Critical advisory intake
Getting a vendor critical into change control the same day — including record Patch Tuesday bundles. Owner, source list, exploited-first triage, evidence. ASD patching meets the NDB clock.
A critical vendor advisory is useless if it dies in a shared inbox. ASD's Essential Eight and ISM patching guidance treat internet-facing and high-impact applications as urgent; the Notifiable Data Breaches scheme treats unpatched exposure that later leaks personal information as a foreseeable pathway to serious harm. Intake is the bridge between those two sentences.
Name one owner (and a deputy) for advisory intake. Subscribe them to the vendor security channels you actually run — PSIRT RSS, GitHub Security Advisories for self-hosted products, ASD/ACSC alerts, and CISA KEV for exploited classes — not only a general IT newsletter. When a critical or actively exploited advisory lands, the owner records the CVE or bulletin id, affected versions you run, internet exposure, data classification behind the service, and the patch or workaround within hours, not at the next CAB.
Escalate on a written trigger: CVSS critical or vendor 'actively exploited', plus any system that holds personal information or is internet-reachable. The escalation path should reach whoever can approve an emergency change after hours. Document why you deferred a patch (compensating control, change freeze with executive acceptance). A process that 'did not identify and escalate' an advisory is an organisational failure, not bad luck — Mathspace's September 2026 Metabase disclosure is the public lesson.
Evidence the intake: advisory received timestamp, decision, change ticket, build installed, and post-patch compromise checks the vendor recommended (session revocation, API-key review, credential rotation). Pair this page with Essential Eight evidence, the data breach response plan, and third-party supply chain. If a managed provider runs the product, your intake still starts when you have grounds to suspect — put their PSIRT contact and shared-responsibility split in the plan before the incident.
Record Patch Tuesday and other mega-releases need a triage lane, not a read-everything lane. Microsoft’s September 2026 security bundle was on the order of a thousand CVEs with two exploited elevation-of-privilege zero-days (CVE-2026-81963 Windows Update Stack; CVE-2026-85880 Windows ALPC). Same-day practice: pull the vendor actively-exploited list first, then internet-facing and identity-plane roles (Exchange, SharePoint, VPN/remote access, IdP), then everything else against your asset inventory. Essential Eight patching still wants internet-facing and known-exploited treated as urgent — volume is not an excuse to average the risk. Log the advisory-received time, the subset you deferred, and who accepted that deferral.
See also:
Fact source: ASD's ACSC, Essential Eight.
