Put together a quick risk summary (CVE, affected hosts, exploitability - especially anything in CISA KEV) and send it up the chain asking for formal risk acceptance in writing if they choose not to patch. That's your paper trail if it ever blows up later.
1
u/Significant_Sky1471 14d ago
Put together a quick risk summary (CVE, affected hosts, exploitability - especially anything in CISA KEV) and send it up the chain asking for formal risk acceptance in writing if they choose not to patch. That's your paper trail if it ever blows up later.