In the newsletter I told you the cushion you used to have for fixing a software flaw is gone. Here is the whole story behind that, why it happened this fast, and what an owner actually does about it.
See Where Your Business Stands → — a plain A-to-F grade on your Windows PCs. No card needed to see it.
The problem: For years you could wait to install a security fix. A flaw got found, and you had weeks, often months, before criminals worked out how to use it. That waiting room is what the zero-day clock measures, and it just fell from about a year down to roughly a day. “We will patch it during the next maintenance window” quietly became a gamble with your payroll and your customer data on the table.
The straight answer: You cannot make your software flawless. Nobody can. What you can control is how fast a real person spots a serious flaw in your business and closes it. When the window shrinks to hours, that speed is the entire game. Let me show you exactly what changed, and what “fast enough” looks like now.
In this article
Hey folks! Let me start with the picture that stopped me cold this month, because once you see it you cannot unsee it.
There is a tracker called the zero-day clock. All it does is measure one gap: the time between a flaw existing in a piece of software and a criminal having a working way to break in through it. That gap is your cushion. It is the head start you get to install the fix before anyone can use the hole against you. A few years ago that head start ran about a year. Today the zero-day clock reads roughly one day. The people who built it think it is headed toward a minute.
I know how that sounds. It sounds like the kind of scary number a vendor invents to sell you something. So here is the proof it is real, straight from the people who caught it happening.
This spring, Google’s threat team found the first case in the wild of a break-in tool built with AI doing the heavy lifting. It was aimed at a widely used business administration program, the sort of thing that quietly runs in the background at plenty of companies. Google spotted it and worked with the software maker to shut the hole before the crooks could turn it into a mass campaign. We got lucky that time, because good people were watching. The tool that built it is not going away.
Michael Sentonas, who runs the security firm CrowdStrike as its president, said the quiet part out loud. We all wake up one day, he warned, to an explosion of flaws with no fixes ready for them. That is not a man selling fear. That is one of the most connected people in the industry telling you where the puck is going.
Here is the mechanics nobody explains to a business owner, and it is worth two minutes because it tells you why this is permanent, not a scare that blows over.
The old way took an expert. When a software maker shipped a security fix, it also, without meaning to, handed criminals a map. A patch shows you the exact spot that was broken. But turning that map into a working break-in used to take a skilled human days or weeks of painstaking work. That labor was your cushion. Most crooks never bothered, and the ones who did were slow.
AI erased the labor. Feed the same patch to the new AI tools and they read the map, find the broken spot, and write the working break-in in hours. The skill barrier that protected you for years is the thing that just fell away. It was never the flaw that gave you time. It was how hard the flaw was to weaponize.
So the cushion did not shrink. It got automated out of existence. The moment a fix goes public, the clock to abuse it now starts in hours, not months, and it runs at machine speed whether you are watching or not.
Sit with what that does to the ordinary rhythm of running a business. The patch lands on a Tuesday. Your one part-time tech person, or the outside company you assume handles this, gets to it “sometime next week.” In the old world that was fine. In this world, the gap between Tuesday and next week is exactly the window a criminal’s tool needs, and it is hunting the whole time. The delay that used to be reasonable is now the opening.
Here is the opinion I have earned in more than 35 years at this, and I will say it plainly. The scheduled maintenance window, the idea that you batch up your updates and apply them on a tidy monthly cadence, is finished. It was built for a world where you had a year of slack. You now have a day. You cannot run a once-a-month process against a once-a-day threat and call yourself protected.
And notice what the zero-day clock quietly does to the excuse most businesses lean on. “We are too small to be a target” was always wishful, but at least it had some logic when attacks took human effort and criminals aimed at the biggest payday. That logic is gone. An automated tool does not decide you are too small to bother with. It does not decide anything. It sweeps every address it can reach and tries the fresh break-in on all of them at once. Being small does not take you off the list. It just means nobody was watching your corner when the tool came through.
