Microsoft recently recommended that organizations deploy security updates within 72 hours, a recommendation that aligns with CISA's continued emphasis on accelerating vulnerability remediation across the industry.
For Adaptiva, these recommendations reinforce a reality the company has been highlighting for years: AI has dramatically compressed the window between vulnerability discovery and exploitation, making speed and scale more important than ever.
But according to Adaptiva’s CEO Deepak Kumar, the industry's focus on patching within 72 hours misses the bigger issue. Most organizations lack the operational capacity to respond at machine speed when the next critical vulnerability emerges, even if they can meet these arbitrary deadlines.
In the conversation below, Deepak discusses how AI is reshaping vulnerability discovery, why capacity has become cybersecurity's biggest challenge, and why autonomous endpoint management has become the foundation for modern cyber resilience.
Why is the cybersecurity industry suddenly talking so much about faster patching?
Deepak Kumar: I think several factors are driving this. The first is AI. Anyone with $50 can now run AI against a code base and find vulnerabilities. What's less obvious is that software supply chains have been compromised before. If somebody gains access to the source code of a popular software vendor and runs AI against it, nothing is protected anymore. Nothing is sacred. All software is now potentially vulnerable. That's game-changing.
The second factor is that you don't have to be a highly resourced attacker anymore. It could be someone sitting in a basement with $50 worth of AI credits, or it could be a nation-state actor. AI gives both access to capabilities that previously required far more time, expertise and resources.
And then the third factor is that organizations are realizing cybersecurity companies can't stop everything. Once a breach happens, the damage is often already done. Reputation is lost. Executives lose their jobs. That's why patching–remediating vulnerabilities before they become exploits– is now being discussed at the board level, not just by IT or security teams.
Everyone is talking about Microsoft's 72-hour recommendation. Are we focused on the right problem?
DK: I think we're asking the wrong question. Whether it's 72 hours, 71 hours, or 69 hours doesn't matter. I think we should be asking: if something critical happens tomorrow, does your organization actually have the capacity to respond?
People keep asking whether 72 hours is realistic. I think 72 hours is too long for truly critical vulnerabilities. But the bigger issue is that many organizations fundamentally don't have the capacity to respond when something serious happens.
If capacity is the real issue, where should organizations start?
DK: If I were running a highly targeted organization, I'd do three things:
First, I'd build the capacity to respond immediately if something bad happened. Think of it like a sprinkler system. If there's a fire, you don't wait around deciding what to do, you respond immediately. Of course, this means that the tedious tasks, like patching, need to be fully automated so that your IT teams have time to deal with out-of-band issues.
Second, I'd create visibility. I want to know what's happening across my environment. If an organization is constantly operating in chaos, there's so much noise that you'll never recognize the signal when something truly unusual happens.
Third, I'd proactively keep locking down the windows and doors that are open. Don't wait for attackers to find them first.
How has AI fundamentally changed vulnerability discovery?
DK: There used to be a belief that open source was safer because so many people could inspect the code, but AI has leveled the playing field, arming attackers as well as security teams.
Large, complex code bases used to be difficult for humans to analyze, but AI doesn't care if the code is complicated or poorly documented. It can analyze enormous amounts of source code and identify vulnerabilities humans might never have found.
Some open source projects have tried moving away from open source, but it's too late. The code is already out there. AI has fundamentally changed how attackers discover vulnerabilities, and every software organization has to assume attackers are taking advantage of that.
Where do humans fit if more security operations become autonomous?
DK: We're already seeing more than 100 new CVEs per day. Nobody, not even the richest company on the planet, can realistically look at all of them. Humans are great at creating strategy, process, thought, and ideas. But relentless, flawless execution of repetitive tasks? We're not very good at that. Humans get tired, we make mistakes, and we have competing priorities. Machines don't.
What an organization needs is something that can work relentlessly, 24 hours a day, seven days a week, consistently following instructions and guidance. That's what machines are good at.
Humans should set the strategy and policy, and let autonomous software execute the instructions in real time. Then give humans control to audit and adjust a truly autonomous system that is relentlessly performing at machine speed.
Where does autonomous endpoint management fit into this new reality?
DK: If you're going to respond at machine speed, you need some form of autonomous system. The challenge is that you have to secure the business without risking the business experiencing disruptions and outages in the process.
This is where an autonomous system is invaluable; it can continuously evaluate what's happening, respond immediately when necessary, and help prevent organizations from being overwhelmed by the sheer volume of vulnerabilities they're facing.
Things aren’t going to slow down. Looking at more than 100 new CVEs per day is already beyond human capability, and it's only going to get more challenging.
People hear "autonomous endpoint management" and assume it means taking humans out of the loop. Is that accurate?
DK: No. People think autonomy means, "Go do whatever you want." That's not what autonomy should mean. An autonomous system should understand the context of the business. And then once it understands that environment, it should be able to operate independently within defined boundaries. But just as importantly, it should know its own limits. It should know when something falls outside those boundaries and when it needs to ask for human guidance. The decision to involve a human should itself be part of autonomous behavior.
To me, that's the ideal. Not software that replaces people, but software that's smart enough to know what it can do on its own and when it needs human judgment.
If you're rethinking your organization's ability to respond to critical vulnerabilities, connect with an Adaptiva expert to discuss how autonomous endpoint management can strengthen your security posture.
