Pith. sign in

REVIEW 3 major objections 5 minor 37 references

Mean Time to Remediate Is Not a Fielding Model: A Cadence Audit for Enterprise Vulnerability Management

T0 review · 3 major / 5 minor · reviewed 2026-07-11 · grok-4.5

Pith's one-line read Mean remediation lag is not a fielding model: the same average lag can hide release calendars that consume a large fraction of local security capacity.

desk verdict Careful method paper: calendar discount and audit packet are the real product; the 17%/5% numbers only mean capacity inside an unvalidated four-state channel, but the paper is honest about that and still deserves referees. read the letter →

arxiv 2607.04511 v1 pith:VXWSBGVW submitted 2026-07-05 cs.CR math.DS

classification cs.CRmath.DS
keywords CybersecurityoperationsvulnerabilitymanagementpatchremediationmetricsMTTRreleasecadencesecuritygovernancecontrolvalidation
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

Enterprise security teams often treat mean time to remediate and SLA compliance as proof that defensive fixes are being fielded safely. This paper argues that is unsafe: two programs can report the same mean lag while one fields continuously and another waits for monthly or bimonthly windows, clears only part of the backlog, or routes work through rings and emergency bypass. The author introduces a remediation-cadence audit that records release period, release fraction, cohort geometry, hard delay, residual-pressure evidence, and rate scenario, then compares a continuous same-mean shortcut with the actual calendar. The audit returns a local capacity verdict plus a calendar discount—the share of mean-only capacity consumed by batching. Worked packets with a fixed 30-day mean show a two-month train consuming about 17 percent of capacity, a monthly train about 5 percent, and a two-week screen about 1 percent; rings do not restore the continuous benchmark, and staggering can help or hurt near capacity. When that discount is material relative to residual-pressure uncertainty or claimed headroom, MTTR alone should not be used as fielding evidence.

What carries the argument

Calendar discount: the fraction of mean-only local capacity consumed by the recorded release calendar, obtained by comparing continuous same-mean capacity boundaries with calendar-aware release-window boundaries under a declared local-channel rate scenario.

What would settle it

On a real estate with sharp BAS or red-team residual-pressure intervals, recompute continuous and calendar-aware boundaries from measured release telemetry; if the calendar-aware process never flips the growth-rate sign and the discount stays negligible relative to measured headroom across a realistic rate band, the claim fails for that channel class.

Watch

Extended reading notes

Core claim

MTTR, SLA compliance, and related mean-lag metrics are useful governance indicators but are not fielding models. Release windows, partial backlog clearing, rings, hard delays, and emergency splits can change the local capacity verdict even when the reported mean lag is held fixed. The remediation-cadence audit therefore reports both an inside/outside capacity verdict and a calendar discount that turns cadence assessment into an evidence-resolution question rather than a fragile point comparison.

Load-bearing premise

Local adaptive risk on a channel is adequately described by a simple four-state dynamical system whose capacity boundary is where small disturbances stop decaying, so continuous-versus-calendar boundary comparison is the right object for fielding claims.

Editorial extensions

If this is right

  • Security teams must record release period, release fraction, rings, hard delay, residual-pressure evidence, and rate scenario before treating MTTR as fielding proof.
  • Deployment rings at fixed per-asset cadence do not recover continuous fielding and cannot be used as verbal assurance.
  • Cohort staggering can help or hurt near capacity and must be checked as evidence, not assumed.
  • Coarser trains (for example bimonthly) produce larger, more easily resolved discounts than monthly ones with the same mean lag.
  • When residual-pressure evidence is coarse relative to the discount, the correct output is an input-resolution finding rather than a forced pass or warning.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • Patch and change-management tooling may need to expose the same telemetry fields the audit requires so governance claims can be recomputed rather than asserted from ticket means.
  • Organizations that improve reported MTTR while lengthening release trains may be silently increasing calendar discount even as dashboards look healthier.
  • The same continuous-versus-batch diagnostic could apply to other security processes such as detection-rule deployment or identity-policy rollout.
  • Public CVE scoring remains prioritization context only; local residual-pressure ledgers stay necessary for capacity claims.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 5 minor

