← Insights

Cyber security

The 2026 patching gap: a risk-based guide for technology leaders

5 August 2026 · 7 min read · 3 public sources

Terminal screen during a network security exercise

Patching has become a board-level resilience issue. Verizon’s 2026 Data Breach Investigations Report identifies vulnerability exploitation as the leading initial access vector in its global dataset, accounting for 31% of breaches. The same report found that only 26% of vulnerabilities listed in CISA’s Known Exploited Vulnerabilities catalog were fully remediated by organizations in the dataset.

The local operational signal

The Uganda Communications Commission’s FY 2024/25 sector report recorded persistent web-server vulnerabilities and linked delayed remediation to limited IT resources, low awareness, and concerns about downtime. The finding applies to the communications sector, but the operating lesson is useful anywhere maintenance windows compete with service availability.

Build a patch queue around business risk

  • Maintain a complete inventory of internet-facing systems, operating systems, applications, and responsible owners.
  • Check exposed vulnerabilities against CISA KEV and current vendor advisories before working through lower-risk findings.
  • Define emergency, routine, and deferred maintenance paths with approval and rollback requirements.
  • Measure time-to-remediate by risk class and report accepted exceptions with an owner and expiry date.
  • Test that security updates have not broken authentication, integrations, backups, or critical workflows.

Treat exceptions as decisions, not silence

Some systems cannot be patched immediately. In that case, record why, who accepted the risk, what temporary controls are in place, and when the decision will be reviewed. Network isolation, access restrictions, additional monitoring, or replacement planning can reduce exposure while a permanent fix is prepared.

A mature vulnerability programme is therefore less about producing a long scan report and more about creating a repeatable path from detection to ownership, remediation, validation, and evidence.

Sources and further reading

This article summarizes publicly available research. Source findings retain their original geographic and sector scope.

  1. [01]2026 Data Breach Investigations ReportVerizon Business · 2026
  2. [02]Communications Sector Cyber Security Posture Report FY 2024/25Uganda Communications Commission · 2026
  3. [03]Known Exploited Vulnerabilities CatalogCISA · Continuously updated

Put this thinking to work

Tell us about your estate and we’ll map what to build, secure, or fix first.

Keep reading

More insights