Skip to main content
Regulaxy

For the CISO

You know what's open.
The question is how long it stays open.

The scanner does its job. The report arrives, the findings are ranked, and the board sees a number coming down too slowly. The reason is almost never that no fix exists — it is that the fix is waiting on a window nobody closed. That wait is what you report on, and it is the one thing you have no tool to manage.

  • TodayThe fix waits for a window
  • When the window is booked immediatelySame install, earlier

The figure illustrates the mechanism. It is not based on a customer measurement, and we will not show a number we do not have.

Figure — the exposure window, from published fix to installed fix

What the report doesn't show

The number falls slowly, and the reason isn't in the scanner.

  • Technically fixed, practically open

    The patch exists, has been tested, and is ready. It is waiting on an approval from an owner who is on leave. On the report it is still a red row.

  • CVSS doesn't know your business

    A 9.8 on a test box and a 7.5 on the core platform. The technical score cannot tell you which one takes payments down.

  • Blast radius is guesswork

    When a window is planned, the question of what falls over with this system is usually answered from the memory of whoever happens to be in the room.

  • Nothing to report but a count

    Open findings is a poor measure of a process. What the board asks is how long it takes to close one, and there is no field for that.

What changes

The patch becomes a schedulable unit.

  • The patch, not the CVE

    One patch usually fixes several vulnerabilities across several hosts. The register groups by patch, because that is the unit a window can be booked for.

  • A score you can explain

    Shown with every term that produced it and how much each contributed — business criticality, exposure, patch age. The terms sum to the score. You can disagree with it; you cannot call it arbitrary.

  • Blast radius read from the estate

    The dependency map is built from actual host-to-host traffic rather than a document. That is also where the two-systems-one-night warning comes from.

  • A measure you can report

    Per patch: when it entered the register, which window it was booked into, and what happened there. The interval is time-to-remediate, and it is read out rather than collected.

What you personally receive

A ranked patch register with time-to-remediate

What is open, on which systems, who owns them, and when a window was booked. That is what goes on the quarterly slide instead of a count.

What is blocking your fixes today?

If the answer is "a window" rather than "a patch", that is precisely the problem this product was built for.