26 August 2026 | By James Thomas
Four challenges every organisation must solve to adopt AI safely
Discover four key challenges affecting AI adoption and how organisations can build confidence in their approach.
Read moreImagine hearing a weather warning about a storm that is already hitting your building. That is effectively what many organisations now face when a software vulnerability is disclosed.
For years, patch management has been one of the most effective ways to reduce cyber risk. When a vulnerability was discovered, IT teams typically had time to assess the threat, test fixes and deploy updates before attackers could take advantage. That process was not perfect, but it provided a valuable window to act.
Today, that window is shrinking at an alarming rate.
According to Zero Day Clock, the median time between a vulnerability being publicly disclosed and exploited in the wild has collapsed from 771 days in 2018 to just four hours in 2024. In 2025, most exploited vulnerabilities were weaponised before they were even publicly disclosed.
For business leaders and IT decision-makers, this changes the conversation. The challenge is no longer just how quickly systems can be patched. It is whether your organisation can remain resilient when threats move faster than traditional patch management processes were designed to handle.
One of the biggest drivers behind this shift is AI. Research published in 2024 showed that a GPT-4 based agent could successfully exploit 87% of a set of real-world vulnerabilities when provided with vulnerability information. Other models and open-source security scanners achieved no successful exploits in the same benchmark.
At the same time, defensive AI is improving too. Programmes from Google, Microsoft, OpenAI and Anthropic are helping researchers identify and fix vulnerabilities before attackers can exploit them. However, there remains a fundamental challenge that favours attackers.
Attackers can test and refine exploits much faster than defenders can validate their security. An attacker typically receives immediate feedback. The exploit either works or it does not. Defenders face a far more complex challenge, needing to determine whether systems are secure, alerts are genuine and vulnerabilities have been fully mitigated. This imbalance is now allowing attackers to adapt at a much greater pace that traditional security processes were never designed to handle.
If your vulnerability management programme revolves around a 14-day patching target and quarterly risk reviews, there is a good chance it was designed for a threat landscape that no longer exists.
Three important implications stand out:
1. Patch management remains critical, but it cannot work alone
A 14-day patching target may have felt proactive a few years ago. Against exploit windows measured in hours, it can still leave organisations exposed for extended periods. Patch management remains one of the most important cyber security controls available, but it cannot be the only line of defence you rely on.
2. Assume compromise before detection
More vulnerabilities are now being weaponised before public disclosure. This means “no known exploit” is becoming a far less useful measure of risk than it once was. Organisations must work on the assumption that a vulnerability could already be under active exploitation before they even know it exists.
3. Resilience matters more than patching speed
The key question is shifting from “how quickly can we patch?” to “how effectively can we detect, contain and recover if something is exploited?”. That makes cyber resilience a business issue as much as a technical one, and increasingly a topic that requires board-level attention.
Many of the wider industry discussions focus on changes software vendors should make. While those conversations are important, there are practical steps organisations can take today to strengthen their own security posture.
1. Prioritise the systems that matter most
Very few organisations can patch every asset within hours of a critical vulnerability being disclosed. What is achievable is prioritising the systems that would have the greatest business impact if compromised.
This typically includes internet-facing applications, VPN infrastructure, identity platforms and other business-critical services. Automated patch deployment, emergency change processes and vulnerability prioritisation based on active exploitation can help reduce risk where it matters most.
2. Reduce unnecessary exposure
Every externally exposed service creates another opportunity for attackers.
Review legacy remote access solutions, minimise publicly exposed management interfaces and regularly evaluate whether systems genuinely need to be internet facing. The smaller your attack surface, the fewer opportunities attackers have to gain a foothold.
3. Take a practical approach to Zero Trust
When vulnerabilities can be exploited before organisations are even aware of them, trust becomes a risk.
A Zero Trust approach helps limit the impact of a compromise by continuously validating access requests, enforcing least-privilege permissions and segmenting environments. If one system is compromised, those controls help prevent attackers from moving freely across the wider estate.
4. Strengthen your detection and response capabilities
The reality is that some attacks will happen before patches can be deployed.
This makes rapid detection and containment increasingly important. Well-tested incident response plans, behavioural monitoring, security analytics and AI-assisted defence capabilities can all help organisations identify and respond to threats before they develop into serious business disruptions.
The Zero Day Clock is not predicting a future problem. It is documenting a challenge that organisations are already facing today.
The organisations that will perform best over the next few years are unlikely to be those that simply patch the fastest. They will be the businesses that understand their critical assets, reduce unnecessary exposure, strengthen detection capabilities and prepare for the possibility that some attacks will arrive before a fix is available.
Patch management remains essential, but modern cyber resilience requires more than patching alone. Success increasingly depends on understanding where your risks lie, limiting the impact of a breach and responding quickly when something goes wrong.
As exploit windows continue to shrink, organisations need confidence that their patch management processes, security controls and cyber resilience strategies can keep pace.
Our Cyber Security Health Check helps uncover areas of risk and highlight practical improvements that can strengthen your overall security posture.
Book a complimentary Cyber Security Health Check with our experts and gain a clearer understanding of your patch management readiness.
Start with a complimentary Cyber Security Health Check today