HD Moore's Pitch to Defenders: Stop Racing Patches, Reshape the Network

The Metasploit creator argues blast-radius control, not patch velocity, is what regulators and boards should be measuring.

ThreatVectr Newsdesk· 3 min read
HD Moore's Pitch to Defenders: Stop Racing Patches, Reshape the Network
Share

HD Moore wants defenders to give up on a fight they were never going to win.

The Metasploit creator, now running asset discovery firm runZero, is making the rounds with a thesis that lines up uncomfortably well with where disclosure regulators are heading: assume the breach, because patching in time stopped being a realistic control years ago.

His argument is straightforward. Zero-days keep shipping. AI is accelerating exploit development faster than vendors push fixes or customers deploy them. The variable you actually control is not which CVE lands in your environment. It is what that CVE can touch once it executes.

That is a network architecture problem. Moore says most organizations have the shape wrong.

The framing matters for anyone tracking the regulatory side of this beat. The SEC's cyber disclosure rule under Item 1.05 of Form 8-K, which took effect in December 2023, turns on materiality — and materiality is largely a function of blast radius. A bug in an isolated segment is a Tuesday. The same bug with lateral reach into financial systems is a filing event.

CIRCIA runs on similar logic. CISA's notice of proposed rulemaking, published April 4, 2024 at 89 FR 23644, defines covered cyber incidents partly by scope of impact, not by the initial access technique. The comment period closed July 3, 2024. A final rule is due by October 2025 under the statutory deadline in 6 U.S.C. § 681b.

NIS2 took the same turn in Europe. Article 21 of Directive (EU) 2022/2555 requires "appropriate and proportionate" measures including network segmentation and access control, with national transposition deadlines that lapsed October 17, 2024. Enforcement is now a member-state matter, and several regulators have signaled segmentation evidence will feature in supervisory reviews.

Moore's pitch, then, is not just operational advice. It tracks where compliance is going.

The practical version of "shape your network like the attacker sees it" is unglamorous work. Inventory what is actually reachable from what. Map trust relationships between identity providers, hypervisors, and management planes. Find the flat Layer 2 domains nobody documented. Decide which crown-jewel systems should never be one hop from a help-desk laptop.

None of that shows up in a CVSS score.

It does show up in a post-incident 8-K, in a CIRCIA report, in an Article 23 NIS2 notification to a competent authority. Regulators are increasingly asking the same question Moore is asking: once something got in, why could it reach so much?

The race to patch is not going away. But it is no longer the metric that determines whether an incident becomes a disclosure.

Boards that have not yet asked their security teams to produce a reachability map, rather than a vulnerability count, are asking the wrong question.

© 2026 Threat Vectr