Summary. The paper argues that MTTR, SLA compliance, and related mean remediation metrics are useful governance indicators but are not fielding models: two processes can share the same reported mean lag while exposing the estate to different release geometry (windows, partial backlog clearing, rings, emergency bypass). It defines a remediation-cadence audit packet (routine mean lag m, period T, release fraction α, cohort geometry, emergency/routine split, hard-delay budget τ_Σ, residual-pressure interval I_L, rate scenario), compares a continuous same-mean shortcut with a calendar-aware release process, and reports a local capacity verdict plus a calendar discount Δ_cal = (L_cont_crit − L_cal_crit)/L_cont_crit. Worked notional packets with fixed m = 30 days and τ_Σ/m = 0.5 give discounts of about 17.4% (T/m = 2), 5.2% (monthly), and 1.3% (two-week) under a normalized screening scenario; a κ band keeps the qualitative reading; rings at fixed per-asset cadence do not recover the continuous boundary; cohort staggering can help or hurt near capacity. The contribution is framed as a reproducible governance diagnostic, not a breach predictor or CVE prioritizer.

Significance. If the capacity semantics are accepted, the paper makes a useful and well-scoped contribution to security-operations measurement and remediation governance. The calendar-discount concept, the audit-record/status table, and the evidence-resolution reading (when Δ_cal is material relative to I_L width or claimed headroom, do not use MTTR alone) are practical and clearer than mean-only dashboards. Strengths that should be credited: careful non-overclaiming (notional ledger, screening rates, limitations section); independent numerical checks of finite boundaries, hard-delay placement invariance, ring limits, and staggering (Tables 11–14, Appendix D); a rate-scenario band; the model-independent same-mean non-equivalence argument in Appendix C; and a stated reproducibility package. The qualitative point that matching mean lag does not match fielding dynamics is independently valuable even if specific L_crit numbers move under alternative backends.

major comments (3)
  1. [§2, §4, Appendix A (A.1–A.11)] The central governance claim—that a material calendar discount means MTTR/SLA should not be used alone as fielding evidence—depends on the operational meaning of L_cont_crit and L_cal_crit. Those boundaries are defined as zero real-part principal root / unit spectral radius for the four-state local channel of Appendix A (Eqs. A.1–A.11), with residual pressure L entering only through the √L couplings. The manuscript does not show that enterprise residual pressure after controls, or attacker technique share, evolves under that structure; rates are a screening convention and the residual ledger is notional. Without structural sensitivity (different order, coupling, multi-channel) or a clearer claim hierarchy that separates model-independent non-equivalence (Appendix C) from model-dependent percentages, the reported 17.4%/5.2%/1.3% discounts risk being treated as capacity loss when they are
  2. [§5 Table 10; §3 Tables 5–6] Table 10’s practical discount bands (“below ~3%”, “3–8%”, “8–15%”, “above ~15%”) and the headline “resolved cadence warning” for the bimonthly packet (Tables 5–6) treat materiality relative to residual-pressure resolution as if those cutoffs were operationally grounded. They are audit language under one normalized delayed scenario (L_cont_crit ≈ 2.767, τ_Σ/m = 0.5). The paper should either derive materiality thresholds from stated headroom/uncertainty rules that do not depend on the particular L scale of the backend, or mark the bands and the worked I_L placement as illustrative under the declared screening convention so readers do not import 5% or 17% as portable policy numbers.
  3. [§3 Eq. (2), Table 4; Table 2] The residual-pressure construction (Eq. 2, Table 4) is a minimal two-by-two substitution ledger mapped to a scalar L = s². That is acceptable for a method paper, but the governance statuses in Table 2 (especially “resolved cadence warning” vs “calendar-discount finding”) inherit the scale and contrast definition of that ledger. Production guidance should require a stated mapping from BAS/control-validation evidence to the same L that enters the characteristic equation, or the audit should report discount and geometry findings without forcing an inside/outside verdict on an uncalibrated L. As written, the bridge from local evidence to L_crit comparison is underspecified relative to the strength of the management reading in §3.
minor comments (5)
  1. [§2 Figure 1, Table 1] Figure 1 and Table 1 are clear; consider adding a one-line mapping from each audit field to the backend symbol (m, T, α, τ_Σ, L) so operations readers can connect the packet to Appendices A–D without hunting.
  2. [§1] The relationship to the companion implementation-filter paper [1] should be stated more sharply in the introduction: what is reused unchanged versus what is new in the audit interface, so novelty is not ambiguous for readers who only see this manuscript.
  3. [§6 Table 12] Table 12: note explicitly that the bimonthly discount is non-monotone in κ (already mentioned in text) in the table caption so the band is not misread as monotone capacity loss.
  4. [Abstract, §1, §9] Minor consistency: abstract says monthly train “5.2%” and later “about 5%”; keep one reported precision when the same screening case is restated in §1 and §9.
  5. [§5; Appendix C] Appendix C’s transfer-function counterexample is one of the clearest model-light arguments in the paper; consider a short forward pointer from §5 so readers who skip appendices still see that same-mean non-equivalence does not require the full capacity machinery.

