Home / Blog / Data Privacy
July 24, 2026 by James Farr
Whether your organization’s patching program is documented or performed ad hoc, you still need resources to fix those vulnerabilities. The IT environment may include applications, cloud systems, endpoints, remote access, and servers, and IT teams are often left with long lists of findings and a familiar question: What should we fix first?
According to Verizon’s 2026 Data Breach Investigations Report[i], the exploitation of vulnerabilities is now the most common initial access vector for breaches, rising to 31% of the reporting dataset. The same report found that only 26% of critical vulnerabilities in the CISA Known Exploited Vulnerabilities (CISA KEV) catalog[ii] were fully remediated by organizations in 2025. The IBM X-Force report[iii] identified a 44% increase in attacks that began with exploitation of public-facing applications and found that vulnerability exploitation accounted for 40% of incidents it observed in 2025.
With limited organizational resources, the key question is: What risk are you reducing?
Some standards, such as the Payment Card Industry Data Security Standard (PCI DSS), require critical and high-risk vulnerabilities to be patched within 30 days of release. However, this approach may not work for every organization.
Consider where the vulnerabilities are found. Is the critical vulnerability on the internal test server as important as the high severity vulnerability found on a public-facing production server? Attackers consider system availability, exposure, known exploitable vulnerabilities, and weaknesses that can be replicated across other systems.
A Common Vulnerability Scoring System (CVSS) score tells only part of the story. Understanding how a vulnerable asset supports the business provides the context needed to prioritize remediation efforts. This approach aligns with CISA BOD 26-04[iv]’s guidance, which emphasizes prioritizing security updates based on exposure, exploitability, and impact.
When determining vulnerability remediation priority, consider the following:
This approach shifts the focus from counting vulnerabilities to understanding which vulnerabilities present the greatest risk to the organization.
Organizations should strive to remediate all identified vulnerabilities, but not all vulnerabilities require the same level of urgency. Effective vulnerability management considers severity, exposure, exploitability, and business impact to ensure that remediation efforts are focused where they reduce risk the most.
[i] https://www.verizon.com/business/resources/T158/reports/2026-dbir-data-breach-investigations-report.pdf
[ii] https://www.cisa.gov/known-exploited-vulnerabilities-catalog
[iii] https://newsroom.ibm.com/2026-02-25-ibm-2026-x-force-threat-index-ai-driven-attacks-are-escalating-as-basic-security-gaps-leave-enterprises-exposed
[iv] https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk