AzureCIO BriefingsRetrospectives

CIO Brief: Why Patch Management Is a Board-Level Issue After WannaCry

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from May 2017, written in 2026 with the benefit of hindsight.

The short version: In 2017, WannaCry ransomware infected hundreds of thousands of computers worldwide using a Windows flaw that had been patched two months earlier. Organizations that applied the update were fine. Those that did not lost days or weeks of operations.

Why patching became a board issue

WannaCry turned a routine IT task into a business continuity crisis. The UK's health service cancelled appointments; manufacturers stopped production. The damage came not from a sophisticated new attack, but from a known weakness left unfixed.

The business impact

  • Downtime across entire organizations, not a single system.
  • Recovery costs far exceeding the cost of patching.
  • Regulatory and reputational fallout, especially in healthcare and critical services.

Questions to ask your team

  • How long does it take us to apply critical security updates — on average and at worst?
  • Which systems can't be patched, and what protects them?
  • Does this include our servers in Azure and AWS, not just office computers?
  • How would we know if one system started infecting others?

What good looks like

Critical updates applied within days for internet-facing systems and within two weeks for everything else, a list of exceptions with compensating controls, and a monthly report to leadership on patch compliance.

The decision

Ask for a patch compliance metric in your regular reporting. What gets measured gets fixed — and the gap between "patch released" and "patch applied" is exactly where attackers operate.

wannacry ransomware impactWannaCry2017

More on this story