Blogs

What CISA BOD 26.04 means for federal exposure management

Written by Matt Malarkey | Jul 24, 2026 10:00:38 AM

On 10 June, CISA issued a new Binding Operational Directive - BOD 26.04 “Prioritizing Security Updates Based on Risk”. It requires US Federal Civilian Executive Branch agencies to focus their efforts on addressing the highest risk vulnerabilities, rather than the quixotic quest to shut them all down. It was accompanied with a blog by senior CISA execs that urged defenders to “patch smarter, not harder.”

This was immediately positioned as a response to both the elevated threat from AI-powered attacks to federak networks, but also the emergence of AI tools that are capable of finding unaddressed vulnerabilities in corporate networks.

Matt Malarkey, Vice-President of Strategic Partnerships at Titania, unpacks what BOD 26.04 means for federal agencies – and its potential wider implications.

How big a change does BOD 26.04 represent?

That depends on how you were approaching patching and security beforehand! In essence, it’s a shift in approach from conventional vulnerability management, giving federal agencies the authority to determine whether one of CISA’s Known Exploited Vulnerabilities (KEV) is actually a risk to their operations.

If it is a serious risk, they are expected to remediate within three days. If it’s a lower risk, the timelines are more relaxed.

The truth is that many federal agencies – like organizations in other sectors – have already been compelled to prioritize their vulnerability remediation efforts and focus on the most serious risks to their business.

CISA acknowledged this in the blog which pointed out that only 26% of vulnerabilities on the KEV catalog were fully remediated by organizations in 2025. Looked at from the other angle, this means that almost three-quarters weren’t!

So BOD 26.04 is in some ways a reflection of the new reality: there are simply too many KEVs now for any organization to remediate them all. CISA knows it, federal agencies know it: they now have the freedom to respond differently.

The core of BOD 26.04 is adopting a risk-based approach. How do you determine risk?

This is absolutely what federal agencies have to decide – and BOD 26.04 demands a lot of reporting around this, which is one of the big challenges agencies will face.

The key question, I believe, is “could this KEV be exploited in your agency?” And if it was exploited, what would the consequences be? There are lots of layers to that, the first of which is simply do you have the technology which the KEV relates to? If it’s about a certain manufacturer that you don’t use, the answer is easy!

But beyond that, organizations are being asked to consider context, and what protections they have in place. For example, if I have a router and the manufacturer has just released an urgent patch, I will obviously want to apply that – but if that router is on an isolated network or site that doesn’t have access to my mission-critical systems, it may not need the three-day vulnerability remediation time.

This is only logical, but the problem is that many security tools do not offer that contextual analysis of network devices. And if you can’t prove it’s not a risk, then you have no choice but to patch.

What are the biggest challenges that BOD 26.04 presents?

Obviously, the timelines for patching critical issues. Three days is fast; especially if it’s a device widely in use across the network. You have to identify the issue, assess it, patch it, and validate it – all in three days. Regardless of what else is in your workload. That’s tough.

In 2025, there were 245. So you’re having to assess nearly five a week – and most organization are already behind the curve for the existing KEVs!

But I think the other big challenge is the reporting requirement. Agencies are expected to either move to fully automated reporting on their vulnerability status, or manually report twice a week. That’s a significant burden.

Obviously BOD 26.04 is focused on federal agencies. What do you see as the wider implications of it?

While other regulators have not yet issued similar directives, it seems likely they will. There has already been a shift across the regulatory landscape to require organizations to focus on the real risks. In financial services, the EU's Digital Operational Resilience Act (DORA) emphasizes ICT risk management and operational resilience, requiring organizations to prioritize actions based on business impact and risk. Across European critical infrastructure sectors, NIS2 similarly requires cybersecurity measures that are proportionate to the risks organizations face. I would anticipate that US organizations in critical infrastructure, energy, finance and other regulated sectors will soon be challenged to take a risk-based approach to vulnerability remediation too.

What do you think of the message “patch smarter, not harder?”

I think the ultimate message is “Do security smarter”! That’s what focusing on risk is about. It’s not just about patching, which is reactive: it happens after a KEV has been identified and the manufacturer has provided a fix for the issue.

Instead, the most effective way to deal with risks is by being proactive. You can pinpoint the prime targets in your operation, so reduce asset exposure: segment your network to make them harder to access – intentionally putting barriers in the way of attackers. Harden devices: make sure you are up to date with patches, and that you aren’t absentmindedly left with readily exploitable vulnerabilities like default configurations. And monitor your network on a regular basis, or better still adopt continuous security monitoring, to spot things that are out of the ordinary.

Get these bits right and – applying the risk lens – far fewer KEVs will fall into the highest risk categories. So you aren’t stuck in a cycle of constant frantic patching… which also reduces your resource to deal with other, potentially more significant issues.

Where do you think federal agencies should start in their response to BOD 26.04t?

Firstly, it’s an analytical task: you need to identify whether there are any KEVs on your mission-critical or task-critical networks. And if there are, work out how to address them, reducing exploitable vulnerabilities through targeted patching and device hardening.

I would say the next step is segmentation, literally closing down potential routes to key assets. That will mean that even if a router – say – is compromised, the attackers cannot move laterally to access critical data.

By adopting this kind of attack surface management, you can significantly limit the potential damage from Zero Day exploits: we like to say it shrinks the blast radius.

If you’ve already segmented your network for this reason, great: now check that your policies are being enforced correctly.

With these foundations in place, it’s then onto monitoring – both of the KEV catalog, so you can respond promptly to new additions, but also to keep an eye out for network changes that could inadvertently reopen KEVs you thought you had dealt with.

Finally and crucially, determine how you are going to meet the reporting requirement.

If an agency does all this, can it stop patching?

Absolutely not! Patching remains a vital component of effective security, but as CISA argues, organizations need to patch smarter: this is about vulnerability prioritization based on risk.

That way, the immediate and most critical issues are dealt with promptly… but you’re also reducing residual risk and closing off avenues of attack.

Titania Nipper solutions are already helping federal agencies adopt a risk-based approach to exposure management.

To find out how – and what Nipper solutions can do for you – visit our federal solutions page.