Vulnerability Remediation Timelines: how fast should you patch?

This is a collection of statistics I gather on the topic of vulnerability remediation timelines.

Vulnerability remediation timelines

SourceMetricRemediation timeline
CISACritical vulnerabilities15 days
EdgeScan’s 2022 reportAverage MTTR for Public Administration Industry89 days
EdgeScan’s 2022 reportAverage MTTR for Manufacturing Industry81 days
EdgeScan’s 2022 reportAverage MTTR for Education Services Industry81 days
EdgeScan’s 2022 reportAverage MTTR for Professional, Scientific & Technical Services Industry69 days
EdgeScan’s 2022 reportAverage MTTR for Accommodation & Food Services Industry68 days
EdgeScan’s 2022 reportAverage MTTR for Healthcare Industry63 days
EdgeScan’s 2022 reportAverage MTTR for Information Industry57 days
EdgeScan’s 2022 reportAverage MTTR for Retail Industry55 days
Mend.io (2023)Average time to fix a vulnerability271 days
Mend.io (2023)Average time to fix a vulnerability with Mend (from Sample of companies that have implemented Mend) 70 days
Infosec InstituteMTTR for vulnerabilities (general)60 to 150 days
GitlabSLA for critical vuln remediation30 days
IvantiSLA for critical vuln remediation14 days
U.S. General Services AdministrationCritical and High vulnerabilities30 days
New York UniversitySLA for critical vuln remediation30 days
University of MichiganSLA for critical vuln remediation30 days
UCLASLA for critical vuln (Severity 5 in Qualys)14 days
NASA’s Software Engineering HandbookVulnerabilities categorized as high5 working days
NASA’s Software Engineering HandbookVulnerabilities categorized as moderate30 working days
NASA’s Software Engineering HandbookVulnerabilities categorized as low60 working days
Google’s Project ZeroVulnerabilities with CVSS score more than 4.090 days
Automox 2020 Cyber Hygiene ReportLargest group of respondents’ average patching time for critical and high severity vulnerabilities
(Across all four categories of systems that they surveyed this was the remediation time followed by the largest set of respondents)
4 – 30 days
FedRampMitigation of high-risk vulnerabilities30 days
FedRampMitigation of moderate-risk vulnerabilities90 days
FedRampMitigation of low-risk vulnerabilities180 days

Sources

Leave a Comment

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply