When patching everything stops being a strategy

CISA’s new directive prioritises vulnerabilities by exploitation and impact, and drops the CVSS mandate altogether. Cyber Essentials hardened the opposite rule. For large enterprises forced to hold CE+ for government work, the gap is becoming impossible to ignore.

6 Min Read

In June, CISA did something the UK’s Cyber Essentials scheme still won’t: It stopped treating every high-severity vulnerability as equally urgent.

Binding Operational Directive 26-04, issued on 10 June 2026, tells US federal agencies to prioritise vulnerabilities by risk rather than by severity score, and in the process it retired the requirement to use CVSS at all. Cyber Essentials hardened its dependence on that same score. For a small business, that contrast is academic. For an enterprise running a large, complicated estate, it is the difference between a programme that describes security and one that describes paperwork.

Two regulators, two philosophies

CISA’s directive replaces a single severity number with four questions an insurance underwriter would recognise. Is the affected asset publicly exposed? Can the flaw be exploited through automation? Does it hand an attacker meaningful control of the system? Is anyone already exploiting it in the wild? A vulnerability that meets all four must be fixed within three days, with forensic triage to check whether it has already been used. Everything below that threshold gets judgment instead of a uniform clock. In consolidating two older directives, BOD 26-04 also removed the obligation to prioritise by CVSS, a quiet but significant concession that severity scores and exploitation risk are not the same thing.

Cyber Essentials, run by the IASME Consortium on behalf of the NCSC, went the other way. Its current specification requires that any in-scope vulnerability with a CVSS v3 base score of 7.0 or above, or one a vendor labels critical or high, or one where the vendor discloses no severity at all, be patched within 14 calendar days of a fix being released. Under the latest question set, missing that window is an automatic fail, with no compensating-control route around it. Commentary from assessors suggests the NCSC has even considered shortening the window to seven days. Large enterprises rarely choose this model. Many inherit it, because CE+ is now a gate for UK government tenders.

A rule built for 10 laptops, applied to 10,000 servers

Cyber Essentials was designed as a baseline for the broad population of UK businesses, most of them small. For a 10-seat firm running mostly auto-updating software, blanket 14-day patching is a gift. It is simple, blunt, and effective. It removes the need to make hard prioritisation calls, because at that scale there are very few to make.

Hand the same rule to an enterprise carrying tens of thousands of assets across acquired estates, legacy systems, operational technology, and clouds it half-remembers buying, and the arithmetic changes entirely. The same instruction now governs a far larger and more heterogeneous surface, much of which cannot be patched on a 14-day cadence without breaking the business it supports. The rule did not get harder to follow because anyone was careless. It got harder because a control built for one population is being applied, through procurement, to another.

The score the rule depends on is disappearing

There is a deeper problem with anchoring a mandate to a CVSS threshold. The threshold itself is becoming unreliable. The public CVE programme published 48,185 vulnerabilities in 2025, up 20.6% on the previous year and up 263% since 2020, roughly 130 a day, according to CVE programme data and NIST. The volume alone strains any model that treats all high-severity findings as equally pressing.

What makes it worse for a CVSS-keyed rule is that the score itself is no longer guaranteed to exist when the clock starts. In April 2026, NIST moved the National Vulnerability Database to a triage model, fully enriching only vulnerabilities that are known to be exploited, used in federal systems, or designated critical, and leaving the rest unscored. In 2025, only about a quarter of new CVEs received full analysis. A rule that begins “CVSS v3 base score of 7.0 or above” increasingly points at a number that, for a growing share of vulnerabilities, is published late or not at all. The trigger is eroding beneath the standard’s feet.

AI already moved the deadline

Every 14-day SLA rests on an assumption. It assumes a meaningful gap between when a vulnerability is disclosed and when it can be weaponised, historically 30 days or more. That assumption is failing. As Resilience’s analysis of Project Glasswing documented, the mean time from disclosure to confirmed exploitation fell below one day in 2026.

The same analysis surfaced the detail that should worry anyone running a CVSS-floor rule. When the tooling was tested under Project Glasswing, its defining capability was not just finding individual flaws but chaining low-severity primitives into working exploits, precisely the bugs a “7.0 and above” threshold is designed to ignore. A severity floor filters out exactly the material that modern tooling now assembles into critical compromises. The pressure is visible on the human side too. The Linux kernel security mailing list went from two to three reports a week to five to 10 a day, a volume its maintainers called almost unmanageable.

A 14-day clock is the wrong instrument when exploitation can precede the patch, and a severity floor is the wrong filter when the danger arrives in pieces that each score below it.

Descoping the estate optimises for the assessor

Faced with a rule that a large estate cannot satisfy on its terms, the rational response many organisations reach for is to shrink the assessment scope until what remains can pass. It works on paper. The certificate is issued, the tender requirement is met, and the dashboard turns green.

Resilience has a name for the instinct behind that move. In its risk-first CISO framing, the compliance operator runs a programme optimised for the assessor rather than the adversary. Descoping is that pattern in miniature, a control implemented to satisfy a requirement rather than to address an exposure. It does not lower the organisation’s real risk. It relocates that risk to a place the certificate cannot see.

Attackers do not respect a scope boundary. A descoped, unpatched, internet-facing asset is exactly the kind of forgotten system that turns a routine incident into a material loss.

What a risk-first approach actually prioritises

The alternative is not patching less. It is prioritisation by exploitation likelihood and business consequence rather than by a severity label assigned in isolation. That is the logic CISA has now adopted, and the logic mature security leaders were already running.

Three signals do most of the work. Whether a flaw is being exploited, captured in CISA’s Known Exploited Vulnerabilities catalogue. How likely it is to be, estimated by the Exploit Prediction Scoring System maintained by FIRST, which scores the large majority of CVEs well below a 10% probability of exploitation in the next 30 days. And whether the vulnerable asset is actually reachable in the environment, which determines whether a theoretical flaw is a practical exposure. Together these replace a binary severity gate with a defensible ranking.

Resilience adds the dimension CVSS never had, the financial consequence of the exposure. As one of our own CISOs puts it, CVSS scores don’t have a dollar sign. The controls that most limit loss severity, such as tested disaster recovery, validated backups, and practised incident response, rarely top a vulnerability scan, yet they move the cost of an incident more than another quarter of aggressive patching. Sitting at the intersection of security operations, underwriting, and claims, Resilience sees consistently which behaviours separate a contained incident from a catastrophic one, and they are seldom the ones a severity score elevates.

What to do before the standard catches up

The standards will converge on risk, because the alternative is becoming arithmetically impossible for large estates. CISA has already made the move. The pressure on the NCSC will grow as CVE volume climbs and AI-assisted discovery keeps compressing the timelines that blanket patching was built around.

Until that happens, large enterprises should not reshape the estate to flatter the certificate. Run the blanket rule where it genuinely fits, on the small, uniform, internet-facing surfaces Cyber Essentials was designed for, and govern the rest by exploitation evidence, reachability, and financial exposure. Hold CE+ for the tenders that require it without mistaking the badge for the security posture.

And when the board or the assessor asks how many vulnerabilities you closed this quarter, answer with the better question. How many of them moved the number?

Nothing here should be taken as legal, financial, or security advice for your specific situation — see the full disclaimer at cyberresilience.com/disclaimer.

When patching everything stops being a strategy

6 Min Read