← Back

Wire · founder news, decoded · regulatory

The 72-Hour Rule: CISA Just Turned Patch Management Into a Ticking Clock

Published

22 July 2026

Topic

regulatory

Sectors

Cybersecurity

Geography

United States

Source

Read at securityboulevard.com

Verified

Fusion42 · 22 July 2026 · Fusion42 review

CISA's Binding Operational Directive 26-04 mandates remediation of high-risk, publicly exposed vulnerabilities within 72 hours, replacing older 15-30 day timelines and establishing a litigation-grade benchmark for "reasonable" cybersecurity response based on exploitability, automation potential, and technical impact.

This Wire brief sits within Fusion42's coverage of Cybersecurity. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.

The Wire takeaway

You now have 72 hours to patch internet-facing vulnerabilities CISA flags as exploitable and automatable, or a regulator, court, or insurer will use that deadline as evidence of negligence. This is not a federal-only rule—it's the new standard of "reasonable" for every company handling customer data or critical infrastructure.

Related on Wire

Topics

Cybersecurity · cisa-bod-26-04 · patch-management · vulnerability-remediation · cybersecurity-compliance · ai-exploitation · litigation-risk

The 72-Hour Rule: CISA Just Turned Patch Management I… | Fusion42