



Every week, hundreds of new Common Vulnerabilities and Exposures (CVEs) are published. Security researchers, vendors, and threat-intelligence feeds push alerts continuously. For an Indian enterprise CISO managing hundreds of servers, dozens of network devices, and a mix of cloud and on-premises workloads, the sheer volume is paralysing. The real danger is not a lack of information — it is the inability to separate what must be patched today from what can wait until next quarter.
This guide presents a structured, 72-hour patch prioritisation framework built for the realities of Indian enterprise environments: stretched IT teams, mixed OT/IT infrastructure, DPDP Act obligations, and CERT-In’s mandatory 6-hour breach-reporting window. At PJ Networks, this framework underpins the vulnerability management lifecycle we run for our managed-security clients across BFSI, manufacturing, healthcare, and government sectors.
A recent survey of mid-to-large Indian enterprises revealed that the average time to patch a critical vulnerability after public disclosure is over 21 days. Threat actors — particularly ransomware groups — have operationalised CVE exploitation within 48 to 72 hours of a public PoC (proof-of-concept) being released. That gap between 72 hours and 21 days is where breaches happen.
The root causes are consistent across organisations:
Effective vulnerability management starts not with scanning but with knowing what you own. Before your first scan, every asset must be classified across two dimensions:
An internet-facing Tier 1 asset with a critical CVE is an emergency. An air-gapped Tier 3 asset with the same CVE may wait for the monthly patch cycle. This two-axis classification matrix — combined with real threat-intelligence data — is the core of risk-based vulnerability prioritisation.
PJ Networks Insight: Our managed FortiGate deployments give clients continuous visibility into their network topology, making asset classification an automated, living process rather than a one-time spreadsheet exercise. The FortiGate Security Fabric maps asset relationships and flags new or unmanaged devices as they appear on the network.
When a significant CVE is published — or when your vulnerability scanner surfaces a critical finding — the clock starts. Here is how we structure the response.
Raw CVSS scores are a starting point, not a verdict. During the first four hours, the goal is to contextualise the vulnerability against your specific environment:
The output of this phase is a prioritised list: Emergency (patch or mitigate within 24 hours), High (within 72 hours), Medium (within 30 days), Low (next scheduled patch cycle).
For Emergency-tier vulnerabilities, waiting for a vendor patch is rarely acceptable. While the patch is sourced, tested, and scheduled, interim mitigations must be deployed immediately:
Vendor patches should be tested in a staging environment before production deployment. The 72-hour window assumes a fast-track process for critical patches — not a bypass of testing, but a compressed testing cycle:
India’s CERT-In mandates that organisations report cybersecurity incidents — including exploitation of vulnerabilities — within 6 hours of discovery. This requirement makes vulnerability management a compliance issue, not just a security one.
The DPDP Act (Digital Personal Data Protection Act, 2023) adds another layer: any data breach resulting from an unpatched vulnerability must be reported to the Data Protection Board. Fines under the DPDP Act can reach ₹250 crore per violation.
For Indian CISOs, this means vulnerability management documentation is as important as the remediation itself. Your 72-hour framework must include:
Regulatory Note: CERT-In’s April 2022 directive also requires organisations to maintain logs for 180 days and report unauthorised access, malware infections, and data breaches. An unpatched, exploited vulnerability that results in unauthorised access triggers this reporting obligation immediately.
The 72-hour framework handles acute situations. Alongside it, Indian enterprises need a continuous vulnerability management programme that prevents the backlog from accumulating in the first place.
Track these KPIs monthly and report them to your board or audit committee:
Vulnerability management data must feed your Security Operations Centre. When your SOC receives an alert about suspicious traffic from a particular host, they need to know immediately whether that host has unpatched critical vulnerabilities. This context transforms a generic alert into a high-priority incident.
At PJ Networks, our integrated NOC/SOC platform correlates FortiGate traffic logs, vulnerability scanner data, and threat-intelligence feeds in real time. When a host with an open critical CVE begins exhibiting anomalous outbound traffic, the alert is automatically escalated — not buried in a queue of low-priority events.
For Indian manufacturing, energy, and utilities organisations operating OT/ICS environments, the standard patch framework requires adaptation. Patching a Programmable Logic Controller (PLC) or a SCADA historian is not like patching a Windows Server:
PJ Networks’ OT security practice deploys dedicated FortiGate OT-edition firewalls between IT and OT network segments, providing virtual patching and deep-packet inspection for industrial protocols (Modbus, DNP3, EtherNet/IP) while OT systems await certified patches.
Building an in-house vulnerability management programme requires specialised tooling (vulnerability scanners, asset inventory platforms, ticketing integration), trained analysts who can interpret CVE data in business context, and 24/7 coverage to respond when critical CVEs drop outside business hours — a common occurrence since major CVE disclosures often coincide with Patch Tuesday or international security conference schedules.
For most Indian enterprises outside the largest banks and IT companies, building this capability in-house costs ₹1.5–3 crore annually in tooling and headcount, with no guarantee of the expertise depth needed to manage complex, mixed IT/OT environments.
Managed vulnerability management — delivered as part of a broader MSSP engagement — provides access to dedicated vulnerability analysts, enterprise-grade tooling, threat-intelligence subscriptions, and 24/7 coverage for a fraction of that cost, with contractual SLAs tied directly to MTTR targets.
Use this checklist to assess your current programme maturity:
PJ Networks delivers end-to-end managed vulnerability management as part of our 24/7 NOC/SOC services for Indian enterprises. Our offering includes continuous vulnerability scanning across IT and OT environments, risk-based prioritisation using threat intelligence tuned for the Indian threat landscape, FortiGate IPS virtual patching for emergency-tier CVEs, and a dedicated vulnerability management analyst team available around the clock.
We integrate directly with your existing ITSM platform to automate patch ticket creation, tracking, and SLA reporting — giving your internal team full visibility without the manual overhead. Our CERT-In and DPDP Act compliance reporting templates ensure your documentation meets regulatory requirements from day one.
If your current vulnerability management programme is reactive, backlogged, or siloed from your SOC operations, we can assess your maturity and build a roadmap to a risk-based, continuous programme — typically within 30 days of engagement start.
Contact PJ Networks today to schedule a no-obligation vulnerability management maturity assessment for your organisation. Our team is available at pjnetworks.com or through your existing account manager.