Abatis Perspectives

Insights, analysis, and commentary from the minds behind Abatis. We explore the evolving world of cybersecurity, share lessons from the field, and offer thought leadership to help you navigate today’s digital threats with confidence.

Patchmageddon: what protects the organisation before the patch arrives?

Official J.P. Morgan report: Patchmageddon: The race to patch software vulnerabilities before zero-day cyber-exploitations proliferate. It is written by Michael Cembalest, Chairman of Market and Investment Strategy for J.P. Morgan Asset & Wealth Management.

Patchmageddon: what protects the organisation before the patch arrives?

Michael Cembalest’s new J.P. Morgan report, Patchmageddon, describes a fundamental change in cybersecurity.

The time available to defenders is collapsing. The report states that the average period between disclosure of a vulnerability and its first exploitation has fallen to a single day. At the same time, organisations are taking longer to remediate vulnerabilities. In approximately 60 per cent of breaches, a patch was already available when the compromise occurred.

AI will intensify the problem. Frontier models can identify previously unknown vulnerabilities, connect apparently modest weaknesses into serious exploit paths, and help turn disclosed vulnerabilities into working exploits far more rapidly than before.

 

Patching remains essential. But patching is not instantaneous.

 

Before a patch can be deployed, an organisation may need to identify every affected asset, update dependent software, test compatibility, obtain operational approval and schedule downtime. Even then, some endpoints may remain unpatched without anyone realising it. The report notes that security teams regularly postpone patches because of the risk of disrupting operations.

 

The problem is more severe in operational technology and critical infrastructure. Industrial systems may remain operational for 10 to 18 years. J.P. Morgan estimates that only 55 to 65 per cent of industrial network hardware may be patchable, leaving a substantial proportion difficult or impossible to update.

 

This raises a question that deserves more attention:

What protects the system during the period when the vulnerability is unknown, the patch does not yet exist, or the equipment cannot safely be patched?

At Abatis, we address this through Deterministic eXecution Integrity™, or DXI.

 

Rather than attempting to determine whether code is malicious after execution has begun, DXI controls whether executable code is authorised to be introduced onto the protected system.

 

DXI does not replace patch management, identity security, segmentation or monitoring. Nor does it eliminate every possible method of exploitation. It provides a compensating control against a critical route from vulnerability to compromise: the introduction or modification of unauthorised executable content.

 

Michael Cembalest’s report defines the emerging problem particularly well. As attacker time to exploit approaches zero, organisations must continue asking how they can patch faster.

 

They should also ask:

What control remains in place while we are waiting for the patch?

 

Read the J.P. Morgan report: https://am.jpmorgan.com/content/dam/jpm-am-aem/global/en/insights/eye-on-the-market/patchmageddon-amv.pdf 

 

Learn how Deterministic eXecution Integrity addresses the gap between exploitation and patching: https://www.abatis.ch/dxi/