Circularity Check

1 steps flagged · score 2.0 of 10

Mild self-citation of the author's implementation-filter backend supplies capacity-boundary semantics; the audit interface, discount definition, and worked packets are not circular by construction.

  1. self citation load bearing [§1 Introduction; §7 Related work; Appendix A; Ref. [1]]
    "The technical backend extends an implementation-filter mechanism, but the contribution here is the security-operations audit built on top of it [1]. ... [1] A. Omelchenko. Implementation filters and delay-budget instability in coupled replicator–mutator dynamics. arXiv preprint arXiv:2607.00227, 2026."

    The numerical capacity boundaries Lcont_crit and Lcal_crit (and thus the headline discounts 17.4%/5.2%/1.3%) are computed from the four-state local-channel system with √L coupling whose structure is imported from the author's own prior arXiv preprint. The audit's governance reading treats those boundaries as the right objects for inside/outside capacity. This is load-bearing self-citation of the backend semantics, not an independent external theorem; however, the paper also states the equations, derives the small-cadence expansion, and supplies an independent numerical map (Appendix D), so the reduction is partial rather than a pure definitional loop.

full rationale

The paper's derivation chain is largely self-contained and non-circular. Calendar discount is defined as (Lcont_crit − Lcal_crit)/Lcont_crit and computed by comparing two different fielding representations (continuous catch-up vs. release-window map) that are mean-matched via mcal = T/2 + T(1−α)/α; same mean lag does not force equal stability boundaries, as Appendix C shows via distinct transfer functions H(z). Capacity boundaries come from characteristic-equation / spectral-radius conditions (A.3–A.11) that are not tautological with the input mean lag. The residual-pressure ledger (Table 4) is explicitly notional and selected for exposition so IL sits between boundaries; the paper does not fit L to data and then call the placement a prediction. The only mild circularity-adjacent element is load-bearing dependence on the author's prior implementation-filter framework [1] for the four-state channel and √L coupling that define what Lcrit means; that is self-citation of the backend, not a definitional reduction of the audit claim. No uniqueness theorem is imported to forbid alternatives, no fitted parameter is renamed as prediction, and no known empirical pattern is merely re-labeled. Score 2 reflects proportionate treatment of one self-citation that is partially load-bearing for the numerical discounts while the governance interface remains independent content.

