Vulnerability Management for Indian Enterprises: A CISO’s 72-Hour Patch Prioritisation Framework

  • Home
  • Vulnerability Management for Indian Enterprises: A CISO’s 72-Hour Patch Prioritisation Framework
Vulnerability Management for Indian Enterprises: A CISO’s 72-Hour Patch Prioritisation Framework
Vulnerability Management for Indian Enterprises: A CISO’s 72-Hour Patch Prioritisation Framework
Vulnerability Management for Indian Enterprises: A CISO’s 72-Hour Patch Prioritisation Framework
Vulnerability Management for Indian Enterprises: A CISO’s 72-Hour Patch Prioritisation Framework
Vulnerability Management for Indian Enterprises: A CISO’s 72-Hour Patch Prioritisation Framework

Every week, hundreds of new Common Vulnerabilities and Exposures (CVEs) are published. Security researchers, vendors, and threat-intelligence feeds push alerts continuously. For an Indian enterprise CISO managing hundreds of servers, dozens of network devices, and a mix of cloud and on-premises workloads, the sheer volume is paralysing. The real danger is not a lack of information — it is the inability to separate what must be patched today from what can wait until next quarter.

This guide presents a structured, 72-hour patch prioritisation framework built for the realities of Indian enterprise environments: stretched IT teams, mixed OT/IT infrastructure, DPDP Act obligations, and CERT-In’s mandatory 6-hour breach-reporting window. At PJ Networks, this framework underpins the vulnerability management lifecycle we run for our managed-security clients across BFSI, manufacturing, healthcare, and government sectors.

Why Most Indian Enterprises Are Failing at Vulnerability Management

A recent survey of mid-to-large Indian enterprises revealed that the average time to patch a critical vulnerability after public disclosure is over 21 days. Threat actors — particularly ransomware groups — have operationalised CVE exploitation within 48 to 72 hours of a public PoC (proof-of-concept) being released. That gap between 72 hours and 21 days is where breaches happen.

The root causes are consistent across organisations:

  • No risk-based prioritisation: Teams patch by CVSS score alone, not by business context. A CVSS 9.8 on an isolated development server is less urgent than a CVSS 7.5 on a payment gateway.
  • Asset inventory gaps: Shadow IT, unmanaged devices, and legacy systems create blind spots. You cannot patch what you do not know exists.
  • Change-management friction: Production patching requires downtime windows, CAB approval, and rollback plans — none of which are available on a 48-hour timeline without pre-built processes.
  • Siloed tooling: Vulnerability scanners, ITSM platforms, and firewall management consoles do not talk to each other, requiring manual correlation.
  • Understaffed security teams: The average Indian enterprise SOC handles vulnerability management alongside incident response, compliance reporting, and routine operations.

The Foundation: Asset Classification Before Vulnerability Scanning

Effective vulnerability management starts not with scanning but with knowing what you own. Before your first scan, every asset must be classified across two dimensions:

Business Criticality (Tier 1–3)

  • Tier 1 – Mission Critical: Payment gateways, core banking systems, ERP production databases, customer-facing APIs, OT/SCADA controllers. Any compromise directly impacts revenue or safety.
  • Tier 2 – Business Important: Internal applications, HR systems, VPN concentrators, collaboration platforms. Compromise disrupts operations but is contained.
  • Tier 3 – Standard: Developer workstations, test environments, print servers. Compromise is inconvenient but low-impact.

Exposure Profile (Internet-Facing vs Internal vs Air-Gapped)

An internet-facing Tier 1 asset with a critical CVE is an emergency. An air-gapped Tier 3 asset with the same CVE may wait for the monthly patch cycle. This two-axis classification matrix — combined with real threat-intelligence data — is the core of risk-based vulnerability prioritisation.

PJ Networks Insight: Our managed FortiGate deployments give clients continuous visibility into their network topology, making asset classification an automated, living process rather than a one-time spreadsheet exercise. The FortiGate Security Fabric maps asset relationships and flags new or unmanaged devices as they appear on the network.

The 72-Hour Patch Prioritisation Framework

When a significant CVE is published — or when your vulnerability scanner surfaces a critical finding — the clock starts. Here is how we structure the response.

