WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships Ransomware Resilience – Deferred Patching Could Result in a Ransomware Attack
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Ransomware Resilience – Deferred Patching Could Result in a Ransomware Attack

Author: Jennifer Walker

Created: Tuesday, September 21, 2021 - 17:39

Categories: Cybersecurity, Security Preparedness

Ransomware resilience is more than just having validated backups to use to restore your systems after a ransomware attack, patching has a lot to do with it too. A security researcher has compiled no less than forty-three (at the time of this writing) technical vulnerabilities across multiple products that ransomware actors are actively exploiting on unpatched devices. Popular vulnerabilities being exploited include IT-based products that WaterISAC has repeatedly issued notices and urgings to patch, including Pulse Connect Secure VPN, Microsoft Exchange Server, Fortinet, F5, Palo Alto, among others. What’s more, less than half (20) of the vulnerabilities were issued vendor patches in 2021 – leaving just over half having had patches available since 2020 (11) or before (12). Some vendor updates have been available since 2017, yet remain unapplied by asset owners. This propensity to postpone patching is prominently known among threat actors and ransomware groups have picked up on it too. No one intentionally plans to prolong patching, but without proper prioritization, deferred patches leave devices in distress. Check out more at BleepingComputer.

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated April 30, 2026)

Apr 30, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Tip of the Week – April 30, 2026

Apr 30, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) Cyber Readiness Institute Joins WaterISAC as a Community Partner to Strengthen Cyber Readiness Across the Water Sector

Apr 30, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar