From two weeks to three days: The KEV deadline debate

Drawing on his experience from his time in government working directly on CISA’s Known Exploited Vulnerabilities (KEV) catalog, Todd Beardsley, VP of Security Research at runZero, explains what it actually took behind the scenes to get a vulnerability added: verifying that real exploitation occurred, confirming the incident mattered to federal interests (including state/local governments, critical infrastructure, or allied nations), and ensuring there was a concrete remediation option before publishing. 

He walks Greg through how those judgments tied back to Binding Operational Directive 22-01 and how deadlines were set and adjusted from the two-week baseline — context that frames the recent trend toward three-day turnaround requirements. From that insider perspective, Beardsley outlines the practical risks of compressing timelines (especially around testing and change-control realities across 100+ civilian agencies) and why ultra-short deadlines can dilute KEV’s value as an “urgency signal,” even as they may push agencies to modernize staffing, automation, and patch processes to respond faster.

Meet Our Speakers

todb

VP, Security Research, runZero

Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.


Related Resources

Podcasts
OT asset exposures & mitigations
Rob King joins the Nexus Podcast to discuss the security risks and exposures introduced by digital transformation to operational technology...
Podcasts
runZero accidentally got good at OT (Risky Biz Interview)
HD Moore discusses the release of runZero v4.9, which introduces enhanced OT scanning, animated visualization maps, and a highly requested dark mode.
Podcasts
Past, Present & Future of Offensive Security w/ HD Moore
HD explores how his deep technical roots helped him build runZero to $1M ARR as a solo operation, his past, and the future of offensive security.
Podcasts
The infinite eye: How AI threat intelligence gives defenders an asymmetric edge
Tod Beardsley, HD Moore, and Jonathan Cran discuss how AI-powered threat intelligence is providing defenders with a much-needed advantage.

See Results in Minutes

See & secure your total attack surface. Even the unknowns & unmanageable.