Hour 0–4: Triage and Contextualisation

Raw CVSS scores are a starting point, not a verdict. During the first four hours, the goal is to contextualise the vulnerability against your specific environment:

  • Map affected software/firmware versions to your asset inventory. Which specific hosts are running the vulnerable version?
  • Check for active exploitation: Is the CVE listed in CISA’s Known Exploited Vulnerabilities catalogue? Has a PoC been published? Are Indian CERT-In advisories referencing this CVE?
  • Assess compensating controls: Does your FortiGate IPS signature set already block known exploit patterns for this CVE? Is the vulnerable port accessible from the internet?
  • Assign business impact tier: Cross-reference affected assets against your Tier 1–3 classification.

The output of this phase is a prioritised list: Emergency (patch or mitigate within 24 hours), High (within 72 hours), Medium (within 30 days), Low (next scheduled patch cycle).

Hour 4–24: Mitigation for Emergency-Tier Assets

For Emergency-tier vulnerabilities, waiting for a vendor patch is rarely acceptable. While the patch is sourced, tested, and scheduled, interim mitigations must be deployed immediately:

  • FortiGate IPS virtual patching: Deploy IPS signatures that block exploit attempts targeting the CVE. This gives you protection before the underlying software is patched — a critical capability when patch testing takes days.
  • Firewall rule hardening: Restrict access to the vulnerable service to known IP ranges or disable it entirely if not business-critical.
  • WAF rules for web-facing vulnerabilities: If the CVE affects a web application, deploy WAF rules to block malicious request patterns.
  • Network segmentation: If you cannot immediately patch or restrict access, isolate the vulnerable asset using VLAN or micro-segmentation policies to limit lateral movement potential.

Hour 24–72: Patch Deployment for Tier 1 and Tier 2 Assets

Vendor patches should be tested in a staging environment before production deployment. The 72-hour window assumes a fast-track process for critical patches — not a bypass of testing, but a compressed testing cycle:

  • Staged rollout: Deploy to the lowest-risk Tier 2 assets first, monitor for 2–4 hours, then proceed to Tier 1.
  • Rollback plan documented: Every patch deployment must have a rollback procedure ready before execution begins.
  • Change management pre-approval: Maintain an emergency change category in your ITSM tool that allows fast-track approval (single approver, 1-hour SLA) for critical security patches.
  • Post-patch scan: Run a targeted scan on patched assets to confirm the vulnerability is remediated. Do not rely on the patch process alone.

CERT-In Compliance and the 6-Hour Reporting Obligation

India’s CERT-In mandates that organisations report cybersecurity incidents — including exploitation of vulnerabilities — within 6 hours of discovery. This requirement makes vulnerability management a compliance issue, not just a security one.

The DPDP Act (Digital Personal Data Protection Act, 2023) adds another layer: any data breach resulting from an unpatched vulnerability must be reported to the Data Protection Board. Fines under the DPDP Act can reach ₹250 crore per violation.

For Indian CISOs, this means vulnerability management documentation is as important as the remediation itself. Your 72-hour framework must include:

  • Timestamped records of when the CVE was first identified in your environment
  • Documentation of interim mitigations deployed and when
  • Records of patch testing and deployment
  • Evidence of post-patch verification scans
  • An escalation path to your incident response team if active exploitation is detected during the 72-hour window

Regulatory Note: CERT-In’s April 2022 directive also requires organisations to maintain logs for 180 days and report unauthorised access, malware infections, and data breaches. An unpatched, exploited vulnerability that results in unauthorised access triggers this reporting obligation immediately.

Building a Continuous Vulnerability Management Programme

The 72-hour framework handles acute situations. Alongside it, Indian enterprises need a continuous vulnerability management programme that prevents the backlog from accumulating in the first place.

Scan Cadence

  • Continuous or daily: Internet-facing assets (web servers, VPN gateways, cloud workloads)
  • Weekly: Tier 1 internal assets (core banking, ERP databases, Active Directory)
  • Monthly: Tier 2 and Tier 3 internal assets
  • After every significant change: Any asset that underwent a configuration change, software update, or new deployment

Metrics That Matter

Track these KPIs monthly and report them to your board or audit committee:

  • Mean Time to Remediate (MTTR): Average days from vulnerability discovery to confirmed remediation, segmented by severity tier
  • Vulnerability Exposure Window: Number of days critical assets were exposed to unpatched critical CVEs
  • Virtual Patch Coverage: Percentage of unpatched critical CVEs with an active IPS virtual patch deployed
  • Scan Coverage: Percentage of known assets scanned in the last 30 days
  • Patch Compliance Rate: Percentage of assets within SLA for each severity tier

Integration with Your SIEM and SOC

Vulnerability management data must feed your Security Operations Centre. When your SOC receives an alert about suspicious traffic from a particular host, they need to know immediately whether that host has unpatched critical vulnerabilities. This context transforms a generic alert into a high-priority incident.

At PJ Networks, our integrated NOC/SOC platform correlates FortiGate traffic logs, vulnerability scanner data, and threat-intelligence feeds in real time. When a host with an open critical CVE begins exhibiting anomalous outbound traffic, the alert is automatically escalated — not buried in a queue of low-priority events.

OT/ICS Environments: Special Considerations

For Indian manufacturing, energy, and utilities organisations operating OT/ICS environments, the standard patch framework requires adaptation. Patching a Programmable Logic Controller (PLC) or a SCADA historian is not like patching a Windows Server:

  • Vendor certification requirements: Many OT vendors require patches to be tested and certified before deployment, adding weeks to the process. Virtual patching via FortiGate IPS is the primary mitigation strategy while awaiting certified patches.
  • Change-window constraints: Production lines cannot accept unplanned downtime. Patches must be scheduled during maintenance windows, which may be quarterly or annual.
  • Air-gap challenges: Air-gapped OT networks cannot receive patches via standard update mechanisms. Manual, offline patch delivery processes are required.
  • Legacy systems: Many OT systems run end-of-life operating systems for which vendor patches no longer exist. Compensating controls — network segmentation, protocol filtering, anomaly detection — become permanent mitigations.

PJ Networks’ OT security practice deploys dedicated FortiGate OT-edition firewalls between IT and OT network segments, providing virtual patching and deep-packet inspection for industrial protocols (Modbus, DNP3, EtherNet/IP) while OT systems await certified patches.

The Business Case for Managed Vulnerability Management

Building an in-house vulnerability management programme requires specialised tooling (vulnerability scanners, asset inventory platforms, ticketing integration), trained analysts who can interpret CVE data in business context, and 24/7 coverage to respond when critical CVEs drop outside business hours — a common occurrence since major CVE disclosures often coincide with Patch Tuesday or international security conference schedules.

For most Indian enterprises outside the largest banks and IT companies, building this capability in-house costs ₹1.5–3 crore annually in tooling and headcount, with no guarantee of the expertise depth needed to manage complex, mixed IT/OT environments.

Managed vulnerability management — delivered as part of a broader MSSP engagement — provides access to dedicated vulnerability analysts, enterprise-grade tooling, threat-intelligence subscriptions, and 24/7 coverage for a fraction of that cost, with contractual SLAs tied directly to MTTR targets.

Checklist: Vulnerability Management Readiness Assessment

Use this checklist to assess your current programme maturity:

  • ☑ Complete, up-to-date asset inventory covering IT, OT, cloud, and endpoint assets
  • ☑ Assets classified by business criticality tier (Tier 1–3) and exposure profile
  • ☑ Authenticated vulnerability scanning deployed across all tiers
  • ☑ FortiGate IPS virtual patching policies mapped to current critical CVEs
  • ☑ Emergency change-management category with fast-track approval (≤1 hour)
  • ☑ CERT-In incident reporting workflow documented and tested
  • ☑ DPDP Act data-breach notification process linked to vulnerability management findings
  • ☑ SOC integration: vulnerability context enriching security alerts in real time
  • ☑ MTTR KPI tracked and reported to leadership monthly
  • ☑ OT/ICS patching policy documented with compensating controls for each legacy system

How PJ Networks Can Help

PJ Networks delivers end-to-end managed vulnerability management as part of our 24/7 NOC/SOC services for Indian enterprises. Our offering includes continuous vulnerability scanning across IT and OT environments, risk-based prioritisation using threat intelligence tuned for the Indian threat landscape, FortiGate IPS virtual patching for emergency-tier CVEs, and a dedicated vulnerability management analyst team available around the clock.

We integrate directly with your existing ITSM platform to automate patch ticket creation, tracking, and SLA reporting — giving your internal team full visibility without the manual overhead. Our CERT-In and DPDP Act compliance reporting templates ensure your documentation meets regulatory requirements from day one.

If your current vulnerability management programme is reactive, backlogged, or siloed from your SOC operations, we can assess your maturity and build a roadmap to a risk-based, continuous programme — typically within 30 days of engagement start.

Contact PJ Networks today to schedule a no-obligation vulnerability management maturity assessment for your organisation. Our team is available at pjnetworks.com or through your existing account manager.

Leave a Reply

Your email address will not be published. Required fields are marked *