Cyber security
The 2026 patching gap: a risk-based guide for technology leaders
5 August 2026 · 7 min read · 3 public sources

Patching has become a board-level resilience issue. Verizon’s 2026 Data Breach Investigations Report identifies vulnerability exploitation as the leading initial access vector in its global dataset, accounting for 31% of breaches. The same report found that only 26% of vulnerabilities listed in CISA’s Known Exploited Vulnerabilities catalog were fully remediated by organizations in the dataset.
The local operational signal
The Uganda Communications Commission’s FY 2024/25 sector report recorded persistent web-server vulnerabilities and linked delayed remediation to limited IT resources, low awareness, and concerns about downtime. The finding applies to the communications sector, but the operating lesson is useful anywhere maintenance windows compete with service availability.
Build a patch queue around business risk
- Maintain a complete inventory of internet-facing systems, operating systems, applications, and responsible owners.
- Check exposed vulnerabilities against CISA KEV and current vendor advisories before working through lower-risk findings.
- Define emergency, routine, and deferred maintenance paths with approval and rollback requirements.
- Measure time-to-remediate by risk class and report accepted exceptions with an owner and expiry date.
- Test that security updates have not broken authentication, integrations, backups, or critical workflows.
Treat exceptions as decisions, not silence
Some systems cannot be patched immediately. In that case, record why, who accepted the risk, what temporary controls are in place, and when the decision will be reviewed. Network isolation, access restrictions, additional monitoring, or replacement planning can reduce exposure while a permanent fix is prepared.
A mature vulnerability programme is therefore less about producing a long scan report and more about creating a repeatable path from detection to ownership, remediation, validation, and evidence.
Sources and further reading
This article summarizes publicly available research. Source findings retain their original geographic and sector scope.
- [01]2026 Data Breach Investigations ReportVerizon Business · 2026
- [02]Communications Sector Cyber Security Posture Report FY 2024/25Uganda Communications Commission · 2026
- [03]Known Exploited Vulnerabilities CatalogCISA · Continuously updated
Put this thinking to work
Tell us about your estate and we’ll map what to build, secure, or fix first.
Keep reading
More insights

Digital platforms
Why enterprise software in Uganda must be designed mobile-first
30 July 2026 · 7 min read

Data protection
Uganda data protection compliance is a technology architecture problem
17 July 2026 · 8 min read
