How Lightwell breaks the forced-upgrade cycle to keep your systems protected and your developers focused on innovation.
The Monday morning CISO nightmare
Picture this: It’s Monday morning. A critical, high-severity Common Vulnerabilities and Exposures (CVE) recently surfaced in an open source library buried deep within your core customer-facing application.
Your CISO rightfully demands an immediate fix to protect your data and brand reputation. But when you ask the application development lead to patch it, their face pales.
"To get that security patch," they explain, "we have to upgrade the entire library to the latest major version. That version introduces breaking changes, deprecates 3 of our key APIs, and will require weeks of rewriting code and running regression tests. Doing this will push back our critical product launch by at least a month."
This is the "upgrade tax." It's the silent, ongoing operational penalty modern enterprises pay every single time they must completely upgrade a software version to acquire a critical security patch.
Anatomy of the upgrade tax
It's estimated that up to 90% of the software in modern application stacks is built with freely available open source software components. While this accelerates initial innovation, it also creates an overwhelming, invisible downstream maintenance burden.
When a vulnerability surfaces, upstream community maintainers typically fix it only in the latest version of their software. For an enterprise with highly customized, interconnected production environments, upgrading is rarely a simple task. Companies typically aren't running on the latest version of an open source project, which creates a challenge. It triggers a painful chain reaction:
- Broken dependencies: Upgrading a single minor component can cascade throughout your stack, creating conflicts with other packages and breaking active, stable integrations.
- Wasted engineering hours: Highly compensated developers spend their weeks performing defensive maintenance, rewriting stable code, and chasing down broken APIs instead of building features that drive business growth.
- The risk versus risk dilemma: This forces IT leaders into an impossible corner. Do they run vulnerable code in production and risk a major security breach, or do they deploy an emergency upgrade and risk system downtime?
This tax drains your innovation budget, frustrates your engineering teams, and severely slows your time-to-market.
Decoupling security from upgrades: Enter Lightwell
What if you could stop paying this tax altogether? What if you could protect your code without changing how your software behaves?
That's the core breakthrough of Lightwell, a massive $5 billion joint commitment by IBM and Red Hat. Backed by a global force of over 20,000 engineers and advanced AI automation, Lightwell fundamentally changes how enterprises protect their software supply chains by decoupling security fixes from version upgrades.
Instead of demanding a migration to an entirely new major release, Lightwell delivers thoroughly tested, digitally signed security remediations built to fit seamlessly into your software stack—delivering critical fixes while preserving API compatibility and system stability. Through Lightwell Network, you gain access to a tested, certified, and rapidly growing catalog of remediated and rebuilt versions of open source libraries such as Java and Python.
Reclaiming your innovation budget
From a business perspective, Lightwell delivers a profound strategic advantage. It shifts the defensive security narrative from a costly bottleneck to an operational accelerator.
- Reclaim developer velocity: By eliminating the need for major version upgrades, your developers can focus on what they do best—writing revenue-generating code and deploying new business features.
- Speed vulnerability remediation: Your mean time to remediation (MTTR) drops from weeks of planning, manual code rewrites, and testing down to a rapid, automated deployment.
- Rely on enterprise open source experts: Red Hat has spent decades mastering the art of backporting patches at the platform level, starting with Red Hat Enterprise Linux (RHEL). Lightwell brings that same rigorous, field-tested methodology directly to the application layer and out to the wider open source community.
The future of enterprise open source security
In the age of AI-driven threat actors, waiting weeks to patch is no longer an option. But forcing constant, disruptive upgrades is a cure often as painful as the disease. Security and system stability don't have to be a zero-sum game.
With Lightwell, you can finally stop paying the upgrade tax and protect your organization at machine speed—without breaking your production environment or stalling your strategic roadmap.
Breaking the forced-upgrade cycle requires a fundamental reframing of application-layer security. When CISOs and engineering leads are no longer forced to trade velocity for protection, security shifts from an operational bottleneck to a core business driver.
To understand where your organization stands, consider using the AI Cyber Resilience Diagnostic for Lightwell to benchmark your open source reliance and identify where hidden maintenance burdens exist.
Lightwell newsletter
About the author
Gunnar Hellekson is Vice President and General Manager for the Lightwell business at Red Hat. Before that, he was the General Manager for Red Hat Enterprise Linux and Chief Strategist for Red Hat’s US Public Sector group. He is a founder of Open Source for America, one of Federal Computer Week’s Fed 100 for 2010, and was voted one of the FedScoop 50 for industry leadership. He was a founder of the Military Open Source working group, a member of the SIIA Software Division Board, and the Open Technology Fund Advisory Council. He perks up when people talk about commoditization and the industrial mobilization of World War II. He is also co-host of the Dave and Gunnar Show.
Prior to joining Red Hat, he worked as a developer, systems administrator, and IT director for a number of Internet businesses. He has also been a business and IT consultant to not-for-profit organizations in New York City. During that time, he spearheaded the reform of safety regulations for New York State’s electrical utilities through the Jodie Lane Project.
More like this
The new currency of enterprise velocity
Closing the loop: From network policy intent to verified reality
Can Compliance Be A Piece Of Cake? | Compiler
Collaboration In Product Security | Compiler
Keep exploring
- Security approaches for hybrid cloud environments
Whitepaper - A layered approach to container and Kubernetes securityWhitepaper
Browse by channel
Automation
The latest on IT automation for tech, teams, and environments
Artificial intelligence
Updates on the platforms that free customers to run AI workloads anywhere
Open hybrid cloud
Explore how we build a more flexible future with hybrid cloud
Security
The latest on how we reduce risks across environments and technologies
Edge computing
Updates on the platforms that simplify operations at the edge
Infrastructure
The latest on the world’s leading enterprise Linux platform
Applications
Inside our solutions to the toughest application challenges
Virtualization
The future of enterprise virtualization for your workloads on-premise or across clouds