Patch, Mitigate, or Accept: How to Choose a Vulnerability Response

Compare remediation options through exposure, consequence, exploit evidence, control effectiveness, operational cost, reversibility, and residual risk.

The correct vulnerability response is the option that reduces risk to an acceptable level within the available time while avoiding greater operational harm. Patching removes the vulnerable condition when successful. Mitigation interrupts an exploit path or limits consequence. Acceptance records a conscious choice to carry residual risk for a period.

Make the decision per affected service or exposure group; one CVE can justify different responses across assets.

Compare the Real Options

For each option assess time to implement, risk reduction, validation, outage, dependencies, rollback, coverage, durability, attacker adaptation, and cost. Include isolation, feature disablement, access restriction, replacement, and retirement where relevant.

Do not compare a tested patch with a hypothetical mitigation. Require implementation evidence for every option.

Verify the Response Changed Exposure

Confirm deployment, configuration, reachable path, control logs, functional behavior, and detection coverage. Sample assets rather than trusting ticket closure. Preserve exceptions and failed installations.

If accepting, document owner, rationale, affected assets, consequence, controls, expiry, review trigger, and recovery plan. “Cannot patch” is a constraint, not a completed risk decision.

Put Temporary Choices on a Clock

Assign expiry and reassessment triggers to mitigations and acceptances. Monitor exploitation, exposure, control health, vendor fixes, and business change. Escalate when the residual risk no longer fits tolerance.

Use the zero-day response guide for fast-moving cases. A defensible response is explicit, verified, owned, and revisited.

Frequently asked questions

Is patching always the safest response?

No. A patch can create outage or incompatibility, while isolation or a verified mitigation may reduce risk faster; compare total consequence.

When is mitigation enough?

When it demonstrably interrupts the relevant exploit path, is monitored, has an owner and expiry, and leaves residual risk within tolerance.

Who can accept vulnerability risk?

An authorized risk or business owner with enough evidence about exposure, consequence, alternatives, duration, and residual risk.

Does a compensating control remove the vulnerability?

Usually not. It changes exploitability or consequence and must be verified and maintained until the underlying exposure is removed or accepted.

What should reopen the decision?

Exploitation evidence, changed exposure, control failure, asset importance, available fix, passed expiry, or a changed business condition.