Patch Fast, Trust Less: What Patch Management Reveals in Due Diligence
Cyber Friday Insights A patch gap is easy to describe as a technical problem. In an acquisition, it is more useful to treat it as operating evidence. This week’s Cyber Friday examples made the point. CISA warned that attackers were actively exploiting on-premises SharePoint Server vulnerabilities to achieve remote code execution. Microsoft’s July Patch Tuesday shipped fixes for hundreds of vulnerabilities, including zero-days already being exploited. CISA also added actively exploited WordPress Core vulnerabilities to its Known Exploited Vulnerabilities catalog. The lesson is not that every target must patch instantly. The lesson is that a buyer should be able to see how the target decides what gets patched, how quickly, by whom, and with what proof.