Documents the transition of vulnerability management into a 'contractual insurance obligation' with specific 21-45 day brightlines for claim eligibility.
Cyber insurance providers are increasingly implementing 'patch exclusions' and sliding scales that allow them to deny or reduce claims arising from unpatched high-severity vulnerabilities. One major U.S. insurer now excludes losses from CVEs with CVSS > 8.0 if a patch has been available for three weeks and not applied, while Chubb utilizes a 'Neglected Software Exploit Endorsement' with a 45-day grace period followed by incremental risk shifting to the policyholder. Coalition argues these exclusions are often impractical, as over 61,000 vulnerabilities (as of July 2025) fit the CVSS 8.0 criteria, yet only 1% are listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. This regulatory shift creates an 'impossible situation' where firms must either prioritize thousands of low-risk vulnerabilities or face catastrophic loss of insurance coverage after a breach.
Insurers are implementing hard brightlines (e.g., 21 or 45 days) for high-severity patches, beyond which they will not cover breach costs.
total loss of insurance coverage and financial ruin following a breach due to 'neglected' software maintenance
benchmarking a project's fix speed against insurance-standard 21-45 day windows is a requirement for maintaining financial coverage in the modern threat landscape.
Some cyber insurers won’t pay if a claim arises from a vulnerability that’s gone unpatched for a certain number of days... others use a sliding scale.
Risk Guard identifies vulnerabilities but does not track the 'Days Remaining' until an insurance policy's grace period (e.g., 21 days) expires.
Risk Guard would be better if it allowed users to input their 'Insurance Patch SLA' (e.g., 21 days) and provided a countdown timer for all CVSS 8.0+ vulnerabilities.