Patch windows collapse, network defense urged
Microsoft says the time to patch vulnerabilities is shrinking, urging network-level controls to bridge the gap.
Microsoft is warning that the window for patching vulnerabilities is shrinking as attackers move from disclosure to exploitation faster than enterprises can safely deploy fixes. In a new blog post, the company urges organizations to adopt network-level controls to limit exposure during that gap.
The shrinking timeline
In the blog post, Igor Sakhnov, corporate vice president and general manager for Azure Networking at Microsoft, said the traditional model of vulnerability management no longer fits the current threat landscape. He wrote that when a vulnerability was disclosed, organizations had time to understand the issue, assess affected systems, test patches, coordinate change windows, and deploy fixes before widespread exploitation occurred. Today, he said, that timeline is rapidly shrinking.
Microsoft said vulnerabilities are now more visible, more widely distributed, and more rapidly weaponized than ever before, while enterprise environments have grown more complex, spanning hybrid and multicloud infrastructure. Modern attack campaigns operate at internet scale, with security research, public disclosures, proof-of-concept exploits, and threat intelligence circulating globally within hours. Meanwhile, the operational realities of enterprise environments have not changed.
This mismatch creates what Microsoft described as one of the most dangerous periods in modern cybersecurity: the window between awareness and remediation.
Real-world impact
Shriya Mehrotra, director analyst at Gartner, said the compression is already visible in some environments. She noted that attackers can exploit critical vulnerabilities within hours, while many enterprises still require weeks to test and deploy patches. However, she added that the dynamic does not apply equally to every vulnerability or every organization.
AI accelerates exploitation
Microsoft said advances in AI and the rapid spread of exploit information are further accelerating the time from disclosure to attack. Sakhnov described the result as a structural imbalance between attackers and defenders.
Network as a control plane
To address this gap, Microsoft is proposing a shift toward a new security control plane centered on the network. Sakhnov wrote that when a workload cannot immediately defend itself, another layer must help provide protection, and organizations are increasingly looking to the network as that layer.
Unlike endpoint-based controls, network-level protections operate around workloads rather than inside them, allowing defenses to be applied without waiting for patches to be deployed or applications to be modified. The objective is not to avoid patching, but to create a meaningful layer of defense during the period when patching has not yet been completed.
Analysts weigh in
Mehrotra said the approach reflects a continuation of existing security practices rather than a complete departure. She said security teams should prioritize vulnerabilities that are actively exploited and externally exposed, then use segmentation, traffic controls, WAF/IPS policies, or temporary isolation until patches can be deployed safely. While the control plane advances automation, it is largely an evolution of established segmentation, compensating-control, and Zero Trust approaches.
Bhupendra Chopra, co-founder and CRO at Kanerika, said many organizations still lack the foundational visibility needed to make such a model work. He noted that most large enterprises don't have one accurate view of their own systems, with asset records sitting in different tools that don't talk to each other and ownership of applications changing hands without updates.
Containment limitations
Microsoft said the goal of the control plane is to reduce exposure during the period between disclosure and remediation, not to replace patching. Sakhnov wrote that organizations cannot rely on patching alone, and security strategies must combine strong patch management practices with compensating controls capable of responding at machine speed.
Analysts said relying on containment introduces its own risks if not managed carefully. Mehrotra noted that network-based containment can miss unmanaged, encrypted, identity-based, or alternative attack paths, and overly broad controls can disrupt legitimate business services. She said organizations should view containment as a way to reduce immediate exposure and buy time, not as a replacement for permanent patching.
Chopra also pointed to the risk that temporary controls become permanent, with network rules blocking risky paths but nobody circling back to patch the underlying system, leaving a workaround that becomes its own liability.
Why it matters
The shift outlined by Microsoft places new emphasis on managing risk during the period when vulnerabilities are known but not yet fixed. Sakhnov wrote that the future of cybersecurity will depend on an organization's ability to reduce risk during the time between disclosure and remediation. This suggests that organizations may need to invest in network-level defenses and automation to keep pace with attackers, even as they continue to patch.
Sources
- CSO Online Original source
Continue Reading
Cyber Insurance Claims Costlier Despite Drop in Frequency
Chubb's 2026 Cyber Claims Report finds fewer claims but soaring average costs, driven by litigation and business interruption.
Who answers for rogue AI agents?
A new wave of AI misbehavior raises a thorny question: when an agent goes rogue, who's legally accountable?
LACMA Breach Exposed Sensitive Data
LACMA's 2025 breach exposed social security and medical data; notifications sent.