Patchpocalypse zero trust push shifts focus from patching to isolation
Zscaler says AI-assisted exploitation has cut patch windows from months to hours, making granular zero trust isolation a priority.
By Dominic Okoye · Staff Writer
· 3 min read
Zscaler is warning that the patchpocalypse zero trust debate has moved from planning exercise to operating requirement as automated attack tools compress compromise timelines from months to minutes. In a contributed analysis, the security company says tools such as Mythos can chain low-level flaws and misconfigurations into critical attacks fast enough to make conventional patch cycles inadequate.
The company frames the issue as a change in attacker speed, rather than a normal increase in vulnerability volume. Zscaler says many organizations built their programs around remediation windows of 30 days to three months, while machine-speed exploitation can turn newly found weaknesses into live risk within hours or less. The company did not cite a new incident count, but argued that legacy infrastructure and exposed internet-facing systems make the gap harder to close.
What is the patchpocalypse?
Patchpocalypse is Zscaler’s term for a security environment in which the volume and speed of exploitable vulnerabilities outstrip an organization’s ability to patch them. The practical claim is that perfect patching is no longer a workable assumption, so enterprises need to reduce exposure and contain compromise through isolation.
Zscaler points to legacy operational systems as the hardest case. It cites examples such as a 40-year-old VAX VMS mainframe used in industrial or financial environments, and Windows 98 or Windows NT systems controlling production or utility operations. In those settings, taking equipment offline for maintenance may disrupt revenue, service delivery or physical safety, and a vendor patch may not exist.
The recommendation is to move from broad network access to granular access control. Zscaler says systems that do not need public exposure should be removed from the internet, segmented and isolated. Public-facing services should sit behind web application firewalls or similar edge protections, while internal assets should be hidden behind access controls that limit each device or user to the specific application or service required.
Why does Zscaler say VPN-style access is not enough?
Zscaler argues that traditional VPN and firewall access can still give a compromised user or device a foothold inside a broader network. Its preferred model is stricter zero trust: least-privilege access at the application or service level, with no visibility into unrelated systems. The company says this turns a compromise of one asset into a contained incident, rather than a starting point for lateral movement.
The analysis calls out SIM-connected devices and operational technology as a priority. Zscaler says some cellular devices connect through exposed gateways, while others reach private corporate infrastructure through internal routing. Both designs can create broad access paths if they rely on permissive “any-any” rules put in place to make deployments work.
According to Zscaler, IoT and OT devices create a distinct risk because they perform physical functions, often arrive as closed vendor-managed systems, and may sit outside normal IT change controls. Examples include production line controllers, traffic lights, vending machines and industrial valve controllers. A ransomware attack on a workstation is disruptive; a compromised controller in a petrochemical setting can raise safety and environmental risks.
Zscaler’s proposed sequence starts with asset inventory across security teams, OT managers and product owners, including operating system, function and connectivity. It then calls for micro-segmentation by asset or group, risk assessment based on business criticality, and mitigation through patching, inspection, strict isolation or longer-term modernization. The company’s conclusion is direct: uptime now requires systems to keep operating while isolated and protected, not just powered on.
This story draws on original reporting from The Register.