How Quickly Do We Patch? A Global Reality Check (Spoiler: Not Fast Enough)
Global Patch Management: Why Speed Matters in Cybersecurity – The Hidden Cost of Slow Patching
Vendors ship the fix. Attackers weaponize it in days. Most organizations still take weeks to deploy. The distance between those two speeds is where breaches live.
Time-to-patch is the number of days between a vendor releasing a security fix and an organization actually deploying it across every affected machine. Measured across the global internet, that number is uncomfortably large, and it is the single clearest signal of how quickly we patch: not nearly quickly enough.
That is not an opinion. In July 2025 the SANS Internet Storm Center published a study that watched patch adoption from orbit, using 30 months of Shodan scanning data measured against CISA's Known Exploited Vulnerabilities catalog. The finding was blunt: for most of these actively exploited flaws, the count of vulnerable systems on the public internet falls only gradually, in a roughly straight line, and tends to level off well before it reaches zero. Long after a fix is available, exposed machines are still sitting there. CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area, and unpatched software is one of the most common weaknesses we find when a new client hands us their environment.
What Does the Global Data Actually Say About How Fast We Patch?
Independent measurement from three separate vantage points reaches the same conclusion: patch deployment lags exploitation, badly.
The global patching picture is slow and uneven. The SANS Internet Storm Center measured it from the outside and found vulnerable-system counts declining gradually and then stalling. Verizon measured it from breach data and found most known-exploited flaws still unremediated a month after patches were available. Both point the same direction.
Start with the SANS study, because it is the report this post is built on. The author pulled 30 months of Shodan data and tracked, for each vulnerability in the CISA KEV catalog, how many internet-facing systems remained exposed over time. For most flaws the exposed count dropped in a slow linear slide rather than a sharp cliff, and the slide flattened out with plenty of vulnerable systems still online. The honest caveat, which the author states plainly, is that Shodan can only fingerprint roughly 200 to 250 of the roughly 1,380 vulnerabilities in the KEV catalog, and it cannot always see a backported fix. Even with that limit, the shape of the curve is the story: patching is a slow bleed, not a fast close.
Verizon's 2025 Data Breach Investigations Report adds hard numbers from the defender's side. Exploitation of vulnerabilities was the initial access path in 20% of breaches, up 34% from the prior year's report. Only about 54% of edge-device and VPN Known Exploited Vulnerabilities were fully remediated across the year, and the median time to remediate them was 32 days. A month, for the flaws attackers are known to be using, on the internet-facing gear that guards the front door.
Google's threat-intelligence team measured the attacker's side of the same clock and found it collapsing. The median time-to-exploit for vulnerabilities fell to five days in the most recent full analysis, down from 32 days a couple of years earlier and 63 days before that. In their look at 112 flaws disclosed in 2024, the average time-to-exploit came out to
Why Is the Gap Between Patch and Exploit the Number That Matters?
A patch you have not deployed protects nobody. The only figure that decides your safety is how many days your machine stays open after the fix goes public.
The exposure window is the stretch of time between a fix becoming public and your machine actually installing it. It is the number that matters because disclosure is symmetric: defenders and attackers read the same advisory at the same moment, and whoever moves faster wins your systems.
Here is the sequence, because it runs the same way almost every time. A vendor discloses a flaw and ships a patch. That advisory is public, so attackers get it too. They reverse-engineer the fix to work out exactly what it changed, build an exploit, and load it into automated scanners that sweep the entire public internet looking for machines that have not applied the update. You are not singled out. You are swept up by tooling that checks millions of addresses for the one door you left open.
Years ago this was survivable because the window was wide. An organization might have had months between disclosure and mass exploitation. That cushion is gone. When Google reports a five-day median time-to-exploit and Verizon reports a zero-day median from disclosure to mass exploitation for edge devices, a 32-day remediation median stops being "reasonably prompt" and becomes "four weeks late." The math is not close, and it does not care how busy the office manager was.
- Disclosure is public on day zero. The advisory that tells you to patch is the same advisory that tells an attacker what to build. There is no head start.
- Exploitation is automated, not personal. Scanning tools hit the whole internet. A 15-person firm in Cypress is as findable as a Fortune 500, and often easier to breach.
- Known-exploited flaws are the priority. The CISA KEV catalog exists because these vulnerabilities are confirmed in active use. A flaw on that list is not theoretical risk, it is a scanner already looking for you.
Find the Open Doors Before a Scanner Does
CinchOps runs patch and vulnerability management as a continuous service for Houston-area SMBs, starting with a full inventory so nothing hides on a home laptop or a forgotten server. It is core to our managed IT and cybersecurity services.
Explore CinchOps cybersecurity →Why Do Houston Small Businesses End Up on the Slow Side of the Curve?
Not because owners are careless. Because patching is a full-time discipline handed to people who already have a full-time job.
Houston SMBs land on the slow side of the global patch curve because patching is nobody's dedicated job, on a mix of systems nobody has a complete inventory of. The failure is structural, and it is exactly the failure the SANS data captures at internet scale: machines that stay exposed long after a fix exists.
