational Directive (BOD) 26-04 marks one of the most important changes to federal vulnerability management in years. Rather than requiring agencies to patch every critical vulnerability on the same timetable, the directive prioritizes remediation based on risk, with patch deadlines ranging from three days for the highest-risk vulnerabilities to deferral for those posing minimal risk. It’s a welcome evolution, but it brings us to the starting blocks, not the finish line.
Security teams have long known that severity alone doesn’t determine risk. A CVSS score says little about whether a vulnerability is reachable from the Internet, is being actively exploited, can be autom...