Patched Doesn't Mean Safe: Why Security Teams Need to Test After They Fix

A new survey of 750 security leaders finds that fewer than one in three organisations check whether a fix actually stopped an attacker. The gap between completing work and reducing risk is where breaches still happen.

ThreatVectr Newsdesk· 4 min read
Photoreal news-editorial style, 16:9, close-up of a glowing server rack in a dark data center, amber warning indicator lights reflecting on polished metal surfa
Share

Key points

  • Only 30% of chief information security officers surveyed say their organisations patch a vulnerability and then test to confirm the risk is truly gone.
  • A global investment firm found 85 security weaknesses that, when combined, opened 251 ways for an attacker to cause serious damage.
  • After fixing those weaknesses and retesting, that firm cut the number of successful attack outcomes from 251 to zero.
  • In a survey of 750 security leaders and practitioners, 22% named "verifying that fixes actually worked" as their single biggest challenge heading into 2026.
  • Closing a ticket and reducing risk are two different things; only one of them stops a real attacker.

What is the difference between patching and actually being safe?

Patching means applying a software update that removes a known flaw. Being safe means an attacker still cannot reach your systems, even after that update. Those two things are not automatically the same.

A vulnerability scanner, which is a software tool that checks your systems for known weaknesses, will tell you the flaw is gone. What it will not tell you is whether a criminal could still break in by a different route, or by combining several smaller problems together. Closing the ticket feels like finishing the job. For an attacker, it changes very little if the door is still open.

Research published by CSO Online, drawing on a survey of 750 security leaders and practitioners, puts a number on that gap. Nearly half of organisations rescan with a vulnerability scanner after patching and call it done. Just 30% of chief information security officers (CISOs, the executives responsible for an organisation's security) said their teams actually test whether an attacker could still succeed.

How bad can the gap get in practice?

Bad enough to be alarming. One global investment firm operating across 18 offices had all the usual tools: vulnerability data, security assessments, regular reporting. What the team lacked was certainty.

An internal penetration test (pentest), meaning a controlled exercise where security professionals try to break in the way a real criminal would, found 85 weaknesses. That number alone sounds manageable. The danger became clear when analysts chained those weaknesses together the way an actual attacker would. The result: 251 distinct ways to cause serious harm.

Outcome measured Before fixes After fixes
Total harmful attack outcomes 251 0
Credential theft successes 52 0
Servers or endpoints taken over 67 0
Active Directory passwords cracked 40 0

Active Directory is the system most organisations use to manage who can log in and what they can access. Cracking those passwords is roughly equivalent to stealing a master key to the building.

After the firm fixed the identified weaknesses and ran the same test again, every single outcome dropped to zero. Not better. Zero.

Should ordinary people be worried about organisations that skip this step?

Yes, in practical terms. When a company holds your personal data, your payment details, or your medical records, the security of that data depends on whether their fixes actually work, not just whether their dashboards look clean.

The survey found 22% of practitioners called fix verification their biggest challenge for 2026, ahead of budget problems and staff shortages. That means a significant share of organisations protecting your data are not confident their repairs held.

If a company you deal with announces a data breach, ask whether they have shared what testing they did after the breach was fixed. A straight answer matters more than a polished press release.

What does a mature approach look like?

The discipline is straightforward, even if the execution takes effort: find the weakness, fix it, then test again to confirm it is gone, and repeat that cycle as the environment changes. Financial services firms and defence suppliers named in the underlying research built this loop into normal operations because their leadership demanded proof, not progress reports.

Scanning and patching remain necessary. Verification is what turns activity into actual confidence.

© 2026 Threat Vectr