Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Risk-Based Patch Prioritization and Remediation Strategies

Ivanti
09/29/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


is this vulnerability? Well, the fact of the matter is, the majority of the time, that's not the vulnerabilities that you really need to be concerned about. So most of the vulnerabilities that are actively being targeted are not the ones that we're prioritizing response to. This is where getting into more of a risk-based approach to prioritization is required to be able to keep up with that. The remediation cycle is the other important part of this. We need to be able to respond to the higher priority items first. More importantly, though, we have to be able to respond to different tracks of remediation items in parallel. So really what we're ending up with is, call it three different tracks of remediation. My normal routine maintenance that happens once a month, doesn't matter what my SLA is, the priority updates, things like the browser updates or communications applications like Zoom and other things like that, that users are using typically are more highly targeted and need to be responded to on a more frequent basis. And then that zero-day response track. If I've got everything configured properly, all of the updates that come out continuously doesn't matter which type they are, all fall into one of those three priorities and get taken care of in the course of my regular activities that are configured within the systems I'm using.

TL;DR

  • Vendor-assigned severity ratings often fail to identify the vulnerabilities that attackers are actually targeting, creating a dangerous prioritization gap.
  • Risk-based prioritization aligns remediation efforts with real-world threat activity rather than theoretical severity scores.
  • A three-track remediation model—routine maintenance, priority updates, and zero-day response—enables parallel processing of different vulnerability types.

Summary

This brief explainer challenges the conventional approach to vulnerability management, arguing that organizations often misprioritize patches by relying solely on vendor-assigned severity ratings. The speaker contends that most actively exploited vulnerabilities are not the ones receiving immediate attention under traditional prioritization models. Instead, a risk-based approach is essential for aligning remediation efforts with actual threat activity. The video introduces a three-track remediation framework: routine monthly maintenance for standard updates, priority updates for frequently targeted applications like browsers and communication tools such as Zoom, and a dedicated zero-day response track for critical emerging threats. When properly configured, this parallel processing model ensures that all updates automatically flow into the appropriate priority track and are addressed through regular operational workflows. The approach emphasizes that effective patch management requires both smarter prioritization based on real-world exploitation data and the operational capability to handle multiple remediation streams simultaneously.

Chapters

0:00 - The Prioritization Problem
0:23 - Risk-Based Approach
0:32 - Three-Track Remediation Model

Key Quotes

0:09 "The fact of the matter is, the majority of the time, that's not the vulnerabilities that you really need to be concerned about."
0:16 "Most of the vulnerabilities that are actively being targeted are not the ones that we're prioritizing response to."
0:23 "This is where getting into more of a risk-based approach to prioritization is required to be able to keep up with that."

FAQ

Why shouldn't organizations rely solely on vendor severity ratings for patch prioritization?

Vendor severity ratings reflect theoretical risk, not real-world exploitation. The speaker notes that most actively targeted vulnerabilities are not the ones receiving priority response under traditional models, meaning organizations may be patching lower-risk items while leaving exploited vulnerabilities unaddressed.

What are the three remediation tracks recommended in this approach?

The framework includes routine monthly maintenance for standard patches, a priority track for frequently targeted applications like browsers and Zoom that need more frequent updates, and a zero-day response track for critical emerging threats requiring immediate action.


Categories:
  • » Webinar Library » Ivanti
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Vulnerability Management
  • Best Practices
  • Security Operations
  • Risk-based vulnerability prioritization
  • Patch management strategy
  • Remediation workflows
  • Zero-day response
  • Vulnerability management
  • Security operations
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Risk-Based Patch Prioritization and Remediation Strategies

              Industry Events (Sponsor Hosted)

              • Oct
                01

                Meta Muse 101: Embracing the Arrival of the Agentic Internet. What's Next?

                10/01/202601:00 PM ET
                • Oct
                  13

                  Interactive Q&A Session on DatasecAI 2026 Insights and Innovations

                  10/13/202602:00 PM ET
                  • Oct
                    15

                    Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                    10/15/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: A Comprehensive Approach to Visibility and Control
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-a-comprehensive-approach-to-visibility-and-control/
                    • 10/01/2026
                      01:00 PM
                      10/01/2026
                      Meta Muse 101: Embracing the Arrival of the Agentic Internet. What's Next?
                      https://www.truthinit.com/index.php/channel/2144/meta-muse-101-embracing-the-arrival-of-the-agentic-internet-whats-next/
                    • 10/13/2026
                      02:00 PM
                      10/13/2026
                      Interactive Q&A Session on DatasecAI 2026 Insights and Innovations
                      https://www.truthinit.com/index.php/channel/2141/interactive-q-a-session-on-datasecai-2026-insights-and-innovations/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 10/20/2026
                      11:00 AM
                      10/20/2026
                      Harnessing Data Governance for AI with Cyera and Snowflake
                      https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                    • 10/27/2026
                      01:00 PM
                      10/27/2026
                      The HUMAN Experience: Real-Time Insights into Page Intelligence
                      https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version