CISO Tradecraft®

#257 - Patch or Perish (with Ross Young)

Nov 3, 2025
Ross Young, an experienced cybersecurity leader and former CIA operator, shares his insights on effective vulnerability management. He reveals a shocking 300-day patching backlog he encountered, emphasizing the growing threat of vulnerabilities exacerbated by AI. Ross proposes a comprehensive framework that combines people, processes, and tools to foster accountability and efficiency in patching. He discusses how integrating AI can drastically reduce remediation times, ensuring organizations can swiftly adapt to emerging threats.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

Hidden Patch Debt Revealed

  • Ross Young discovered his predecessor reported 99% patching while only showing Windows endpoints, revealing 350 days of unpatched systems and legacy Oracle 9.
  • He used Qualys to uncover the true state and then set out to overhaul the program to reduce patch cycles to 30 days.
INSIGHT

Vulnerability Volume Is Exploding

  • Published CVEs have more than doubled from ~18.5k in 2020 to ~40k in 2024, dramatically increasing remediation workload.
  • Ross Young highlights a 38% year-over-year growth in Q1 2025, stressing patch SLAs are now much harder to meet.
INSIGHT

AI Lowers Barrier To Exploitation

  • AI can dramatically speed exploit development; a study weaponized ~51% of sampled CVEs and produced exploits cheaply and fast.
  • Ross Young warns that previously acceptable SLAs (e.g., 30 days) may become obsolete as attackers can automate exploits in hours.
Get the Snipd Podcast app to discover more snips from this episode
Get the app