Key Takeaways
- Cybercriminals can exploit a vulnerability in as little as 24 to 48 hours, while organisations take an average of 43 days to remediate it.
- The key is no longer to patch more vulnerabilities, but to prioritise those that pose the greatest risk to the business.
- Automation and risk-based vulnerability management help accelerate response and strengthen cybersecurity posture.
It is not always possible to patch vulnerabilities as quickly as hackers exploit them, but recent figures show just how much this gap has widened.
FortiGuard Labs estimates that the time between the disclosure of a critical vulnerability and its active exploitation has dropped sharply to between 24 and 48 hours. By contrast, Verizon’s 2026 Data Breach Investigations Report shows that organisations take a median of 43 days to complete vulnerability remediation.
As many leaders in the global financial sector know all too well, a tremendous amount of damage can occur in the days and weeks between the exploitation of a vulnerability and the successful deployment of a patch.
From the perspective of industry leaders, both figures are moving in the wrong direction. It used to be common for hackers to need a week to exploit a vulnerability. And the patching process also used to be faster: the current figure of 43 days is up from 32 days recorded twelve months earlier.
Hackers are getting faster.
Patching is getting slower.
Chasing hackers is not the answer
It may seem like the right answer is to keep chasing hackers by reactively identifying and patching as many vulnerabilities as possible.
But that is not necessarily the best option.
Instead, financial institutions worldwide should seriously consider prioritising proactive patch management. Rather than trying to patch as many vulnerabilities as possible, prioritisation means patching the right vulnerabilities. This includes models such as Risk-Based Vulnerability Management, which asks questions such as: Which vulnerabilities pose the greatest risk to the business? How critical are the affected assets? How likely are they to be exploited? What would the potential operational impact be if exploitation occurred?
These questions can help prioritise the response and enable IT and security teams to work more strategically. This is particularly important given the growing cyber pressure financial institutions face globally as they manage increasingly complex IT environments.
Measure the right metrics
According to a new report on the state of cybersecurity, 57% of security professionals consider software vulnerabilities a high or critical threat, while only 27% say they are very prepared. That 30-percentage-point gap widened by 11 points in just one year.
Before you can effectively prioritise patches, you need to measure the right metrics. The report reveals that only 51% of companies use a cybersecurity risk exposure score or another risk-based index. The rest rely on process metrics, such as mean time to remediate (47%) or the percentage of exposures remediated (41%): indicators of speed and coverage that say little about whether the risk posture has actually improved. One in three companies says they struggle to prioritise risk remediation in areas such as patch management.
Automation can help
With IT and security teams already under heavy workloads, an operational change can seem more like a complication than a help. Automation can alleviate some of that burden, but only if it is implemented properly. The report on the state of cybersecurity found that 92% of security professionals say automation reduces their teams’ mean time to respond. However, only 42% use AI for vulnerability response and remediation.
Automation has the potential to make better use of the information that is already available. It can enable faster decision-making and prioritisation based on the specific risks of each business. The trend toward risk-based vulnerability management, supported by automation, is already evident in many of the world’s leading financial institutions, and the rest of the industry should take note. Hackers are not becoming any less ambitious.