Assumptions & free parameters 4 free parameters · 4 assumptions · 3 invented entities

The central governance claim rests on a local dynamical model of defender/attacker adaptation, a mean-matching convention that isolates release geometry, a notional residual-pressure construction, and a normalized rate screening convention. These are the free choices and background objects a reader must accept; public CVE/EPSS/KEV data are explicitly not used for L.

free parameters (4)
  • normalized local rates μ_X = μ_Y = κ = 1 (screening convention)
    Default rate scenario used for all headline discounts; production audits must declare or band this choice (Table 12 shows 16-fold κ sensitivity).
  • notional residual-pressure ledger cells (Table 4) and resulting L ≈ 2.706, I_L = [2.657, 2.756]
    Hand-selected 0–2 scores chosen to instantiate a resolved cadence-sensitive packet; not fitted to enterprise data.
  • routine mean lag m = 30 days and hard-delay budget τ_Σ/m = 0.5
    Fixed timing anchors for all worked packets; change either and the numerical discounts move.
  • mean-matched release fraction α(T) = T / (m + T/2)
    Enforces same mean lag across calendars so geometry, not average speed, is isolated; production α should come from telemetry instead.
assumptions (4)
  • ad hoc to paper Local adaptive channel obeys the four-state ODE system (A.1) with fielding law either continuous catch-up (A.2) or synchronized release update (A.5–A.6), and capacity is the L at which the principal growth rate is zero.
    Core modeling choice imported/extended from the author’s prior implementation-filter work; not derived from enterprise incident data in this paper.
  • domain assumption Residual attacker pressure after local controls is summarized by a scalar L (or interval I_L) obtained from a centered contrast of a posture×technique ledger, L = s².
    Section 3 two-by-two convention; assumes differential substitution pressure is the right one-dimensional input to the capacity calculation.
  • standard math Idealized same-mean fielding lag under uniform arrival phase and geometric backlog clearing is m_cal = T/2 + T(1−α)/α.
    Standard waiting-time plus geometric residual for synchronized windows; used throughout worked packets (Eq. 3 / A.12).
  • domain assumption Public severity/exploit signals (CVSS, EPSS, KEV) cannot replace local residual-pressure evidence for the audited channel.
    Stated repeatedly in §1–2 and Table 3; scopes the audit away from prioritization scores.
invented entities (3)
  • calendar discount Δ_cal = (L_cont_crit − L_cal_crit) / L_cont_crit
    purpose: Quantifies fraction of mean-only local capacity consumed by the recorded release calendar; turns cadence into an evidence-resolution question.
    Primary new governance quantity; defined in §2 and used as the main output alongside inside/outside verdict.
  • remediation-cadence audit packet and status table (mean-only adequate, resolved cadence warning, calendar-discount finding, etc.)
    purpose: Operational record joining timing, geometry, hard delay, residual-pressure interval, and rate scenario into a single governance object.
    Table 1–2 and Figure 1; the paper’s main methodological product.
  • local residual-pressure interval I_L from a substitution ledger mapped to capacity boundaries
    purpose: Local attacker-side pressure after controls, used to place the channel relative to continuous and calendar-aware thresholds.
    Not a public CVE score; constructed in §3 and required for every production run.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Mean Time to Remediate Is Not a Fielding Model: A Cadence Audit for Enterprise Vulnerability Management." pith.science (2026). https://pith.science/paper/VXWSBGVW

@misc{pith2026260704511,
  author       = {Pith},
  title        = {Pith review of: Mean Time to Remediate Is Not a Fielding Model: A Cadence Audit for Enterprise Vulnerability Management},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/VXWSBGVW}},
  note         = {Machine review of arXiv:2607.04511}
}
read the original abstract

