The Patch Window Is Closed: Why CISOs Are Quietly Reallocating to BAS
Vulnerability management was built around a buffer between disclosure and weaponization. Generative tooling is collapsing that buffer, and breach-and-attack simulation budgets are absorbing the panic.

For three decades, vulnerability management ran on borrowed time.
The model was simple. A CVE drops, severity gets scored, the patch team queues it against a change window, and somewhere in the middle a tester confirms the fix didn't break the SAP install. The whole workflow assumed an exploit-development gap measured in weeks or months. That gap is what made CVSS-driven triage rational in the first place.
That gap is now measured in hours, sometimes less. And it's not because defenders got slower.
The shift is on the offense side. Coding assistants — Claude, GPT-5-class models, the open-weight Qwen and DeepSeek variants getting fine-tuned in less savory corners — have compressed the time between a vendor advisory and a working proof-of-concept. We've covered cases where N-day exploit code appeared within a day of public disclosure, often reconstructed from the patch diff itself. The buffer didn't shrink. It's gone.
This breaks a load-bearing assumption in most enterprise security programs.
If you can't patch faster than attackers can weaponize, severity-based queuing stops being a defense strategy and starts being an accounting exercise. Critical, high, medium, low — the labels still matter for audit, but they no longer describe a race you're winning. Plenty of CISOs have figured this out. The interesting question is what they're doing with the budget that used to fund quarterly scan-and-patch cycles.
A lot of it is moving into breach-and-attack simulation.
BAS isn't new. Vendors like SafeBreach, AttackIQ, and Cymulate have been pitching continuous control validation for years, mostly to mature SOCs with money to spend. What's changed is the buyer's framing. The pitch used to be "prove your EDR works." The pitch now is "assume the vuln will be exploited before you can patch it, and validate that your compensating controls actually catch the post-exploitation behavior." That's a different product even if the dashboards look similar.
It's also closer to how attackers actually think. A weaponized CVE is one node in a kill chain. If your segmentation holds, your EDR flags the lateral movement, and your identity tier prevents privilege escalation, the unpatched box is a problem but not a breach. BAS gives you a way to test that chain on a Tuesday instead of during an incident.
The risk in this shift is the usual one: treating BAS as a replacement for patching rather than a hedge against patching being slow. Vulnerability management isn't dead. It's demoted. The new top of the stack is whatever proves your controls work when — not if — a patch lands after the exploit.
CISOs who frame it that way are getting their budget approved. The ones still selling "reduce critical CVE count by 30%" are watching the board's eyes glaze over.



