Target Industry
Indiscriminate, opportunistic targeting.
Overview
Cyber insurers are increasingly adding exclusions to their policies for claims linked to unpatched vulnerabilities – especially those classified as Common Vulnerabilities and Exposures (CVEs). For example, one US insurer excludes coverage for CVEs with a CVSS score above 8.0 if a patch has been available for three weeks but not applied. In July there were over 61,000 vulnerabilities that met this benchmark, though only around 1% are listed in the Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities catalogue. With over 40,000 new vulnerabilities emerging annually, keeping systems fully patched is becoming increasingly difficult.
Impact
Unpatched CVEs can lead to serious consequences, including financial loss, operational disruption, and reputational damage. Insurers may reject claims stemming from these vulnerabilities, pushing organisations to invest more in patch management or risk losing coverage. This is especially critical for larger firms, where the cost and complexity of breaches are rising.
Exploitation
Threat actors often exploit known vulnerabilities to gain unauthorised access. Techniques include phishing, exploiting misconfigurations, and using automated tools to identify and attack unpatched systems.
Containment, Mitigations & Remediations
To reduce risk, organisations should:
- Implement a robust patch management policy
- Use threat intelligence to prioritise critical vulnerabilities
- Apply compensating controls where patching isn’t immediately possible
- Provide regular security training to staff.
Threat Landscape
Cyberattacks targeting unpatched vulnerabilities are on the rise, with ransomware and business email compromise being common. Attackers are financially motivated and increasingly sophisticated, making strong cybersecurity measures essential.
Threat Group
Groups exploiting these vulnerabilities include organised cybercriminals and state-sponsored actors. They often target high-value sectors like critical infrastructure, using advanced tactics and techniques to breach defences.
Further Information
Intelligence Terminology Yardstick













