Cybersecurity

Why Does Vulnerability Management Need a New Control Layer Before Patches Are Installed?

Igor Sakhnov of Microsoft believes that the gap between vulnerability discovery and remediation has become more dangerous than organizations can reduce, particularly as AI-enabled exploitation accelerates. He proposes that the network serve as an adaptive defense layer that temporarily reduces exploitability until a patch can be tested and deployed.

2026-08-25
5 min read
10 views
فريق تحرير certi.news
Why Does Vulnerability Management Need a New Control Layer Before Patches Are Installed?

Igor Sakhnov, Executive Vice President and General Manager of Azure Networking at Microsoft, believes that the traditional vulnerability management model can no longer keep pace with the speed of modern threats. Organizations often need days or weeks to understand a vulnerability’s impact, identify affected systems, test the patch, coordinate with operations teams, and deploy it in production environments. By contrast, a disclosed vulnerability may move to scanning and active exploitation within hours.

This position, published on August 25, 2026, on the Microsoft Security Blog, does not announce a specific product so much as present the company’s view on redistributing the roles of protection layers. The central idea is that patching will remain necessary, but it will not always be the fastest action for reducing risk. Organizations therefore need compensating controls that operate during the interval between discovering a problem and closing it permanently.

The Patching Window Is Narrowing

Traditional vulnerability management was built on the assumption that defenders had enough time to assess a problem before attackers exploited it on a broad scale. But enterprise environments now include thousands of servers, applications, databases, containers, and network assets distributed across cloud, hybrid, and multicloud environments. In addition, many business-critical applications cannot be taken offline as soon as a security update becomes available.

Verification steps remain necessary and are not an indication of weak processes. Security teams must understand the vulnerability’s business impact, identify affected systems, examine dependencies and compatibility, validate the patch in test environments, coordinate change schedules, and then monitor for any operational side effects. The problem is that these operational safeguards require time, while the time attackers need to discover an exploitable path is shrinking.

AI Is Compressing the Timeline

According to Sakhnov, AI’s impact is not limited to helping organizations analyze data and improve security. AI-supported operations can also accelerate the analysis of vulnerability disclosures, understanding of exploitation conditions, identification of attack paths, and correlation of complex technical information. As these capabilities become more widely available, the gap between a vulnerability’s disclosure and attempted exploitation is shrinking.

A clear imbalance in responsibilities emerges here: the defender must protect a complete and complex environment, while the attacker needs only one viable path to reach a target. It is therefore not enough for an organization to know which systems are vulnerable or to raise the patch’s priority. What is required is to reduce exploitability immediately when the update cannot be installed.

The Network as a Temporary Containment Layer

The article proposes viewing the network as a fast “control layer” that can protect workloads while remediation continues. The network sits outside applications and has visibility into communication patterns, trust relationships, and traffic flows, enabling changes to be applied without modifying the application itself or waiting to deploy a new agent to every endpoint.

According to the proposal, these controls can restrict access to vulnerable systems, reduce potential attack paths, limit lateral movement, isolate high-risk assets, and reduce the potential scope of damage. They can also be adjusted as new information emerges, potentially faster than the cycle of testing and deploying a patch in a large enterprise environment.

The source gives the example of a vulnerability in HTTP/2 for which the temporary remediation recommendation might be to disable the protocol entirely, but that could affect application performance and availability. A more precise response might involve limiting the number of concurrent streams, tightening request restrictions, or rate-limiting abusive communication patterns while keeping the service available. The example illustrates the difference between blocking communication entirely and restricting the behavior on which exploitation depends.

From Awareness to Adaptive Enforcement

Sakhnov emphasizes that visibility tools, threat intelligence, and analytics are important, but they do not reduce exposure on their own. Adaptive protection requires three interconnected capabilities: understanding the nature of the vulnerability, relating it to the actual environment in terms of configurations, communication paths, and exposure, and then converting that understanding into controls that can be applied quickly and at scale.

In certi.news’s reading, the proposal’s importance lies in identifying a practical gap that patching alone does not solve: what does an organization do when it knows about the risk but cannot change the system immediately? However, this view does not eliminate patch management, nor does it establish that network controls are suitable for every vulnerability. Their effectiveness depends on understanding exploitation behavior and tuning rules so that containment measures do not become service disruptions or create a false sense of security. The source also presents an editorial position from a Microsoft official, not independent test results or a commitment regarding the capabilities of a specific product. The open question therefore remains how precise and applicable this adaptive protection is across different environments, while final patching continues to be the fundamental remediation for the problem.

News source
Microsoft Security Blog
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news