“Zero-day” is a cybersecurity term that is often misunderstood. The term makes it seem like the clock is ticking and there is an immanent threat looming over your IT systems.
A zero-day doesn’t necessarily mean High Severity or elevated Risk:
The “Zero” in Zero-day means there are no days for the defender to prepare for mitigation before it is known about. Consequently, a zero-day threat, vulnerability, exploit or patch are simply threats, vulnerabilities, exploits, or patches that have been brought to attention of the defender essentially at the same time as bad actors. This doesn’t make it more dangerous.
It can be nearly any Severity: Low, Medium, High, or Critical.
Risk is unique to you; the user, the business owner, stakeholders, or systems. Risk is not something published, it’s generally ascertained by your IT Department, MSP, CIO, vCIO, IT Admin.
The reason some Managed Service Providers and IT Departments tout processes that Mitigate Zero-Day vulnerabilities and exploits is:
They are generally isolated from other mitigation schedules. The term is catchy and it’s easier to communicate and raise awareness of threats and all the work that goes into mitigating them.
Managed Service Providers and organizations that hire them should always be able to discuss the severity of security flaws affecting their information systems.
I used a capital “S” in Severity because it is a defined term used in quantifying vulnerabilities. It can be calculated using a sophisticated formulation framework that has matured over the years and is called the Common Vulnerability Scoring System (CVSS). The single source of truth on this is of course NIST; NIST relies upon an organization by the name of First. First is dedicated to a safe internet and among other things, is the single source of truth on the CVSS.