IEC 62443 already provides the vocabulary for acting on those answers: zones and conduits to define exposure, plus compensating countermeasures where patching is not feasible on the required timeline — segmentation, allow-listing, virtual patching at the network boundary, removal of unnecessary reachability and tightened monitoring for exploitation attempts against the specific flaw (TR 62443-2-3 covers patch management in industrial environments in detail). Official doctrine now points the same way: in late July, an ASD-led coalition with CISA, the FBI, NCSC-UK and CCCS published CI Fortify, joint guidance on isolating vital OT systems and running them disconnected for extended periods — containment promoted from workaround to designed-in capability. The honest, auditable position for a large share of the OT estate is therefore not “patched within SLA.” It is: we do not patch this asset on this timeline; we contain it — here is the compensating control, here is the monitoring and here is the retirement date. Under NIS2, where management carries personal accountability for risk measures, a documented containment decision defends considerably better than a silently missed patch SLA.
Plan the surge like an outage
Hathaway urges governments to map patch volumes against national exposure and to prepare surge capacity. Operators should run the same exercise one level down, and four moves matter most. First, interrogate your OEMs and system integrators now: how do they ingest AI-discovered findings, what patch volume and cadence do they expect for your installed base, and what are their qualification timelines? The joint CSA, SANS and OWASP guidance published in April on building “Mythos-ready” security programs is a usable checklist for exactly that conversation. Europe adds leverage here: on September 11, the Cyber Resilience Act’s first hard obligation takes effect — manufacturers must report actively exploited vulnerabilities through ENISA’s new Single Reporting Platform, with an early warning within 24 hours and a fuller notification within 72, and the duty covers products already on the market, not only new ones. That means earlier upstream signals: ask your vendors, in writing, how those advisories and the accompanying SBOM data will reach you as an operator.
Second, pre-negotiate emergency windows with operations before you need them, including written criteria for when a vulnerability justifies unplanned downtime — a decision framework like any other safety call, agreed in daylight rather than improvised at 2 a.m. Third, exercise the scenario that is actually coming: not one incident, but a week in which several high-severity advisories land across different vendors simultaneously. Hathaway recommends such exercises at national level; they are even more useful at plant level, where the constraint is a finite pool of automation engineers. Fourth, give every unpatchable asset a retirement date and a budget line. Compensating controls are a bridge, not a destination, and an inventory that quietly accumulates permanent exceptions is technical debt wearing a compliance costume.


