logo

The truth about KEV: CISA’s vuln deadlines good influence on private-sector patching

ID: 71882ffa-4950-5267-af06-377f14c7b87e

STIX ID: report--71882ffa-4950-5267-af06-377f14c7b87e

Feed Name: The Register (Security)

Threat Score
45/100

Date Published: 2024-05-07

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Bitsight research described in this article shows organizations remediate vulnerabilities on CISA's KEV list much faster (average ~175 days) than non-KEV flaws (~621 days), with KEVs linked to ransomware patched the fastest; federal civilian executive branch agencies patch more quickly than private firms but still sometimes miss CISA deadlines (example: an Adobe ColdFusion compromise). The piece recommends organizations set internal patching SLAs based on severity (e.g., seven days for critical/KEVs up to 180 days for low severity) and establish emergency zero-day procedures with executive support.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.