Enterprise security teams commonly summarize remediation through mean time to remediate (MTTR), SLA compliance, dwell time, or detection delay. These metrics are useful, but they can hide how fixes actually reach the estate: continuously, through scheduled maintenance windows, in deployment rings, or through emergency bypass paths. This paper introduces a remediation-cadence audit for enterprise vulnerability management. The audit records routine mean lag, release period, release fraction, cohort geometry, emergency/routine split, non-fielding delay, local residual-pressure evidence, and declared rate scenario. It compares a continuous same-mean shortcut with the recorded release calendar and reports a local capacity verdict plus a calendar discount: the fraction of mean-only local capacity consumed by calendarized fielding. Worked notional packets with the same 30-day mean lag show why this matters. Under the normalized screening scenario, a two-month release train consumes 17.4\% of mean-only capacity, a monthly train 5.2\%, and a two-week screen 1.3\%; across a 16-fold attacker-adjustment rate band, the two-month discount remains at least about 12\% and the monthly discount stays in the resolution-sensitive 3--8\% range. The audit therefore turns cadence assessment into an evidence-resolution question: when the discount is material relative to residual-pressure uncertainty or claimed headroom, MTTR/SLA should not be used alone as fielding evidence. Release-geometry checks show that deployment rings do not automatically recover the continuous benchmark, and cohort staggering can help or hurt near capacity. The result is a reproducible governance diagnostic, not a breach predictor or CVE prioritizer.

Figures

Figures reproduced from arXiv: 2607.04511 by the authors.

Figure 1
Figure 1. Remediation-cadence audit workflow. The audit does not treat MTTR as a fielding model. It [PITH_FULL_IMAGE:figures/full_fig_p005_1.png] view at source ↗
Figure 2
Figure 2. Calendar discount under the normalized delayed scenario used in the worked packets. Coarser [PITH_FULL_IMAGE:figures/full_fig_p011_2.png] view at source ↗
Figure 3
Figure 3. Independent boundary check for the monthly audit point. The calendar-aware boundary stabilizes [PITH_FULL_IMAGE:figures/full_fig_p021_3.png] view at source ↗
Figures from the paper (2 more)
Figure 4
Figure 4. Figure 4: Increasing the number of equal-phase cohorts at fixed monthly per-asset cadence converges to a [PITH_FULL_IMAGE:figures/full_fig_p023_4.png]
Figure 5
Figure 5. Figure 5: Cohort phasing is a regime-dependent design variable. Staggering can improve or worsen the local [PITH_FULL_IMAGE:figures/full_fig_p024_5.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

37 extracted references · 9 canonical work pages

  1. [1]

    Omelchenko

    A. Omelchenko. Implementation filters and delay-budget instability in coupled replicator–mutator dynamics. arXiv preprint arXiv:2607.00227, 2026

  2. [2]

    Verendel

    V. Verendel. Quantified security is a weak hypothesis: A critical survey of results and assumptions. InProceedings of the 2009 New Security Paradigms Workshop, pages 37–50, 2009. DOI: 10.1145/1719030.1719036

  3. [3]

    Pendleton, R

    M. Pendleton, R. Garcia-Lebron, J.-H. Cho, and S. Xu. A survey on systems security metrics.ACM Computing Surveys, 49(4), Article 62, 2017. DOI: 10.1145/3005714

  4. [4]

    stealthy takeover

    M. van Dijk, A. Juels, A. Oprea, and R. L. Rivest. FlipIt: The game of “stealthy takeover”.Journal of Cryptology, 26(4):655–713, 2013. DOI: 10.1007/s00145-012-9134- 5

  5. [5]

    J.-H. Cho, D. P. Sharma, H. Alavizadeh, S. Yoon, N. Ben-Asher, T. J. Moore, D. S. Kim, H. Lim, and F. F. Nelson. Toward proactive, adaptive defense: A survey on moving target defense.IEEE Communications Surveys & Tutorials, 22(1):709–745, 2020. DOI: 10.1109/COMST.2019.2963791

  6. [6]

    Sengupta, A

    S. Sengupta, A. Chowdhary, A. Sabur, A. Alshamrani, D. Huang, and S. Kambhampati. A survey of moving target defenses for network security.IEEE Communications Surveys & Tutorials, 22(3):1909–1941, 2020

  7. [7]

