🔴 Under active attack? Get connected to an incident response team now — Get Emergency Help →
Patch what faces the internet first: prioritizing the edge attackers actually hit
Defense & Hardening

Patch what faces the internet first: prioritizing the edge attackers actually hit

ERD Research TeamJun 16, 20266 min read

Key takeaways

  • A large share of enterprise breaches begin with an unpatched internet-facing device — VPNs, firewalls, and remote-access appliances.
  • Patch by exposure and exploitation, not by CVSS score alone: an exploited flaw on an edge device beats a theoretical critical buried inside.
  • You can't defend what you haven't inventoried — an accurate external attack-surface picture is the prerequisite.

The edge is where initial access lives

Ransomware crews and the access brokers who feed them love internet-facing appliances: VPN concentrators, firewalls, file-transfer tools, and remote-access gateways. These devices are exposed to the whole internet by definition, often run software that's hard to patch on a normal cadence, and when a vulnerability drops, mass exploitation begins within days — sometimes hours. A meaningful share of enterprise breaches trace back to one of these devices left unpatched past that window.

Prioritize by exploitation, not just severity

You cannot patch everything immediately, so triage matters — but CVSS score alone is the wrong sort. A 'critical' vulnerability on an internal system with no known exploit is less urgent than a 'high' on your internet-facing VPN that is being actively exploited in the wild right now. Blend three factors: is it internet-facing, is it being exploited, and how central is the device. Public catalogs of known-exploited vulnerabilities are built for exactly this and belong at the top of your prioritization.

You can't patch what you can't see

The prerequisite for all of this is an accurate inventory of what you actually expose. Most organizations have forgotten edge devices — a test VPN, a legacy appliance, a vendor's remote-access box — that never make it onto the patch schedule because nobody remembers they're there. An external attack-surface view, refreshed regularly, turns 'we think we patched the important ones' into a defensible list. The device you didn't know was internet-facing is the one that gets you.

When you can't patch fast enough

Sometimes a fix isn't available or can't be deployed in time. That's when compensating controls earn their keep: restrict the device's exposure to known source addresses, put it behind an authenticated broker, increase monitoring on it, or take a non-essential service offline until it's patched. The goal is to shrink the window between disclosure and mitigation — because on the internet-facing edge, that window is measured against an adversary who is already scanning for you.

We respect your privacy

We use analytics cookies to understand how visitors use this site and improve our defense resources. No advertising or cross-site tracking. Privacy Policy