“[Enterprises should focus on] identifying vulnerabilities with credible and functional PoCs, verified exploitation, or sustained attention from ransomware groups, threat actors, and botnets,” says Caitlin Condon, vice president of security research at VulnCheck. “Timely exploit intelligence helps organizations identify the bugs that require immediate attention, while allowing lower-risk issues to proceed through appropriate testing and change control.”
Other independent experts are more sympathetic to Microsoft’s argument that AI has made vulnerability discovery and exploit development faster than ever and, as a result, the risks of delaying patches are far greater.
“Organizations sometimes delay patches to protect the uptime of critical systems, and many updates still require a restart,” says Danny Jenkins, CEO and co-founder at endpoint protection technology vendor ThreatLocker. “Some teams also stay one update cycle behind because they are concerned that a new patch could introduce bugs or break an overlooked dependency. Unfortunately, delaying patches to preserve uptime is becoming much harder to justify.”
Jenkins adds: “Organizations should not leave critical systems exposed while waiting for the next maintenance window. Patches should still be tested, but that process needs to move quickly, with the highest priority given to vulnerabilities that are actively exploited or exposed to the internet. A controlled interruption is usually far less costly than a successful attack exploiting a known vulnerability.”


