The patch race is arithmetically lost. Fifteen minutes of response is what's left to manage.
48,185 vulnerabilities disclosed, 7,500 patched, exploitation median at one day. The only variable left is automated containment time.
Michael Cembalest published the numbers that end the patching debate, and then concluded that we should patch faster.
His July issue of Eye on the Market, Patchmageddon, is the most useful cyber document a bank has put out this year, and it argues against itself. In 2025, 48,185 vulnerabilities were disclosed and roughly 7,500 were patched. The median time between disclosure and first exploitation was about a year in 2021, one day in 2026, and the Zero Day Clock he cites projects one minute in 2027. Close to 80% of exploitations now land on or before the day of disclosure. In 2026, no disclosed vulnerability was left unexploited after fifty days.
You cannot patch faster than one minute. Nobody can. That isn't a maturity problem, it's arithmetic.
The better argument is sitting in his own first paragraph. He opens on tornado warnings. The US had none until the late 1940s, and once the Weather Bureau started issuing them, tornado deaths per million fell by 90%. Average lead time, then and now, is about fifteen minutes.
Nobody reinforced a house in fifteen minutes. They went to the basement.
That distinction is the whole thing, and the industry keeps walking past it. A warning doesn't buy you engineering. It buys one action, executed fast, by someone who already knows what to do and is allowed to do it. The 90% came from behavior inside the window, not from better construction outside it. Translated for a security team in 2026, the disclosure is the siren, the patch is the rebuild, and the only variable still under your control is what happens in between.
The standard objection is that the same models finding these flaws will fix them. Partly true, and worth taking seriously. Anthropic's Project Glasswing surfaced more than 23,000 potential open source vulnerabilities through May 2026, 3,900 of them high or critical, and Claude Security has since been used to patch over 2,100. Real work.
Now look at the other side of the handoff. Of 530 high and critical open source issues reported to maintainers, 75 were patched. Tuskira measured discovery outpacing patching by 16.5 times, with 90% maintainer acknowledgement. Acknowledgement isn't deployment.
Remediation ends in a human decision that somebody postpones. Over 80% of security professionals in Cembalest's citation have skipped a patch to avoid disrupting the business, and 80% of CIOs and CISOs have found out that a patch they believed was fully deployed had quietly missed part of the estate. In roughly 60% of breaches, the patch already existed.
Generation scales. Deployment doesn't. Feeding a faster generator into an unchanged deployment pipeline widens the gap it was supposed to close.
That leaves time to contain as the only number a security leader can still move, and it exposes something most organizations would rather not say out loud. No human team contains in fifteen minutes. Not one that pages an on-call analyst, opens a ticket, waits for a change window, and asks a platform owner at two in the morning for permission to isolate a host. Dragos found that 30% of its 2025 incident response cases began with a person noticing that something seemed wrong rather than with a detection, and that in most of those cases the telemetry needed to answer whether a cyber event had occurred was never recorded at all.
Fifteen minutes isn't a human interval. It's a machine interval with a human accountable for it.
Which means the response has to be an agent. Playbooks trained on real threat behavior, wired to real telemetry, with pre-authorized scope to contain, isolate, revoke, block and roll back without waking anyone. Acting, not advising.
I argued the other side of this a week ago in Everyone is shopping for agentic AI use cases, that the thing nobody governs is standing authority to act on production systems. That still holds, and it isn't a contradiction. The conclusion was never to withhold the authority. It's to grant it on purpose, scoped tightly, logged completely, with a kill switch and a named owner. Withholding is also a decision, and at one-minute exploitation it's the expensive one.
The blocker here isn't technical. It's that the conversation with the board is still denominated in the wrong unit.
Arielle Waldman's piece in Dark Reading last Friday comes at this from the opposite side. Boards aren't indifferent, they're mistranslated. Chris Novak of Quadrum Advisors puts it plainly, that directors govern in exposure, resilience, tradeoffs and accountability while security teams present threats and controls, and that both should settle on a small number of decision-useful measures covering recovery readiness and incident preparedness. He's describing the metric without naming it. Edna Conway, formerly chief security and risk officer at Microsoft, adds the part that makes it work, that you live and die by transparency.
Transparency is exactly what the current unit prevents. Checkmarx surveyed 2,350 CISOs, AppSec managers and developers across 14 countries in March. 95% feel pressure to suppress or delay compliance-related security findings when a deadline is at stake. 75% of organizations knowingly ship vulnerable code. And 93% had a recent breach traced to their own applications while 73% describe their security posture as advanced or highly mature.
That last pair is the governance failure in one line. A board told "we're mature" has been handed a number that cannot fail.
Patch coverage is that kind of number. It rises every quarter, it survives every breach, and it stopped correlating with whether you get hurt. Two numbers still correlate. Median time to contain, measured from first signal, and the share of containments that no human touched. The second one is the one that matters, because it's the only one that can survive a one-minute exploit window. If it's zero, you don't have a response capability, you have a documentation capability.
I made a version of this point in Your board still buys cybersecurity like insurance, where the payout restarts nothing. Patch coverage reports nothing about survival either.
The other side has already made the move. The AI-run ransomware operation I looked at last week diagnosed its own failed login, deleted the broken account and reinserted a correct password hash in 31 seconds, with no operator awake. That's the benchmark now, not a competitor's dashboard.
And the patch race has itself become an attack surface. Sekoia's TDR team documented a campaign it calls ChocoPoC, where threat actors trojanized Python dependencies inside proof-of-concept exploit code, aimed squarely at the pressure researchers are under to test new vulnerabilities fast. The urgency to patch got turned into the intrusion vector. Speed without authority is how you get hurt twice.
None of this makes patching optional. Run current versions, keep a live inventory, drop dependencies with no identifiable steward, and read CISA's exploited catalog like a work queue rather than a newsletter. All necessary. None of it is a strategy any more, because the tornado doesn't care how much you reinforced.
Fifteen minutes cut tornado deaths by 90% for one reason. When the siren went off, people were allowed to move.
Most security teams still aren't.


