Skip to main content

Critical Zero-Day Response

Use this playbook to respond quickly when a new critical zero-day vulnerability is announced (e.g., widely exploited RCE or library vulnerability).

Assess Relevance

  1. Gather basic information:
    • Affected products, versions, and configurations.
    • Known exploit vectors and mitigations.
  2. Determine whether your technology stack uses impacted software or services.

Identify Potentially Affected Assets

Using Cloudaware:

  1. Search Cloudaware Vulnerability Scan records for:
    • CVE identifier (once available).
    • Package/library names and versions.
  2. If scanners have not yet released signatures:
    • Use CMDB and Breeze Agent data to identify where affected software may be installed.
    • Use tags, packages, and configuration data to build an initial asset list.

Create an Initiative and Tasks

  1. Create a dedicated Zero‑Day Initiative that:
    • Describes the vulnerability, business impact, and timelines.
    • Serves as a container for related tasks and reporting.
  2. Create Remediation Tasks per OU/application or platform team, including:
    • Initial scoping and validation steps.
    • Patch or configuration changes once vendor guidance is available.

See also: Vulnerability Management Processes

Coordinate with Patch and Change Management

  1. Work with Patch Management to:
    • Prioritize patches or configuration changes related to the zero‑day.
    • Schedule emergency maintenance windows as needed.
  2. Ensure Change Management processes are followed for high‑risk changes, but streamline approvals for emergency fixes where policy permits.

Communicate Broadly

  1. Use collaboration and ITSM integrations to:
    • Notify affected teams, leadership, and incident response.
    • Provide regular status updates (e.g., which systems are patched, which remain exposed).
  2. Update dashboards with a dedicated view for the zero‑day Initiative.

Verify Remediation

  1. Run targeted scans or rely on updated scanner signatures to confirm:
    • Vulnerabilities are no longer detected on patched systems.
    • No unexpected regressions appear.
  2. Update Initiative and task status to reflect remediation progress.

Document and Improve

  1. Capture:
    • Timeline of detection, triage, remediation, and verification.
    • Decisions about exceptions and compensating controls.
  2. Use this information to:
    • Improve future zero‑day response.
    • Adjust SLAs, risk models, and patch processes as needed.