How long does it typically take your organization to patch a non-critical vulnerability?

< 1 Week19%

< 1 Month50%

< 3 Months17%

< 6 Months9%

1 Year+2%

207 PARTICIPANTS
2.4k viewscircle icon1 Upvotecircle icon2 Comments
Sort by:
Senior IT Manager in Government4 years ago

Impossible to give a single answer, because it depends upon the nature of the vulnerability and the specific business/infrastructure.  Some non-criticals are critical for us. Others are mitigated by means other than patching.

Lightbulb on1
ISSO and Director of the IRU in Healthcare and Biotech5 years ago

It’s also dependent on what level below on critical we have a remediation framework for critical, highs, medium and lows.

Content you might like

Yes83%

No15%

Not sure1%

View Results

Inevitable4%

Highly likely14%

Somewhat likely16%

Somewhat unlikely17%

Very unlikely41%

Impossible6%

View Results