TAMPA — The humble software patch has turned into a major headache and growing operational challenge for Pentagon and defense‑industry networks as AI‑driven cyberattacks proliferate. The issue was a central focus of this week’s Defense Intelligence Agency (DIA) DODIIS conference.
Speakers observed that vulnerabilities are being uncovered and exploited at an accelerated pace, vendors are releasing fixes at an unprecedented frequency, and government networks cannot afford to go offline for every software update.
Roger Greenwell, CIO of the Defense Information Systems Agency (DISA), described a cycle that places a heavy burden on patching teams.
“What keeps me up at night is recognizing that our adversaries are using these capabilities to look for inherent vulnerabilities within our software, within industry software, within common software,” he said. “The speed at which we need to be able to patch is working our people very hard these days.”
“All of these vendors are out there looking in depth at their code, discovering vulnerabilities, coming out with patches at a rate that we’ve never seen before,” Greenwell said. “How do you make sure that you actually are getting those patches applied to everything? How are you taking care of your workforce who is working rapidly to do this trying to stay ahead of the game.”
Installing patches often forces downtime for critical systems that support intelligence, communications, command‑and‑control, and other missions, which cannot tolerate being offline.
“We can’t afford the downtime,” Greenwell added, noting that the solution increasingly relies on resilient architectures and industry products that can “dynamically patch literally at a moment’s notice.”
Colin Hankey, the State Department CIO responsible for its Intelligence Community element, said the accelerating tempo is reshaping cybersecurity risk calculations.
“We now face an intensity of patching and security alerts that forces us to accept a higher level of risk than we previously tolerated, because there is simply no time to fully assess impacts,” Hankey said. “That reality is ‘very scary’ and there is no easy answer.”
Organizations must choose between applying a fix quickly without fully understanding its operational impact or leaving a known vulnerability exposed. As Hankey put it, “What risk do you accept by not patching?”
A further complication is that a patch may not resolve the issue.
DIA CIO Edacheril “EP” Matthew cited a case where a DIA cybersecurity tool discovered a zero‑day vulnerability in an industry vendor and issued an alert. The vendor released a patch weeks later, but a subsequent scan showed the patch “was not valid, not efficient,” requiring officials to return to the vendor before the vulnerability was finally fixed.
US Strategic Command Deputy CIO Elizabeth Durham‑Ruiz described patching as a fundamental readiness requirement. At the onset of the Russia‑Ukraine conflict, she said, officials “struggled” with whether systems could be safely taken offline for updates.
“The original thought was we’re going to just stop patching,” Durham‑Ruiz said. That approach proved untenable, so they established a dedicated team to review every authorized service interruption.
She compared it to physical weapons maintenance: “If you didn’t do maintenance on your weapon system, if you didn’t do maintenance on your aircraft or your submarine, you wouldn’t be able to have trust in that system moving forward.”
James Grimsley, US Transportation Command’s deputy CIO and executive director for command, control, communications, and cyber systems, said the underlying cultural problem is the long‑standing belief that certain operational systems must stay continuously available and cannot be taken offline for a patch. That tradeoff is becoming increasingly difficult to justify as cyber threats accelerate.
Also Read
- Israeli Resident of Athens Expelled from Digital Nomad Event After Revealing Identity
- Owner of Crans-Montana Bar Detained on Suspected Domestic Abuse Charges
- UK Prime Minister Keir Starmer Visits Kyiv for Ukraine’s Independence Anniversary, Announces Missile Technology Transfer
- Malaysian Shares Set for Rangebound Session Amid Positive Global Lead

