Microsoft's Azure Networking VP Igor Sakhnov argues that the gap between vulnerability disclosure and exploitation has shrunk so much that traditional patch-and-deploy cycles can no longer keep enterprises safe, urging a shift toward network-level compensating controls like segmentation, WAF/IPS policies, and temporary isolation to reduce exposure while patches are still pending. Gartner analyst Shriya Mehrotra agrees the compression is real for high-risk, internet-facing systems but calls the proposed approach more an evolution of existing Zero Trust and segmentation practices than a wholesale shift. Both she and Kanerika's Bhupendra Chopra caution that most enterprises lack the asset visibility needed to implement real-time containment reliably, and that temporary workarounds risk becoming permanent, unpatched liabilities.
Questions this post answers
Why does Microsoft say patching alone is no longer enough to manage vulnerabilities?
Attack timelines have compressed so much that exploitation now often happens within hours of disclosure, while enterprises still typically need weeks to test and deploy patches across complex hybrid and multicloud environments. Microsoft's Azure Networking VP Igor Sakhnov calls this the 'window between awareness and remediation' and recommends network-level compensating controls, such as segmentation and WAF/IPS policies, to reduce exposure while patches are still pending. Track evolving vendor guidance on vulnerability response and compensating controls on daily.dev.
What are the risks of relying on network-level containment instead of patching vulnerabilities?
Containment can miss unmanaged, encrypted, identity-based, or alternative attack paths, and overly broad network rules can disrupt legitimate business services. There is also a practical risk that temporary fixes become permanent: a network rule blocks a risky path, nobody circles back to patch the underlying system, and months later that workaround becomes an unmanaged liability. Analysts stress containment should buy time, not replace patching. Security teams weighing containment versus patching tradeoffs can follow this debate on daily.dev.