Approximately 31 percent of breaches originate from hackers exploiting known vulnerabilities, according to Verizon’s 19th annual Data Breach Investigations Report — a gap that faster patching alone could close for roughly one in three incidents.
Verizon DBIR and the persistent gap in patching
The 31 percent figure recurs throughout conversations about patch management because it ties a measurable share of breaches directly to known, often-patchable flaws. As Daniel Lawson, senior vice-president of global solutions at Verizon Business, put it, “…the foundational principles of security and strong risk management remain the most effective defense.” The implication: patching remains the remediation engine of modern cyber defense, and delays translate directly into increased exposure time and breach probability.
AI is compressing the window to exploit
Defenders now face a rapidly shrinking window between vulnerability disclosure and live exploitation. Six years ago, organizations were aiming for a 14-day service-level agreement; average release-to-exploit code availability at that time ran 14–28 days. Today, with more than 45,000 CVEs disclosed annually, Derek Illum reports that the median time-to-exploit “has now been reduced to five days.” The source further warns that this exploit window is estimated to shrink more by 2027 (pre‑Claude Mythos numbers).
AI plays a central role in that compression. According to the interview, AI enables malicious actors and advanced persistent threat (APT) groups to reverse-engineer each new security patch as it’s released, while LLMs and specialized cyber models can mine code, configurations, and public CVE data to identify exploitable conditions at scale. “AI exploit frameworks can rapidly generate, refine, and share working exploits,” Illum said, shrinking the gap between disclosure and active attacks and making traditional monthly patch cycles structurally too slow.
Operational realities inside government agencies and education institutions
The public sector faces several practical constraints that make rapid patching difficult. Illum cited legacy systems, fragmented toolsets, and ticket-driven workflows that produce manual handoffs and coverage gaps. Small teams in government and education are juggling multiple modernization priorities while complying with strict FedRAMP and NIST requirements, even as the threat environment accelerates.
Concrete measurements underline the problem: Ivanti’s discovery tool often finds that about 30 percent of assets are missing from Configuration Management Databases (CMDBs), and 73 percent of security leaders report incidents involving unknown or unmanaged devices. The report summarizes the operational strain bluntly: IT and cybersecurity staff at government agencies are essentially bailing water from an actively sinking ship.
Four pillars of a modern patch management approach
Illum lays out four concrete characteristics of a modern, effective patch program that depart from traditional, periodic processes.
- Unified system of record. Replace separate inventory, vulnerability, and patching tools with a single authoritative record that combines endpoint inventory, risk, patch state, and compliance posture in one unified motion.
- Continuous discovery and visibility. Continuously scan for managed devices, unmanaged devices, shadow IT, and cloud workloads and reconcile them into one view so endpoints do not fall out of patch scope.
- Risk-based prioritization using VRR. Move beyond CVSS-only prioritization. Use Vulnerability Risk Rating (VRR), which incorporates exploit activity, asset criticality, and real-time threat intelligence, to decide what to patch first.
- Always-on, autonomous enforcement. Shift from scheduled, manual campaigns to continuous, autonomous remediation that reduces exposure from weeks to hours. Key features include autonomous deployment to remediate missed or offline devices as soon as they reconnect, closed-loop verification, drift detection, and audit-ready proof — all “with a human in the loop.”
What this means for government agencies, IT and security teams, and threat actors
- Government agencies and education institutions: Reconcile CMDB gaps and move toward continuous discovery and enforcement while meeting FedRAMP/NIST mandates; periodic patch cycles are no longer adequate in an AI-accelerated landscape.
- IT and security teams: Expect to rely more on automation, closed-loop workflows, and unified systems of record to reduce manual ticketing, cover unmanaged or offline devices, and shorten exposure windows from weeks to hours.
- Threat actors and APT groups: Are increasingly empowered by AI to reverse-engineer patches, generate working exploits rapidly, and target the shortest windows between disclosure and deployment.
The practical takeaway is straightforward and stark: modern patch management must be continuous, risk‑aware, and automated to keep pace with an AI-accelerated threat environment. For practitioners seeking operational answers, Derek Illum will discuss these points on the Ivanti panel “Managing Risk Across a Growing Attack Surface” at the Ivanti Public Sector Summit, which promises a closer look at automating the full vulnerability lifecycle from discovery through remediation.