    Pawlick, E

    J. Pawlick, E. Colbert, and Q. Zhu. A game-theoretic taxonomy and survey of defensive deception for cybersecurity and privacy.ACM Computing Surveys, 52(4), Article 82,

  8. [8]

    DOI: 10.1145/3337772. 35

Show all 37 references
  1. [9]

    Eshghi, M

    S. Eshghi, M. H. R. Khouzani, S. Sarkar, and S. S. Venkatesh. Optimal patching in clustered malware epidemics.IEEE/ACM Transactions on Networking, 24(1):283–298, 2016

  2. [10]

    Taynitskiy, E

    V. Taynitskiy, E. Gubar, and Q. Zhu. Optimal impulse control of SIR epidemics over scale-free networks. arXiv:1810.04797, 2018

  3. [11]

    Allodi and F

    L. Allodi and F. Massacci. Comparing vulnerability severity and exploits using case- control studies.ACM Transactions on Information and System Security, 17(1), Article 1, 2014. DOI: 10.1145/2630069

  4. [12]

    Holm and K

    H. Holm and K. K. Afridi. An expert-based investigation of the Common Vulnerability Scoring System.Computers & Security, 53:18–30, 2015. DOI: 10.1016/j.cose.2015.04.012

  5. [13]

    Jacobs, S

    J. Jacobs, S. Romanosky, I. Adjerid, and W. Baker. Improving vulnerability remediation through better exploit prediction.Journal of Cybersecurity, 6(1):tyaa015, 2020. DOI: 10.1093/cybsec/tyaa015

  6. [14]

    Jacobs, S

    J. Jacobs, S. Romanosky, B. Edwards, M. Roytman, and I. Adjerid. Exploit prediction scoring system (EPSS).Digital Threats: Research and Practice, 2(3), Article 20, 2021. DOI: 10.1145/3436242

  7. [15]

    A. Shah, K. A. Farris, R. Ganesan, and S. Jajodia. Vulnerability selection for re- mediation: An empirical analysis.The Journal of Defense Modeling and Simulation, 19(1):13–22, 2022. DOI: 10.1177/1548512919874129

  8. [16]

    Prioritization to Prediction, Volume 3: Winning the Remediation Race

    Kenna Security and Cyentia Institute. Prioritization to Prediction, Volume 3: Winning the Remediation Race. Technical report, 2019. URL:https://www.cyentia.com/ p2p-vol3-wade/. Accessed: July 5, 2026

  9. [17]

    Patching Cadence Risk Vector: Core Overview

    BitSight. Patching Cadence Risk Vector: Core Overview. BitSight Help Center, 2026. URL:https://help.bitsighttech.com/hc/en-us/articles/ 231647627-Patching-Cadence-Risk-Vector-Core-Overview. Accessed: July 5, 2026

  10. [18]

    Common Vulnerability Scoring System version 4.0 specification

    Forum of Incident Response and Security Teams. Common Vulnerability Scoring System version 4.0 specification. FIRST, 2023. URL:https://www.first.org/cvss/v4.0/ specification-document. Accessed: July 5, 2026

  11. [19]

    Known Exploited Vulnerabilities Catalog

    Cybersecurity and Infrastructure Security Agency. Known Exploited Vulnerabilities Catalog. U.S. Department of Homeland Security, 2026. URL:https://www.cisa.gov/ known-exploited-vulnerabilities-catalog. Accessed: July 5, 2026

  12. [20]

    Binding Operational Directive 26- 04: Prioritizing Security Updates Based on Risk

    Cybersecurity and Infrastructure Security Agency. Binding Operational Directive 26- 04: Prioritizing Security Updates Based on Risk. U.S. Department of Homeland Security, June 10, 2026. URL:https://www.cisa.gov/news-events/directives/ bod-26-04-prioritizing-security-updates-ba...