Walk into a typical 25-person firm in Katy or Sugar Land and you will not find a patch manager. You will find an office manager who also "handles the computers," or an owner resetting passwords between sales calls. Patching competes with payroll, client deadlines, and every fire louder than a security advisory nobody read. In 35 years doing this, the pattern barely changes: the intent is there, the time is not. That is how a business becomes one of the flat-lined systems in a global scan, still vulnerable months later.
The specific things that push small Houston businesses into the lag are predictable:
- No complete asset inventory. You cannot patch what you do not know you own. A laptop that went home, a server in a closet, a line-of-business app three versions behind, a firewall a prior vendor set up and never revisited. The unknown gear is where the exploit lands.
- Fear of breaking production. A bad patch can disrupt as much as the bug it fixes. An owner burned once becomes reluctant to apply anything, which is worse, because now the known-exploited flaws stay open by choice.
- Third-party software blind spots. Windows nags you to update. The PDF reader, browser plugins, accounting package, and remote-access tool often do not, and those are exactly what Verizon shows attackers probing on the edge.
- Remote and hybrid machines. A laptop that rarely touches the office network can go months without checking in for updates. Most Houston SMBs now run several.
- No verification step. Clicking "update" is not the same as confirming the patch installed on all 40 endpoints. Without a report, you are guessing, and the one machine you missed is the one the scanner finds.
This region gives the problem a real local edge. The Houston metro runs on lean, often family-run companies in construction, engineering, oil and gas services, CPA practices, and law firms, many growing faster than their back-office systems. That growth bolts on new devices and new software constantly, widening the patch surface at exactly the pace a small team cannot match. Add the Gulf Coast reality that energy-sector operators here carry older operational technology that vendors patch slowly or not at all, and you get a corridor of capable businesses sitting further out on the slow end of the global curve than their owners realize.
Where Does Your Business Sit on the Patch Curve?
Most Houston SMBs discover unpatched, actively exploited flaws the moment someone finally looks. A CinchOps assessment shows you exactly where you stand across every device.
Get a Free Patch AssessmentThe economics run in the small business's favor here, which is not always true in security. A managed provider spreads the cost of patch tooling and the expertise to run it across many clients, so a Houston company with 30 employees gets enterprise-grade patch discipline for a predictable monthly fee. Set against the cost of one ransomware event that walked in through an unpatched remote-access tool, the comparison is not a close call.
The global data just confirms what I have seen for 35 years: the breach almost never needs a clever new trick. It needs a patch that shipped weeks ago and a business that never got around to installing it. Attackers moved to a five-day clock. Most small companies are still on a five-week one. That gap is the whole game.
How CinchOps Closes the Patch Gap for Houston Businesses
CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area. CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10-200 employees.
For patch management specifically, that means we take time-to-patch off your plate and run it as a continuous service, not a favor somebody remembers to do. Here is what that looks like for a Houston SMB:
- Complete visibility. We inventory every endpoint, server, and network device so patching is measured against your real environment, home laptops and edge gear included.
- Risk-based prioritization. Actively exploited and CISA KEV-listed flaws get closed first, on deadlines that match how fast those specific flaws are being used, not a generic monthly cycle.
- Tested deployment. Updates run through a controlled pilot ring before they reach production, so patching protects the business instead of disrupting it, which answers the fear that keeps owners from patching at all.
- Reporting you can show an auditor. Documented patch status supports cyber insurance requirements and compliance obligations for regulated Houston industries.
Time-to-patch is not the exciting part of security, and that is exactly why it slides until the day it turns into an incident. If your business in Houston, Katy, or Sugar Land has no clear answer to "when was every machine last patched," that is the gap worth closing first. It is the exposure that hits construction, oil and gas, and law firms alike. When you want a straight answer about where you stand on the curve, talk to CinchOps and we will show you.
Frequently Asked Questions
How quickly do organizations actually patch known vulnerabilities?
Not quickly enough. The SANS Internet Storm Center used 30 months of Shodan data and found vulnerable systems dropping off only gradually after a patch ships. Verizon's 2025 DBIR reported a median of 32 days to remediate edge-device known-exploited flaws, with only about 54% fully fixed across the year.
Why does the gap between patch release and deployment matter so much?
Because attackers move faster than defenders. Google's threat team found the median time-to-exploit fell to five days, and for 2024 flaws the average was negative one day, meaning exploitation before a patch existed. A machine patched a month after disclosure sat open the entire time attackers were scanning for it.
Why do small Houston businesses fall behind on patching?
Patching is a full-time discipline usually handed to someone with another full-time job. Small Houston firms lack complete asset inventories, fear a patch will break production software, and miss third-party and remote-machine updates. The failure is structural, not a matter of effort, which is why managed automation is the realistic fix.
Discover More
Sources
- SANS Internet Storm Center, "How quickly do we patch? A quick look from the global viewpoint" (30 months of Shodan data vs. the CISA KEV catalog)
- Verizon, 2025 Data Breach Investigations Report (vulnerability exploitation as initial access, edge/VPN KEV remediation rates and median days)
- Google Threat Intelligence / Mandiant, time-to-exploit trend analysis (five-day median; 2024 average time-to-exploit)
- CISA, Known Exploited Vulnerabilities Catalog (confirmed actively exploited flaws and federal patch deadlines)