The 2026 Verizon Data Breach Investigations Report says exploitation of software vulnerabilities now accounts for 31% of breach entry, ahead of stolen credentials. It also reports ransomware in 48% of breaches and generative AI augmenting 15 distinct attack techniques. Those figures are global signals, not a risk score for your organisation, but they should change the order of operations.

The operating changeMove from “severity-only patching” to exposure-led prioritisation: known exploitation, internet reachability, asset importance, identity privilege and available compensating controls.

1. Put exploitation evidence above theoretical severity

A critical score is useful, but it does not tell you whether an issue is being used in the wild. Add CISA's Known Exploited Vulnerabilities catalogue—or an equivalent trusted exploitation feed—to the prioritisation process. An exposed, exploited flaw on an identity system usually deserves attention before a higher-scoring flaw on an isolated test host.

2. Treat the attack surface as inventory, not a scan

Teams need an answer to four questions: what is exposed, who owns it, what software it runs and how quickly it can be changed. Vulnerability discovery without ownership creates a queue; discovery linked to an accountable service creates work.

3. Connect ransomware readiness to recovery evidence

Prevention still matters, but the ransomware signal makes recovery verification non-negotiable. Confirm protected backups, isolated administrative paths, tested restoration and a decision process for containment. A backup job marked “successful” is not the same as a service restored within an acceptable time.

4. Make third-party access visible

Supplier and partner exposure belongs in the same operational view as internal assets. Document remote access, data flows, support identities, contractual notification routes and the fastest way to disable a connection without guessing during an incident.

A practical 30-day move

  1. Export your internet-facing inventory and name an owner for every item.
  2. Overlay known exploitation and active threat intelligence.
  3. Identify systems that combine exposure, privilege and sensitive data.
  4. Set remediation dates with explicit risk acceptance for exceptions.
  5. Run one recovery test and one supplier-access containment exercise.

That is a smaller programme than “fix every vulnerability,” and a more defensible one.