Endpoint protection and patching

What is the critical patching target (24h / 72h / 7d / >7d)?

This answer is a commitment, not a description. Whatever number you write becomes the standard you are measured against after a loss.

Partly verifiable from your tenant

What the carrier is actually asking

The carrier wants the deadline for remediating critical-severity vulnerabilities, usually offering brackets. It is asking about the actual practice rather than the policy target, and the difference between those two is where the exposure lives.

Why it is underwritten

Exploit code for critical vulnerabilities in internet-facing software now appears within days and sometimes hours. The interval between disclosure and remediation is a directly measurable predictor of compromise, so carriers use it as a rating input and, for some classes of insured, as a condition.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Meeting the target is demonstrated by measurement over time, not by the policy that states it.

PlatformWhere the setting livesWhat has to be true
AzureVulnerability findings with first-detected and resolved timestampsTime-to-remediate for critical findings, measured rather than estimated
AzureDefender for Cloud secure score history and recommendation ageingWhether critical recommendations close inside your stated window or age past it
Microsoft 365Expedited update deployment capability for endpointsA mechanism exists to push an out-of-band update quickly, since a seventy-two hour target needs a path that does not wait for the next ring
Change processEmergency change route for security patchesA defined path that does not require a weekly change advisory board, since a monthly board makes a short target impossible
Vulnerability programmeReporting on met and missed targets by periodA record showing the target is met most of the time, with exceptions explained. Attested
Pick the number you actually meet

Twenty-four hours reads well on an application and is very hard to sustain across an estate. If your record shows five days, writing seven creates a defensible position while writing one creates a representation you will fail. Carriers reward the honest number far more than they reward the aggressive one.

What a defensible yes requires

  • The stated window is supported by measured remediation times over at least a quarter.
  • An emergency change path exists that can move faster than the routine cycle.
  • Internet-facing systems are prioritised ahead of internal ones within the same window.
  • Exceptions are recorded with compensating controls rather than being silently missed.
  • The target covers third-party and appliance firmware, not only operating systems.

How this answer goes wrong

The number written on the form is aspirational, and there is no measurement behind it. In a claims review the adjuster asks for evidence that the window was met for the specific vulnerability exploited, and the absence of any measurement makes the original answer unsupportable. The second failure is scope: the target applies to servers and not to the appliance that was actually exploited.

Frequently asked

Is 24 hours realistic?

For a small internet-facing estate with strong automation, yes. Across a mixed estate with change control and appliances, rarely. Match the answer to the systems that matter most and say so.

What counts as critical?

Define it. Most organisations use a severity score threshold, and adding known-exploited status as an accelerator is a stronger design because it prioritises what is actually being used against you.

Do compensating controls buy time?

They do, when they are real and documented: blocking exposure at the edge, disabling the vulnerable feature, isolating the system. Record them as an exception with an end date rather than treating the deadline as met.

How do we evidence this?

A report of critical findings with detection and remediation dates for the last few quarters. It is the single most convincing artefact behind this answer.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture