Patching has always been a race against exploit development. That race just changed shape: disclosure-to-exploit time has collapsed to an average of roughly 10 hours, down from about two years in 2020, while the number of new doors into the network keeps climbing — an estimated 300 new WAN-facing doors a month from cloud services, APIs, IoT, and B2B integrations. Trying to patch faster than that isn’t a strategy. Removing reachability is a different move entirely: it doesn’t try to win the race, it takes your workloads out of it.

Download the PDF here.

Three Key Takeaways

1. The economics of the patch race have genuinely broken. A roughly 8x increase in edge breaches, patch cycles shattering records, and a disclosure agency that says it can no longer publish every CVE are all symptoms of the same underlying shift: AI has compressed the window between a vulnerability becoming public and it being weaponized down to hours. Every one of those 300 new monthly doors is a fresh target the moment it opens. Reachability itself — not just unpatched code — is now the thing driving risk.

2. Removing reachability turns emergencies into routine tickets. A known exploited vulnerability on a workload that simply can’t be reached isn’t a war room or a rushed, after-hours patch — it’s a normal ticket on a normal schedule. That has a real dollar value: every avoided emergency change removes both the direct labor cost and the uptime risk that comes with rushed testing. It also functions as a genuine audit-grade compensating control — PCI DSS compensating-control worksheets, DORA/NYDFS/CIP mitigations, and risk-acceptance memos backed by evidence any tester can independently verify: scan the workload and find nothing to connect to.

3. For the workloads that can never be patched, unreachability isn’t a stopgap — it’s the actual fix. End-of-life systems, legacy applications, a large share of OT and medical devices, vendor appliances, and M&A estates with unknown patch status all share the same problem: no patch is ever coming. Where microsegmentation and ZTNA/SASE both leave gaps — microsegmentation typically covers only mapped east-west workflows, and ZTNA/SASE cover employee-to-modern-app paths while leaving other workload-to-workload paths reachable — an approach that makes a workload unreachable to unauthorized parties, human or non-human, closes that gap regardless of whether the workload is a legacy appliance or an AI agent.

How It Actually Works

Nothing exotic: client and server sides both dial outbound to a virtualized overlay, eliminating the open inbound port, NAT configuration, and IP overlap that unauthorized traffic would otherwise use to find a target in the first place. No identity, authentication, and policy authorization means no packets pass — full stop. The practical result is the one that matters most: an unauthorized party can’t discover, ping, scan, or connect to a protected workload, because there’s no path to attempt any of those against. A specific vulnerable workload can be made unreachable in hours, surgically, without touching anything else around it — whether that’s in response to a live KEV or proactively ahead of the next one.