  13. [21]

    MITRE ATT&CK: Enterprise matrix and techniques

    MITRE Corporation. MITRE ATT&CK: Enterprise matrix and techniques. MITRE,

  14. [22]

    Accessed: July 5, 2026

    URL:https://attack.mitre.org/matrices/enterprise/. Accessed: July 5, 2026

  15. [23]

    Apache CALDERA: A scalable, automated adversary emulation platform

    Apache Software Foundation. Apache CALDERA: A scalable, automated adversary emulation platform. Project website, 2026. URL:https://caldera.apache.org/. Accessed: July 5, 2026

  16. [24]

    Atomic Red Team: MITRE ATT&CK-mapped tests for security teams

    Red Canary. Atomic Red Team: MITRE ATT&CK-mapped tests for security teams. Projectwebsite, 2026. URL:https://www.atomicredteam.io/.Accessed: July5, 2026

  17. [25]

    NIST Special Publication 800-53A Revision 5, National Institute of Standards and Technology, 2022

    Joint Task Force.Assessing Security and Privacy Controls in Information Systems and Organizations. NIST Special Publication 800-53A Revision 5, National Institute of Standards and Technology, 2022. DOI: 10.6028/NIST.SP.800-53Ar5

  18. [26]

    Souppaya and K

    M. Souppaya and K. Scarfone.Guide to Enterprise Patch Management Planning: Pre- ventive Maintenance for Technology. NIST Special Publication 800-40 Revision 4, Na- tional Institute of Standards and Technology, 2022. DOI: 10.6028/NIST.SP.800-40r4

  19. [27]

    Update release cycle for Windows clients

    Microsoft. Update release cycle for Windows clients. Microsoft Learn documentation, March 27, 2025. URL:https://learn.microsoft.com/en-us/windows/deployment/ update/release-cycle. Accessed: July 5, 2026

  20. [28]

    Schedule recurring updates for machines by using the Azure portal and Azure Policy

    Microsoft. Schedule recurring updates for machines by using the Azure portal and Azure Policy. Microsoft Learn documentation, August 21, 2025. URL:https: //learn.microsoft.com/en-us/azure/update-manager/scheduled-patching. Ac- cessed: July 5, 2026

  21. [29]

    Open Source Vulnerabilities database

    OSV.dev. Open Source Vulnerabilities database. OSV, 2026. URL:https://osv.dev/. Accessed: July 5, 2026

  22. [30]

    GitHub Advisory Database

    GitHub. GitHub Advisory Database. GitHub, 2026. URL:https://github.com/ advisories. Accessed: July 5, 2026

  23. [31]

    Zhang, M

    W. Zhang, M. S. Branicky, and S. M. Phillips. Stability of networked control systems. IEEE Control Systems Magazine, 21(1):84–99, 2001

  24. [32]

    Hetel, J

    L. Hetel, J. Daafouz, and C. Iung. Stabilization of arbitrary switched linear systems with unknown time-varying delays.IEEE Transactions on Automatic Control, 51(10):1668– 1674, 2006

  25. [33]

    K. Gu, V. L. Kharitonov, and J. Chen.Stability of Time-Delay Systems. Birkhauser, 2003

  26. [34]

    Fridman.Introduction to Time-Delay Systems: Analysis and Control

    E. Fridman.Introduction to Time-Delay Systems: Analysis and Control. Birkhauser, 2014

  27. [35]

    Breda, S

    D. Breda, S. Maset, and R. Vermiglio. Pseudospectral differencing methods for charac- teristic roots of delay differential equations.Applied Numerical Mathematics, 56:318– 331, 2005. 37

  28. [36]

    Breda, S

    D. Breda, S. Maset, and R. Vermiglio.Stability of Linear Delay Differential Equations: A Numerical Approach with MATLAB. Springer, 2015

  29. [37]

    Breda, D

    D. Breda, D. Liessi, and R. Vermiglio. Piecewise discretization of monodromy operators of delay equations on adapted meshes.Journal of Computational Dynamics, 9:103–121, 2022. 38

Pith tools

Reviewed July 11, 2026 · model on record in the stance chip above.