The Patch Window Just Closed. Here's What Comes Next.
Cisco, Friday, August 28th, 2026
Cisco argues time-to-exploitation has gone negative and positions MSPs running the NOC to close the gap with VulnOps.
Cisco argues something has shifted in the vulnerability landscape that most of the industry is still not acting on.
For years vulnerability management rested on the comfortable assumption that defenders and attackers moved at roughly human speed, which gave organizations a patch window between disclosure and exploitation.
That window has now closed, with time-to-exploitation effectively going negative as exploitation precedes disclosure. The post makes the case that managed service providers who run the network operations center are best placed to close the resulting gap, and introduces VulnOps as the operating model for doing so.