Support
Contact
Book a Free ReviewCall 1300 053 948
Cybersecurity

Early intel: how we find the holes in your systems before someone walks through them

The gap between a vulnerability being published and being exploited keeps shrinking. How Key IT uses early threat intelligence to find and fix exposed systems across client infrastructure — before the attackers arrive.

When a serious vulnerability is published, two races start at once: attackers racing to exploit it, and defenders racing to patch it. Most businesses don't know the race has started. This post is about how we make sure our clients are running before their attackers are.

Every week, security researchers and vendors publish new vulnerabilities — flaws in firewalls, email servers, VPNs, business software. Each one comes with an uncomfortable truth: publication is a starting gun. The moment a vulnerability is public, ransomware crews and access brokers begin scanning the internet for systems that haven't been fixed yet, and the window between "announced" and "actively exploited" keeps shrinking — for the worst flaws it is now measured in days, sometimes hours. A business that patches on a monthly cycle is, for that window, defending itself with information that's a month old.

What do we mean by early intel?

Early intel means hearing the starting gun — knowing about a newly published or newly exploited vulnerability at the moment it matters, not at the next scheduled review. Our in-house 24/7 SOC watches the sources where that signal appears first:

ACSC alerts and advisories

the Australian Cyber Security Centre's warnings about threats being used against Australian organisations right now.

Known-exploited-vulnerability catalogues

curated lists, such as the one CISA maintains, of flaws confirmed to be exploited in the wild — the difference between "theoretically bad" and "being used against businesses like yours today".

Vendor security bulletins

Microsoft, firewall and VPN vendors, and the business platforms our clients run, announcing flaws in the products we manage.

The threat intelligence in our SOC tooling

indicators and exploitation patterns flowing from the security platforms that watch our clients' environments around the clock.

None of these sources is secret. What makes it "intel" is that someone is actually watching them at 2am, understands what they mean, and — critically — knows which clients are affected.

Why intel is useless without an inventory

Here is the step most businesses miss: an advisory only matters if you know whether it applies to you. "Critical flaw in brand-X firewalls" is trivia unless someone can answer, within minutes, "do we run brand-X firewalls — where, on what firmware, exposed to what?" That answer comes from the continuous vulnerability scanning we run across client infrastructure: it maintains a live picture of every device, operating system and internet-facing service in each environment. When an advisory lands, we don't send a generic "please check your systems" email — we cross-reference the flaw against what we know each client actually runs, and go straight to the environments that are exposed.

What acting early looks like in practice

When early intel meets a live inventory, the response is specific and fast:

Match.

A new exploited vulnerability is published; the SOC checks it against every client environment. Most clients aren't affected — they hear nothing, and lose nothing to alarm fatigue.

Prioritise.

For affected environments, we rank by real risk: is it internet-facing, is exploitation confirmed in the wild, what would compromise cost this business? The Essential Eight sets the clock we work to — critical, actively exploited flaws patched within 48 hours.

Fix or shield.

Usually that means an emergency patch inside an agreed window. When a patch doesn't exist yet, we mitigate — disable the vulnerable feature, restrict access to it, tighten monitoring around it — so the hole is covered while the vendor catches up.

Verify.

The next scan confirms the fix actually landed everywhere. "We think we patched it" is not a security posture.

Watch for the ones that got through.

Monitoring looks backwards too: if a flaw was being exploited before it was public, the SOC hunts for signs it was already used in a client environment — because finding that early is the difference between an incident and a catastrophe. That's where incident response takes over.

The pattern keeps repeating

This isn't theoretical. The pattern — vulnerability published, laggards exploited — has driven most of the incidents that made Australian headlines in the past few years, from perimeter devices to file-transfer tools. We wrote about a live example when the Akira crew went after unpatched SonicWall VPNs: the businesses hit weren't unlucky, they were slow — still exposed after the fix existed. Early intel exists precisely so our clients are never in that group.

Why speed is a system, not a heroic effort

Any IT provider can patch fast once — when a client calls in a panic after reading the news. The point of building intel, inventory, prioritisation and verification into one continuous loop is that fast is the default, for every advisory, whether or not it makes the news. That's also why this is delivered as a managed program rather than a tool: the value isn't the feed, it's the people and process wrapped around it. Your team hears about the flaws that affect you, with the fix already scheduled — not a weekly digest of everything scary on the internet.

FAQ

Frequently asked questions

We already patch monthly. Isn't that enough?

For routine updates, a monthly cycle is fine. For critical, actively exploited vulnerabilities it is far too slow — the Essential Eight expects those closed within 48 hours, and attackers scan for newly published flaws immediately. You need both: the routine cycle, and a fast lane for the flaws that can't wait.

Where does your threat intelligence come from?

ACSC alerts, known-exploited-vulnerability catalogues, vendor security bulletins, and the intelligence built into the SOC platforms watching our clients' environments — triaged by our Melbourne team so only what's relevant to your systems reaches you.

What if there's no patch yet for a flaw you find?

We mitigate: disable or restrict the vulnerable component, limit its exposure to the internet, and tighten monitoring around it until the vendor ships a fix. A hole you're watching and have shielded is a very different risk from one nobody knows about.

Do we need to be a cybersecurity client for this?

The full loop — intel, scanning, SOC triage, managed remediation — is part of our managed cybersecurity service, with continuous scanning available Australia-wide from $149/month. If you just want to know where you stand today, start with a free health check.

The next step

Ask your current provider one question: "when the next big vulnerability is announced, how will you know whether it affects us — and how fast will it be fixed?" If the answer is a pause, that's your gap. Call 1300 053 948 or start with vulnerability scanning & management — the inventory half of the loop, running within days.

Book your free IT & Cyber Security Review

See exactly where your IT and security stand, and what to fix first. No jargon, no obligation.