Your Patch Window Is Now Your Attack Window
Exploits now hit in hours while the median fix still takes 43 days. A CISO's read for founders who can't out-patch the internet.
The gap between a security flaw becoming public and attackers exploiting it at scale has compressed from months to hours. The median time to fix one is now 43 days. Both figures come from the 2026 Verizon Data Breach Investigations Report (DBIR) and the reporting on it. Put them next to each other and you have the whole problem in a line: your patch window is your attack window. For as long as a fix sits in the queue, an internet-facing system with a known hole stays open to anyone who goes looking.
For years, the classic first move was a stolen key - a phished password, a credential pulled from an infostealer log. It still works. But the report, built on forensic data from more than 22,000 real breaches, shows attackers reaching more and more for the easier way in: not the key, the window someone left unlatched. An unpatched, internet-facing system, hit at scale before anyone boards it up.
If you run security for a small company, the useful conclusion comes fast. You cannot win this race. A ten-person team will never patch faster than the internet can scan it. So stop trying to win on speed and win on surface area instead: give the internet less to aim at, then triage the handful of exposed systems that actually matter.
Patching faster is not a strategy for a small team
Defenders are losing ground on exactly the flaws attackers are proven to use. Of the vulnerabilities on CISA’s Known Exploited Vulnerabilities catalog - the ones with confirmed real-world attacks - only about a quarter now get fully fixed, down from more than a third a year ago. A full week after a flaw is known to be under active attack, 60 to 70% of organizations still have not closed it, and spending alone does not seem to change that much.
The cause is arithmetic. Nobody is being lazy. The number of known-exploited flaws an average organization has to chase keeps climbing, so even a team patching at a steady rate falls further behind. Now shrink that team to the size of a startup. You have less patching capacity, more systems you stood up fast and never hardened, and a growing share of your infrastructure - the SaaS tools and managed services holding your data - that you cannot patch at all, because someone else runs it. Which is the real point: your job is choosing what you expose and who can reach it, not pretending you can patch everything yourself. “Patch faster” assumes a race you have the staff to run. You don’t.
Where to spend the hours instead
You cannot out-patch the internet, but you can give it less to aim at. The founders I talk to almost always over-index on buying a tool and under-index on what is actually reachable from the open internet right now. Here is the order that works for a team without a security hire:
Shrink what faces the internet. Every public service is a window on the street. Take offline, or put behind single sign-on, anything strangers do not need to reach. Fewer windows beats faster boarding.
Patch KEV-first, internet-facing-first. Work the short list where three things overlap: reachable from the internet, listed on the CISA Known Exploited Vulnerabilities catalog, and attached to a system that matters. That intersection is where real breaches start, and it is short enough to act on.
Keep the credential basics, because attackers chain both. Vulnerabilities may be the fastest way in now, but look across the whole arc of a breach - not just the first step - and stolen credentials still turn up more than any other single technique. The unpatched window is how they get in; the stolen key is how they move once inside. So keep phishing-resistant MFA, no standing admin access, and access killed the day someone leaves. Cheap, and it breaks the second move.
Buy managed, not platforms. You need endpoints that auto-patch and a host that patches its own servers. You do not need an exposure-management suite built for a security operations center you do not have. For the rest of the short list, start with the first controls worth putting in place.
Bring the one-page version to a fundraise or customer review
A security questionnaire now expects a real answer about how you handle vulnerabilities. “We patch when we get to it” reads to a diligence team or an enterprise buyer as unmanaged risk, and it surfaces right when you are trying to close a round or a first big customer.
The backlog you defer is not free. It compounds into the kind of security debt that costs ten times more to fix at Series B than it would this quarter. A one-page account of what faces the internet and how you triage it is worth more in that room than any tool you could buy.
None of this says passwords stopped mattering. It says a startup’s scarce security hours belong on attack surface and triage, not on a patch-speed sprint no one is winning. Pick three of your own services that face the open internet this week, and check each against CISA’s Known Exploited list. That is a better use of an afternoon than a platform demo.
Sources
Verizon 2026 Data Breach Investigations Report - Verizon, May 2026
Vulnerability Exploitation Overtakes Credential Theft as Top Breach Vector - SecurityWeek, May 2026
Verizon 2026 DBIR findings - Help Net Security, May 2026
Key findings from the Verizon DBIR 2026 - Tenable, May 2026
What the Verizon DBIR tells us about breaches in 2026 - Push Security, May 2026


