Patching is necessary. But it is not security.
Organizations patch thousands of vulnerabilities every month, track compliance metrics religiously, and maintain pristine patch dashboards. Yet attackers continue to exploit gaps that were never on the patch list. Patched, Not Protected explains why.
The second book in The Gap Series by Greg Hay, author of Checked, Not Secured, turns from the illusion of compliance to the equally dangerous illusion of patching. Hay argues with forensic clarity that the patch mentality, the organizational reflex that equates fixing known vulnerabilities with being secure, has created a profound Strategic Vulnerability Gap between what was patched, what was missed, and what was never addressable by patches at all.
Through methodical analysis across twenty-five chapters, Hay examines the architecture decisions made under deadline pressure that become permanent vulnerabilities, supply chain attacks that sit structurally outside what patching can address, identity sprawl that creates a perimeter no patch can close, and the board room communication gap where CVE counts mean nothing and strategic risk means everything. These are not failures of negligence. They are the natural consequence of organizations treating patches as the finish line rather than the starting point.
Moving from diagnosis to prescription, Patched, Not Protected equips CISOs, security directors, IT practitioners, and executive leadership with frameworks for understanding strategic vulnerability, building security strategy that sticks, and implementing a practical 90-day start toward closing the gap before attackers find it.
Essential reading for anyone who knows that patching is necessary but not sufficient, and ready to close the gap that patches were never designed to address.