Patching alone isn’t enough

Layered cyber security: Why patching alone isn’t enough in an AI-accelerated threat landscape
Most Australian businesses know they need to patch. Operating systems are kept current, business software gets updated, and someone on the IT side keeps an eye on the patch backlog. For years, that was the foundation of being “secure enough” for an SME.
That foundation is shifting. The window between a vulnerability being disclosed and an exploit being available has collapsed, and AI is making it shrink faster. Patches still matter, but they don’t carry the same weight they used to.
Treating patching as the centre of a security program made sense when attackers needed weeks or months to weaponise a vulnerability. It makes less sense in 2026, where exploits are arriving before patches and being deployed at scale within days. The useful question now is what happens when patching isn’t fast enough.
The patching problem most people overlook
Patching is good and necessary. The question is whether patching can do the job on its own.
There’s a structural limit to how fast any business can patch. Patches need to exist (vendors have to release them). Patches need to be tested in your environment so they don’t break things. Patches need a deployment window that doesn’t disrupt the business. Even with strong tooling and discipline, that cycle is measured in days at best.
The attacker side of that equation has been moving the other way. Mandiant’s 2026 M-Trends report found that close to a third of disclosed vulnerabilities are now exploited within 24 hours of going public. For some vulnerability categories, exploits are arriving before the patches do.
How AI changed the math
AI hasn’t created new categories of attack. It’s made the old categories cheaper, faster, and more scalable.
Verizon’s 2026 Data Breach Investigations Report identified vulnerability exploitation as the leading initial access vector in breaches, overtaking stolen credentials for the first time. Among the techniques AI is being used to scale, exploit development sits at 32 percent of cases.
Rapid7’s 2026 threat landscape report adds another angle: the number of high and critical-severity vulnerabilities being actively exploited more than doubled from 2024 to 2025. Most of what attackers are weaponising isn’t novel or sophisticated. It’s well-understood, well-documented, and now well-automated.
For a small or mid-sized business, patch velocity is no longer the variable that determines whether an attack succeeds. The gap between disclosure and exploitation is shrinking faster than any patch cycle can close it.
Defence in depth: The shift to proactive controls
The ACSC’s Essential Eight has always been a layered framework. It was designed to work as a whole, not as a checklist where each control is optional.
In most Australian businesses, the easier controls have been adopted first. Multi-factor authentication is widespread. Backups are usually in place. Operating systems are usually patched. The harder controls, the ones that change how users and applications interact with the system, are often deferred.
Those harder controls are where layered security earns its place. Application control and restricting administrative privileges are both proactive. They don’t wait for a vulnerability to be discovered. They reduce the damage a vulnerability can do, whether the patch is available or not.
A reactive control depends on knowing about the threat. A proactive control assumes the threat will get through and limits what it can do.
Application allow listing: Choosing what runs, not what to block
Traditional security tools work by recognising bad things and blocking them. Antivirus, threat detection, and email filtering all start by trying to identify a signature, behaviour, or pattern that’s known to be malicious.
That model breaks down when attackers can generate new variants faster than defenders can categorise them. AI accelerates that gap further.
Application allow listing flips the question. Instead of asking “is this application bad”, the system asks “is this application approved”. Anything that isn’t on the approved list cannot execute, regardless of whether it’s known to be malicious or has never been seen before. A new exploit can still land on a device, but the malicious payload cannot run.
The ACSC ranks application control as the first of the Essential Eight. Done properly, it removes whole categories of risk that would otherwise need to be handled one threat at a time.
Elevation control: Removing the easy path
To encrypt files, disable backups, install persistent malware, or move laterally across a network, attackers need elevated privileges. In a typical attack chain, that’s the step that turns a foothold into a broader compromise.
In many SMEs, those privileges are easier to come by than they should be. Long-tenured staff sometimes hold local admin rights from when they were needed for a specific task and never reviewed. Service accounts with elevated permissions sit on devices long after the original use case has ended. IT teams give themselves admin access on user workstations to make support easier.
Elevation control changes the default. Users operate with standard permissions for day-to-day work, and elevated rights are granted only when a specific approved task requires them. Those elevations are time-bound, logged, and reviewable.
The effect is to narrow the blast radius of any compromise. If a phishing attack lands on a user’s machine and that user doesn’t have admin rights, the attack has further to climb before it can spread or persist.
What this looks like in an Australian context
Australian regulators and cyber insurance underwriters are responding to the same shift.
The Cyber Security Act 2024 moved from its education phase into its enforcement phase on 1 January 2026, with reporting requirements that put cyber incidents firmly on the executive agenda. Cyber insurance underwriters are asking more detailed questions about controls and pricing more aggressively for businesses without them. Recent ACSC guidance has signalled that application control is moving from recommended to expected for any business operating in sectors with sustained ransomware pressure.
Maturity Level Two of the Essential Eight is increasingly the baseline that defence supply chains, larger customers, and insurers want to see. That includes application control implemented in a way that actually stops unapproved execution, not just monitored alerts on it.
A short layered security check
Before deciding what to do next, it’s worth checking where the business currently stands.
- How quickly can the business deploy a critical patch end to end?
- Which user accounts have administrative rights, and which of those rights are actually needed?
- If a user opened a malicious file today, what would stop the payload from executing?
- How often is the list of approved applications reviewed?
- Who owns the layered security plan, beyond the patching schedule?
These questions don’t need formal answers right away. Working through them surfaces where the business is most exposed and where layering would help most. An independent IT security assessment is often the cleanest way to get those answers in one place.
Better foundations make patching less of a single point of failure
Patching will continue to matter. It will keep being a core discipline of any sensible security program. What’s changed is the weight it can carry on its own.
The businesses that hold up well in this environment will be the ones that treat patching as one layer among several, not as the layer. Application control, elevation control, identity discipline, network segmentation, monitored detection, and tested recovery all work together. Each layer has limits on its own. Used together, they reduce both the likelihood of an incident and the damage if one occurs.
This isn’t about spending more for the sake of it. It’s about funding the right work, in the right order, with a clear view of where the business is most exposed.
How do we get started?
The easiest first step is a short conversation about how your current controls hold up against today’s threat landscape. We’ll look at where patching is doing its job, where layered controls would add the most value, and what a sensible roadmap looks like for the year ahead.
Get in touch with us to start the conversation.



