Every unpatched CVE becomes "accepted risk."
It doesn't have to.
The gap between a disclosed vulnerability and a deployed patch is widening every year — and the assets stuck in that gap are exactly the ones attackers go after first. Get the step-by-step playbook for closing the exploit path without waiting on a patch, a change window, or a budget cycle.
Written for the people who own or influence the risk register
Security writes the risk-acceptance memo. This playbook is for whoever has to actually close the exploit path underneath it.
An indefinite waiver isn't a control an auditor wants to see twice.
Reclassify accepted risk as compensated risk with an access log instead of a memo re-justified every quarter.
Not every CVE deserves an emergency change window.
Close the exploit path in minutes, then patch the underlying system on your normal maintenance schedule.
Virtual patching is a control that never stops needing attention.
An asset that can't be reached doesn't need a signature watching what reaches it.
"What's exposed to the public internet?" should have a one-line answer.
It does, once the asset has no listening port at all.
ACL sprawl is what happens when nobody trusts removing a rule.
Identity-based policy travels with the workload — no rebuild when the network around it changes.
A risk register should shrink, not just grow.
Track time-to-compensating-control against the count of risk with no compensating control at all.
Eight sections. One compensating control you can operationalize this week.
From naming the five categories of unpatchable risk to a joint Security + IT Ops workflow mapped to concrete platform steps.
TACTICAL PLAYBOOK
Get The Unpatchable Vulnerability Playbook
The full compensating-control matrix, the technical mechanics of identity-first reachability, and both ready-to-use templates — ready to apply to your first cloaked asset.
