A vulnerability ticket is very good at recording a software update. It is a poor witness to what happened before the update. Recent NetScaler reporting makes that gap concrete: CISA warned that updates may cost forensic visibility, and Unit 42 documented web shells planted before public disclosure. Its large exposure estimate identifies potentially vulnerable internet-facing instances, not thousands of confirmed intrusions.
For the next known-exploited edge flaw, make the affected asset and its reachable service the unit of work. Decide who can restrict access, what evidence survives the change, who assesses compromise, and what restores confidence in the device and adjacent identities. Otherwise, a completed change can look like a completed investigation. The patch queue is not lying; it simply was not asked the right question.
The fuller operating model.