惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

腾讯CDC
The Cloudflare Blog
IT之家
IT之家
V
V2EX
雷峰网
雷峰网
MyScale Blog
MyScale Blog
P
Proofpoint News Feed
Stack Overflow Blog
Stack Overflow Blog
博客园 - Franky
Engineering at Meta
Engineering at Meta
S
SegmentFault 最新的问题
GbyAI
GbyAI
Microsoft Azure Blog
Microsoft Azure Blog
博客园 - 司徒正美
云风的 BLOG
云风的 BLOG
小众软件
小众软件
博客园 - 叶小钗
Blog — PlanetScale
Blog — PlanetScale
C
Check Point Blog
A
About on SuperTechFans
B
Blog
月光博客
月光博客
宝玉的分享
宝玉的分享
Last Week in AI
Last Week in AI

Forbes - Innovation

Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2 Quordle Hints Today: Monday, April 13 Clues And Answers
Why Patching Shouldn't Be Your Only Remediation Strategy
Roi Cohen · 2026-05-05 · via Forbes - Innovation

As the CEO and co-founder of Vicarius, Roi Cohen leads a cybersecurity company that provides exposure management solutions for enterprises.

getty

​In every environment I’ve worked with, there are always systems you can’t patch. Sometimes it’s because a vendor hasn’t released a patch. Sometimes it’s because of legacy systems that cannot have patches applied. Sometimes it’s a dependency chain you can’t untangle without risking downtime. And sometimes the cost of touching production is simply too high.

​But the risk is still there while you figure it out—or don't.

​And in many cases, that “temporary” delay becomes the default. A known vulnerability sits open, not because teams don’t see it or ignore it, but because they’re out of safe options and push it into their backlog.

​The problem is only compounding as modern work environments become more interconnected and more fragile. Cloud services, SaaS platforms and legacy systems now coexist in ways that increase both dependency and risk. With that complexity comes tighter change management, more approvals and a lower tolerance for disruption.

​At the same time, the window for attackers keeps shrinking. What used to take days can now happen in minutes. Remediation timelines, however, haven’t kept up. They’re still governed by operational realities: testing cycles, cross-team coordination and the very real fear of breaking something critical.

​This is not just a technical gap, but an operational one too. Which is why we need to rethink how remediation actually works in practice.

Remediation Should Provide Options

Remediation is no longer a single action. It’s a set of options teams choose from based on what’s possible in the moment. When a vulnerability appears, teams effectively ask:

Can we patch this without introducing risk?
If not, how do we reduce exposure in the meantime?

​That second question is where most teams get stuck because they haven’t operationalized what “next best” actually looks like.

​When a patch isn’t viable, teams are forced to look elsewhere: scripting temporary fixes, adjusting configurations or applying runtime protections that block exploitation without changing the underlying code.

What I see across organizations is a gradual but important shift in mindset. Teams are moving away from waiting for a clean, permanent fix before acting. Instead, they’re focusing on reducing exposure continuously, using whatever reliable controls are available to them at the time. That often means creating a culture that accepts that the first step might not be perfect, but should be effective enough to lower risk immediately.

Three Practical Paths Teams Take

There isn’t a single “right” way to remediate. Most teams rely on a combination of approaches, depending on the system, the risk and the constraints around it.

Patch When You Can

Patching is still the most complete and reliable fix. But in real-world environments, patching isn’t always immediate. It requires testing, coordination and often a maintenance window that’s hard to justify on short notice. That delay is where risk starts to build.

Script And Configure Around The Problem

When patching isn’t practical, teams often turn to scripting or configuration changes. This might mean restricting access, disabling vulnerable components or applying temporary fixes that reduce the attack surface. It’s a fast and flexible way to respond without waiting for the ideal conditions. The trade-off is that these fixes need to be tracked and revisited or temporary workarounds can become a permanent risk.

Apply Runtime Protection

Another approach is to prevent exploitation at runtime. Often referred to as virtual patching or patchless protection, this involves controlling how applications behave in memory, limiting API calls or blocking known exploit paths. And while it doesn’t remove the vulnerability, it mitigates the risk of exploitation, buying teams time to remediate the vulnerability. This is especially critical for legacy systems, high-risk production environments or assets that simply can’t be patched on demand.

The Bottom Line

The most effective teams don’t rely on a single remediation path. They understand all the options available to them and their trade-offs, and use them in combination to reduce risk as quickly as possible.

​Patching remains essential. But treating it as the default—or only—path to remediation assumes a level of control and speed that most organizations simply don’t have. In a threat landscape where exploitation timelines are measured in minutes and remediation still takes weeks, waiting for the “right” fix can leave too much room for exposure to grow.​

In practice, resilience comes down to having options and knowing how to use them when it matters.​


Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?