Anton Chuvakin, Security Advisor at Google Cloud, made this point in a CISO Platform session on practical AI in cybersecurity, in conversation with David Randleman, Field CISO at FireCompass. It has nothing to do with AI and everything to do with how security policy is written: most patching policies are worded in a way that guarantees the organization is out of compliance with its own rules every single day.

Absolute patching deadlines put you in permanent violation. Chuvakin described the policy language he saw repeatedly during his Gartner years: critical vulnerabilities patched in 10 days, high in 30, low never. Read literally, that policy is broken the moment a single critical finding sits unpatched past day 10. Not occasionally. Continuously.

The gap is operational reality, not negligence. His example is deliberately mundane. A critical vulnerability lands on the laptop of an employee who is twelve days into a vacation. There is no team, no budget, and no tooling that patches that machine inside the 10-day window. The policy did not account for the world it was written for, so the failure is structural rather than a matter of effort or discipline.

Percentages turn an unmeetable rule into a real SLA. Chuvakin’s fix is to change the sentence, not the target: "How about you say we patch 97% of critical within 10 days." The number becomes something a team can hit, report against, and defend. It also makes the residual 3% visible and discussable instead of hiding it inside a rule everyone quietly knows is fictional.

Why this matters for CISOs

A policy nobody can meet is worse than no policy. It gives auditors a standing finding, it gives the board a metric that is always red, and it trains your own team to treat the written rule as decoration. Rewriting patching commitments as percentage-based service levels changes what you report upward: instead of explaining why you are non-compliant again, you are reporting a coverage rate against a threshold you set deliberately. That is a conversation about risk appetite, which is the conversation you want to be having with the board and with your auditors.

It also changes what you buy and how you staff. If the target is 97% of critical findings inside 10 days, you can measure which gaps are tooling problems, which are asset-visibility problems, and which are simply unreachable endpoints. Absolute deadlines flatten all three into one undifferentiated failure.

Over to you

Is your patching policy written as an absolute deadline or as a coverage percentage? And if you have tried moving your organization from one to the other, what did your auditors say about it? That second part is where most people get stuck.

Join the CISO Platform community. Thousands of senior security leaders across North America use CISO Platform to compare notes on exactly these decisions, before they have to defend them to a board. Become a member here and add your view to this discussion.

Source: Practical AI In Cybersecurity, a CISO Platform Best of the World Talks session with Anton Chuvakin, Security Advisor, Google Cloud.

Votes: 0
E-mail me when people leave their comments –

You need to be a member of CISO Platform to add comments!

Join CISO Platform

Join The Community Discussion