Back to the threat counter
Threat brief

Unpatched vulnerabilities. The open door.

Every connected system carries vulnerabilities. The question is not whether they will be found, but whether you patch before somebody exploits them.

The headline number

60%

of breaches exploit unpatched vulnerabilities

Average time to patch
97 days
Patch within 24 hours
10%
CVEs published in 2024
28,000+

97 days

Average time to patch critical flaws

10%

Organisations patching within 24 hours

60%

Breaches involving unpatched flaws

28,000+

CVEs published in 2024

Vulnerability types

Every connected system has weaknesses

Four classes of weakness, each with a different window between discovery and exploitation.

Zero-Day Exploits

Time to exploit: < 24 hours

Unknown vulnerabilities discovered and exploited before vendors can issue patches. Organisations are defenceless until a fix is released.

Example: MOVEit (2023) - Zero-day in file transfer software exposed 77M+ people

Known Vulnerabilities

Time to exploit: 15 days average

Patches exist but are not applied. The average time to exploit a known vulnerability is just 15 days, faster than most patch cycles.

Example: Log4Shell - Critical vulnerability, many systems still unpatched a year later

Misconfigurations

Time to exploit: Immediate

Open ports, default credentials, exposed admin panels. These are not bugs. They are setup mistakes that create easy entry points.

Example: Microsoft Power Apps - 38M records exposed via misconfigured portals

Legacy Systems

Time to exploit: Permanent risk

End-of-life software receiving no security updates. Many critical systems run on Windows 7, XP, or even older platforms.

Example: WannaCry - Exploited Windows XP systems still running in NHS hospitals

Recent exploits

Vulnerabilities under active exploitation

MOVEit Transfer

CVE-2023-34362

77 million individuals affected

Victims

2,600+ organisations

Citrix NetScaler

CVE-2023-4966

Session hijacking and data theft

Victims

Major corporations

FortiOS SSL VPN

CVE-2022-42475

Remote code execution

Victims

Government agencies

You cannot patch fast enough. Disconnect instead.

With more than 28,000 new vulnerabilities published each year, patching is an endless race. Offline Secure Storage® removes the attack surface, so there is nothing on the network to exploit.

Mark Fermor
David Bailey
Kenny Phipps
Online Now
Concierge

Which offline secure storage solution is right for you?

Answer a few quick questions and we will recommend the right solution, whether that is a personal vault or a scalable offline storage system built for your needs.

Takes about 2 minutes. No account needed.

Free2 minsNo sign-up