How long does it typically take your organization to patch a non-critical vulnerability?
< 1 Week19%
< 1 Month50%
< 3 Months17%
< 6 Months9%
1 Year+2%
207 PARTICIPANTS
Sort by:
ISSO and Director of the IRU in Healthcare and Biotech5 years ago
It’s also dependent on what level below on critical we have a remediation framework for critical, highs, medium and lows.

Impossible to give a single answer, because it depends upon the nature of the vulnerability and the specific business/infrastructure. Some non-criticals are critical for us. Others are mitigated by means other than patching.