Most Open Critical & High Vulnerabilities Remain Unpatched for Over 90 Days
What Happened – Detectify’s scan of 1,293 organizations in the US, UK and Nordics shows that 97 % of critical and high‑severity flaws on internet‑facing assets have been exposed for more than 90 days. Public‑sector bodies resolve the fewest findings (under 9 % of critical/high issues), while consumer brands and technology firms perform better but still leave large backlogs.
Why It Matters for Trust & Control Assurance
- Long‑lived critical flaws indicate a gap in the vulnerability‑management control objective – the very process continuous‑control programs are built to monitor, document and remediate.
- Without evidence of timely patching, organizations struggle to provide a defensible audit trail for frameworks such as NIST CSF 2.0, which expects measurable remediation cadence.
- The backlog creates “alternative risk‑tolerance drift,” where unpatched issues become de‑facto accepted risk, eroding the trust signal that continuous monitoring is meant to protect.
Who Is Affected – Government & public‑sector agencies, consumer‑brand companies, technology firms, financial services, manufacturing, and any organization with internet‑facing assets.
Recommended Actions
- Map your vulnerability‑remediation workflow to the Verisq Trust Center to capture remediation dates, risk‑acceptance decisions, and ownership.
- Prioritize patches on assets that are high‑value or exposed, and embed patch approval into change‑management tickets with audit‑ready evidence.
- Establish a 30‑day SLA for critical/high findings and automate status reporting to satisfy continuous‑control monitoring requirements.
Source: Help Net Security article
Technical Notes
- The data reflects payload‑based testing confirming exploitability of each flaw.
- No single CVE is highlighted; the issue is systemic – prolonged exposure of critical/high vulnerabilities across sectors.
- Public‑sector delays stem from legacy infrastructure, fragmented ownership, and lengthy procurement cycles.
Source: same as above