Target Industry

Indiscriminate, opportunistic targeting.

Overview

Cyber insurers are increasingly adding exclusions to their policies for claims linked to unpatched vulnerabilitiesespecially those classified as Common Vulnerabilities and Exposures (CVEs). For example, one US insurer excludes coverage for CVEs with a CVSS score above 8.0 if a patch has been available for three weeks but not applied. In July there were over 61,000 vulnerabilities that met this benchmark, though only around 1% are listed in the Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities catalogue. With over 40,000 new vulnerabilities emerging annually, keeping systems fully patched is becoming increasingly difficult. 

Impact

Unpatched CVEs can lead to serious consequences, including financial loss, operational disruption, and reputational damage. Insurers may reject claims stemming from these vulnerabilities, pushing organisations to invest more in patch management or risk losing coverage. This is especially critical for larger firms, where the cost and complexity of breaches are rising. 

Exploitation

Threat actors often exploit known vulnerabilities to gain unauthorised access. Techniques include phishing, exploiting misconfigurations, and using automated tools to identify and attack unpatched systems. 

Containment, Mitigations & Remediations

To reduce risk, organisations should: 

  • Implement a robust patch management policy 
  • Use threat intelligence to prioritise critical vulnerabilities 
  • Apply compensating controls where patching isn’t immediately possible 
  • Provide regular security training to staff. 

Threat Landscape

Cyberattacks targeting unpatched vulnerabilities are on the rise, with ransomware and business email compromise being common. Attackers are financially motivated and increasingly sophisticated, making strong cybersecurity measures essential. 

Threat Group

Groups exploiting these vulnerabilities include organised cybercriminals and state-sponsored actors. They often target high-value sectors like critical infrastructure, using advanced tactics and techniques to breach defences. 

Further Information

Intelligence Terminology Yardstick

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content