What is the critical patching target (24h / 72h / 7d / >7d)?
This answer is a commitment, not a description. Whatever number you write becomes the standard you are measured against after a loss.
What the carrier is actually asking
The carrier wants the deadline for remediating critical-severity vulnerabilities, usually offering brackets. It is asking about the actual practice rather than the policy target, and the difference between those two is where the exposure lives.
Why it is underwritten
Exploit code for critical vulnerabilities in internet-facing software now appears within days and sometimes hours. The interval between disclosure and remediation is a directly measurable predictor of compromise, so carriers use it as a rating input and, for some classes of insured, as a condition.
Where the answer lives in Microsoft 365, Entra ID, and Azure
Meeting the target is demonstrated by measurement over time, not by the policy that states it.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Azure | Vulnerability findings with first-detected and resolved timestamps | Time-to-remediate for critical findings, measured rather than estimated |
| Azure | Defender for Cloud secure score history and recommendation ageing | Whether critical recommendations close inside your stated window or age past it |
| Microsoft 365 | Expedited update deployment capability for endpoints | A mechanism exists to push an out-of-band update quickly, since a seventy-two hour target needs a path that does not wait for the next ring |
| Change process | Emergency change route for security patches | A defined path that does not require a weekly change advisory board, since a monthly board makes a short target impossible |
| Vulnerability programme | Reporting on met and missed targets by period | A record showing the target is met most of the time, with exceptions explained. Attested |
Twenty-four hours reads well on an application and is very hard to sustain across an estate. If your record shows five days, writing seven creates a defensible position while writing one creates a representation you will fail. Carriers reward the honest number far more than they reward the aggressive one.
What a defensible yes requires
- The stated window is supported by measured remediation times over at least a quarter.
- An emergency change path exists that can move faster than the routine cycle.
- Internet-facing systems are prioritised ahead of internal ones within the same window.
- Exceptions are recorded with compensating controls rather than being silently missed.
- The target covers third-party and appliance firmware, not only operating systems.
How this answer goes wrong
The number written on the form is aspirational, and there is no measurement behind it. In a claims review the adjuster asks for evidence that the window was met for the specific vulnerability exploited, and the absence of any measurement makes the original answer unsupportable. The second failure is scope: the target applies to servers and not to the appliance that was actually exploited.
Frequently asked
Is 24 hours realistic?
For a small internet-facing estate with strong automation, yes. Across a mixed estate with change control and appliances, rarely. Match the answer to the systems that matter most and say so.
What counts as critical?
Define it. Most organisations use a severity score threshold, and adding known-exploited status as an accelerator is a stronger design because it prioritises what is actually being used against you.
Do compensating controls buy time?
They do, when they are real and documented: blocking exposure at the edge, disabling the vulnerable feature, isolating the system. Record them as an exception with an end date rather than treating the deadline as met.
How do we evidence this?
A report of critical findings with detection and remediation dates for the last few quarters. It is the single most convincing artefact behind this answer.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture