Qualys CTO Wolfgang Kandek discussed the length of time required to remediate the most widespread viruses and security flaws, dating back to before the internet and up until Heartbleed. After each major event, the industry responded - by building CERTs, by releasing regular patches (after Sasser), by engaging in working groups (after Conficker), and now the auditing of open source standards (after OpenSSL/Heartbleed). He remains concerned, however, about the long tail of devices as yet unpatched, and how this cycle might cope with the 'internet of things'.