So the real question stopped being “does my software have holes.” It always will, everybody’s does. The question is now the only one that matters: when a serious flaw shows up in something my business runs, who notices, and how fast do they close it? If the honest answer is “I am not sure anyone does,” that is not a knock on you. You built a business. Standing guard over a clock that ticks in hours was never supposed to be your job. It was supposed to be someone’s job. The trouble starts when everyone assumes it is someone else’s.
This is the whole reason the fix-it step exists in what we do. Seeing the open doors is one thing. Closing them fast, every time, before the automated crowd gets there, is the actual work. And it is not a once-a-year project. It is a habit someone has to own.
You do not need to understand a single line of code. You need to know whether anyone is actually holding the clock. These three moves tell you.
1. Get one name, in writing, for your updates.
Ask who owns patching for your business and how fast they act when an urgent fix drops. Not “the IT company,” a person and a time. “Within 24 hours of a critical patch” is an answer. A shrug is your weakest door, and now you have found it.
2. Turn on automatic updates everywhere they exist.
Windows, your browsers, your phones, the apps your team lives in. It will not cover the deeper business systems, but it closes the easy doors the automated tools try first, and it costs you nothing but ten minutes. The stuff automatic updates cannot reach is exactly the stuff that needs a human, which brings us to number three.
3. Find out where you stand right now.
Run a Reveal scan on your Windows computers and get a plain grade, A to F, on each one, with the open doors listed out. It is the same first step most of the businesses I now manage took before they signed on. You cannot fix a clock you cannot see.
My father fell for a phishing email. More than three decades in this field, and it still reached the person I most wanted to protect. Scammers got remote access to his computer and started hunting for his financial papers. My step-mother noticed something was wrong, called me, and I stopped them before they reached his bank credentials. We were lucky. We caught it in time. A day slower and it would have been a very different phone call.
That is what a shrinking clock feels like when it is your family, and it is why I built Forward to Safety around people who actually watch, backed by good technology. More than 35 years at this, since 1991. FBI InfraGard trainer. Not one client I manage has ever been hit by ransomware, because when a fix drops, a real person is holding the clock instead of an empty maintenance window.
Partly, and it is a good habit. Automatic updates handle Windows and your everyday apps, and that closes plenty of easy doors. But the systems that run your actual business, your website tools, your remote-access setup, the server humming in the closet, the specialty app your office depends on, usually do not update themselves. Those are the ones a person has to watch, and those are the ones the automated attackers love.
So the honest question is not “do my computers update.” It is “when a critical fix lands on the one system that does not update itself, who installs it, and how fast?” If nobody can answer, the clock is running and no one is holding it.
Let me ask you a few plain questions, and just answer them in your head. You did not start your business to babysit software updates, right? You figured somebody had that covered. And now that you know the window to fix a serious flaw is down to about a day, “we will get to it next week” does not sit right anymore. If you are honest, you are not actually sure who is holding that clock for you today.
That itch you feel reading this is worth listening to. It is the gap between the careful owner you are and a job that quietly went unwatched, and that is not a knock on you. Here is the thing about that gap. You close it one of two ways. You can tell yourself it is probably fine and feel the same itch the next time a story like this lands in your inbox. Or you can take fifteen minutes, find out where you actually stand, and put the question to bed. One of those roads ends the worry. The other just reschedules it.
No magic here. When a serious flaw shows up in something your business runs, we already know, and we close it before the automated crowd gets there. That is the whole job.
We see the doors, we patch and harden them for you, and then we keep watching around the clock so the next one does not sit open for a week. You get back to running your business instead of chasing patch notes you were never meant to read.
Not one client we manage has ever been hit by ransomware. That is not luck. That is someone holding the clock.
Let’s grab fifteen minutes and find the one flaw most likely to hurt you, and exactly how to close it. No pitch, no obligation.
Book My 15-Minute Game Plan → — fifteen minutes with a real person, straight talk on where your business stands.
Want this kind of plain-English security news every week? Sign up for Craig’s Insider Notes at CraigPeterson.com.
#ZeroDayClock #Patching #SmallBusinessSecurity #AIThreats #ForwardToSafety
Join thousands of security professionals who receive Craig Peterson's Insider Show Notes and cybersecurity updates.
Join 10,000+ cybersecurity professionals