There are so many nice ways to start the day. A croissant, a cappuccino, birds outside the window. Instead, I keep waking up to news of some fresh disaster with a CVE number. Wonderful. Because apparently our day wasn’t complicated enough without a brand-new exploit dropping by to wreck the schedule.
And now for the “good news”: the clock isn’t ticking in days anymore. It’s ticking in hours.
The Clock Isn’t Ticking in Days Anymore
We used to talk about the “patch gap” like it was a manageable problem — give an organization a few weeks, maybe a month, and IT would get around to it eventually. That luxury is dead, and it’s not coming back.
The ConnectWise ScreenConnect vulnerability that surfaced in early 2024 was being actively exploited within days of disclosure — and ScreenConnect is exactly the kind of remote-support tool your own IT provider might be using to manage your systems. Which is a genuinely unsettling thought if you let it sit for a second.
If you’re running Microsoft 365 or Google Workspace instead of your own on-prem infrastructure, don’t get comfortable — the clock still applies, just not to the platform itself. Microsoft and Google patch the core software on their own timeline, whether you notice or not; what’s exposed is everything bolted onto it — the third-party integrations, connected apps, and plugins your organization has added. WordPress plugin vulnerabilities tell the same story on a smaller scale: A huge share of nonprofit websites run on WordPress, and one unpatched plugin (usually the kind nobody remembers installing) is often all it takes to deface a donation page or plant something worse. We had one of these, and it was the devil to fix! Not to mention the staff time and downtime for our website.
Five Days Is a Fantasy for Most of Us
Here’s the part that makes me think I should switch from cappuccino to something stronger. Should I take up smoking again? That five-day number assumes someone is actually reading the advisory the day it drops. Most nonprofits and startups don’t have a security operations center (SOC) on standby for this. IT is one person, or one contracted provider, juggling payroll systems, program support, and whatever’s on fire that week. And now, apparently, also expected to have a sixth sense for zero-days on top of everything else.
Five days doesn’t feel tight when you’re a Fortune 500 with a SOC. But if you’re not, it feels like a joke when patching is competing with a dozen other priorities and nobody’s actual job description says “watch CISA all day.”
Patching Isn’t Even the Real Fight in the Cloud
Big enterprises spin up virtual patches and lock down configs the moment a vulnerability makes news. Great for them. Most mission-driven organizations and lean startups can’t build that exact muscle in-house. But here’s the thing: if you’re running Microsoft 365 or Google Workspace instead of your own on-prem infrastructure, patching was never really your job to begin with. Microsoft and Google handle that automatically, on their own timeline, for their own infrastructure, whether you notice or not.
What’s actually on you is everything an attacker doesn’t need a vulnerability for. Because most real-world breaches in either platform aren’t some clever exploit: They’re a stolen or guessed password walking in the front door because nobody bothered to lock it. MFA enforcement, blocking legacy authentication, and locking down conditional access or context-aware access rules exist for exactly that reason: to close the doors that don’t require the vendor to patch anything.
There’s likely an alert waiting for you right now, probably, sitting unread. Patching isn’t the fight for most cloud-office tenants. Configuration and vigilance are, and most breaches happen because nobody wanted to deal with either.
Don’t Forget What’s in Everyone’s Pocket
And let’s not forget the fleet of laptops, desktops, and phones sitting in people’s bags and back pockets — those are patchable too, and just as exploitable. Windows and macOS updates, browser patches, the OS update nagging everyone ignores on their iPhone or Android — each one is a live door if it sits unpatched long enough. The five-day clock doesn’t care whether the vulnerable thing is a server or someone’s laptop that hasn’t restarted in three weeks because they didn’t want to lose their open tabs.
The fix here isn’t heroic — it’s automatic updates pushed to every device by default, not left up to whether someone remembers to click “update now”. Because they won’t. Critical fixes should go out immediately; routine ones can sit in a short test group first, just in case something breaks. Either way, updates need a forced reboot after a grace period, because a patch that installs but never restarts isn’t protecting anyone — it’s just decoration.
Additionally, someone needs visibility into which devices are actually caught up and which are quietly falling behind, rather than just trusting that the push worked and hoping for the best.
Your Best Defense Is a List
What actually moves the needle at this scale starts with knowing what you’re running: An unglamorous asset inventory is still the single highest-leverage thing a small IT shop can maintain. Unsexy, yes. But it beats finding out about your own infrastructure from a breach notice. Which is a genuinely humiliating way to learn your own network.
From there, the smart move is usually to let someone else watch the wire: a managed provider whose actual job is tracking CVEs, monitoring alerts, and pushing patches buys you reaction speed you’ll never build internally. Not because your team is incapable, but because nobody on staff can stay awake for this at 2am. (Nor should they have to.) Whatever you can’t lock down immediately, segment it. Limit what it can talk to, so a compromised account stays a contained headache instead of a red carpet to everything else.
Stop Pretending You Can Do This Alone
This isn’t really about technology. It’s about whether you’re willing to admit what a lean team can actually own versus who needs a partner. And unfortunately, most people would rather guess wrong than ask for help. Giant corporations have SOCs and budgets built for exactly this. Most of us don’t, and pretending otherwise is how you end up in next month’s breach notification email.
That’s exactly why the five-day window matters more here, not less.
For over forty-three years, CGNET has provided state-of-the-art IT services to organizations of all sizes, across the globe. We’ve done it all, from IT and cybersecurity assessments to cloud services management to generative AI user training. Want to learn more about who we are and how we might be able to help you? If so, check out our website or send us a message!




0 Comments