CIO Brief: Why Patch Management Is a Board-Level Issue After WannaCry
Retrospective: this article looks back at events from May 2017, written in 2026 with the benefit of hindsight.
The short version: In 2017, WannaCry ransomware infected hundreds of thousands of computers worldwide using a Windows flaw that had been patched two months earlier. Organizations that applied the update were fine. Those that did not lost days or weeks of operations.
Why patching became a board issue
WannaCry turned a routine IT task into a business continuity crisis. The UK's health service cancelled appointments; manufacturers stopped production. The damage came not from a sophisticated new attack, but from a known weakness left unfixed.
The business impact
- Downtime across entire organizations, not a single system.
- Recovery costs far exceeding the cost of patching.
- Regulatory and reputational fallout, especially in healthcare and critical services.
Questions to ask your team
- How long does it take us to apply critical security updates — on average and at worst?
- Which systems can't be patched, and what protects them?
- Does this include our servers in Azure and AWS, not just office computers?
- How would we know if one system started infecting others?
What good looks like
Critical updates applied within days for internet-facing systems and within two weeks for everything else, a list of exceptions with compensating controls, and a monthly report to leadership on patch compliance.
The decision
Ask for a patch compliance metric in your regular reporting. What gets measured gets fixed — and the gap between "patch released" and "patch applied" is exactly where attackers operate.
- WannaCry (May 2017): SMBv1, Unpatched Servers and What Cloud Teams Missed Incident Teardowns
- How to Disable SMBv1 and Enforce Patch Compliance on Azure VMs How-To & Hardening
- Detecting SMBv1 Exploitation: Defender for Cloud and Sentinel KQL Detection & Response