Microsoft is warning that the time available for patching vulnerabilities is rapidly collapsing, as attackers now move from disclosure to exploitation faster than enterprises can safely roll out fixes. In a blog post, Igor Sakhnov, corporate vice president and general manager for Azure Networking at Microsoft, urged organizations to adopt network-level controls to limit exposure during the gap between awareness and remediation. The traditional model of vulnerability management "increasingly reflects a world that no longer exists," Sakhnov wrote, as modern attack timelines compress while enterprise processes remain unchanged.
Vulnerabilities are now "more visible, more widely distributed, and more rapidly weaponized than ever before," according to Microsoft, while enterprise environments have grown more complex, spanning hybrid and multicloud infrastructure. Modern attack campaigns operate at internet scale, with security research, public disclosures, proof-of-concept exploits, and threat intelligence circulating globally within hours. Meanwhile, the operational realities of enterprise environments haven't changed. Shriya Mehrotra, director analyst at Gartner, said attackers can exploit critical vulnerabilities within hours for high-risk, internet-facing systems, while many enterprises still require weeks to test and deploy patches.
Sakhnov wrote that when a vulnerability was disclosed in the past, organizations had time to understand the issue, assess affected systems, test patches, coordinate change windows, and deploy fixes before widespread exploitation occurred. "Today that timeline is rapidly shrinking," he wrote. Microsoft said advances in AI and the rapid spread of exploit information are further accelerating the time from disclosure to attack, creating what the company described as "one of the most dangerous periods in modern cybersecurity: the window between awareness and remediation." The result is a "structural imbalance" between attackers and defenders, according to Sakhnov.
To address this gap, Microsoft is proposing a shift toward a new security "control plane" centered on the network. Unlike endpoint-based controls, network-level protections "operate around workloads rather than inside them," allowing defenses to be applied without waiting for patches to be deployed or applications to be modified, Sakhnov wrote. The objective isn't to avoid patching, but to create a meaningful layer of defense during the period when patching hasn't yet been completed. Mehrotra said security teams should prioritize vulnerabilities that are actively exploited and externally exposed, then use segmentation, traffic controls, WAF/IPS policies, or temporary isolation until patches can be deployed safely. However, she noted that effective real-time containment depends on accurate asset inventories, exposure mapping, traffic visibility, application context, and centralized policy enforcement. Bhupendra Chopra, co-founder and CRO at Kanerika, said most large enterprises don't have one accurate view of their own systems, with asset records sitting in different tools that don't talk to each other.
Microsoft emphasized that in this new reality, organizations can't rely on patching alone, and security strategies must combine strong patch management practices with compensating controls capable of responding at machine speed. Mehrotra warned that network-based containment can miss unmanaged, encrypted, identity-based, or alternative attack paths, and that overly broad controls can disrupt legitimate business services. Organizations should view containment as a way to reduce immediate exposure and buy time, not as a replacement for permanent patching, she said. Sakhnov wrote that the future of cybersecurity will depend on an organization's ability to reduce risk during the time between disclosure and remediation. The tension here cuts deeper than tooling—it forces security leaders to confront whether their risk tolerance and change approval processes still match the threat environment they're actually defending against, and whether temporary protections that were meant to buy days end up becoming permanent technical debt no one owns.

