When The Patch Tsunami Meets The Maintenance Window
CSO Online, Wednesday, September 2nd, 2026
AI-speed vulnerability discovery has broken OT patch cycles; triage, containment and surge planning matter more than patching faster.
Models can now surface exploitable flaws in hours rather than the roughly 60 days human researchers needed, but remediation in operational technology still runs at plant speed.
Patches can reboot controllers, changes near safety systems carry their own hazards, OEM validation takes weeks to months, and much legacy equipment has no update path at all.
The author's prescription is three shifts: triage on exploitation evidence, real asset exposure and operational consequence rather than CVSS alone; contain with segmentation, allow-listing and virtual patching where patching is not feasible; and pre-negotiate emergency maintenance windows while rehearsing multi-advisory scenarios before a crisis.