From Patch Counts to Risk Operations

Tune in Wednesday, September 9 at 1:00 PM EST

On June 10, 2026, CISA issued BOD 26-04, retiring legacy “patch everything” programs and mandating an evidence-based, risk-prioritized model for federal agencies. At the same time, frontier AI models can now discover, test, and weaponize vulnerabilities in hours, shrinking exploit windows that used to span weeks and creating a new class of operational risk. Agencies that stay on legacy VM practices will not only fall out of compliance, but they will also struggle to keep pace with AI-speed threats. In this webinar, federal cybersecurity leaders from GuidePoint Security and Qualys unpack what BOD 26-04 really demands, how it supersedes earlier directives, and why agencies need a Risk Operations Center (ROC) to operationalize risk-based vulnerability management at scale. You will see how a ROC turns threat intelligence, asset context, exploitability data, and exposure analytics into a single, repeatable operating model for detection, prioritization, validation, and remediation across your environment.

Key Takeaways:

  • How BOD 26-04 replaces BOD 22-01 and 19-02, and the immediate changes your vulnerability management program must make.
  • How to build a Risk Operations Center that unifies AI-speed detection, risk-based prioritization, and zero-day remediation in a closed loop.
  • Your 180-day compliance clock and what must be live now, at 60 days, and at 180 days to show real progress on BOD 26-04.

Speaker Details

Joseph Tyler

Lead Security Solutions Architect,
Qualys

Timothy Amerson

Federal CISO
GuidePoint Security

Event Topic

Modernization, Risk Management/Regulatory, Digital Transformation

Relevant Audiences

All Federal Government
From Patch Counts to Risk Operations
Event Type
Virtual / Online
Event Subtype
Webinar / Webcast
When
Wed, Sep 09, 2026 | 1:00 pm - 2:00 pm ET
Registration Cost
Complimentary
Website
Click here to view event website
Organizer
GovExec