[GAME THEORY] Patching a KEV does not answer the incident question

[GAME THEORY] Patching a KEV does not answer the incident question

A lot of KEV response still collapses into one closure condition: the vulnerable system was patched. That works if exploitation never happened. It is weaker when the asset was exposed, telemetry is incomplete, or the system carries identity, remote-access, payment, or administrative authority.