Patch Management Essential But Still Difficult To Achieve

28 November 2018by Abdallah Alhajeid

Effective and well-managed patch management has always been an essential element of any cyber security programme. The Gartner report, ‘Focus on the Biggest Security Threats” estimated that 99.96 of all cyber threats in 2017 were based on known software vulnerabilities. Despite their importance, many organisations still struggle to keep their operating systems and core business software applications updated with the latest security patches.

 

What is patch management?

All software that runs on a computer device contains security flaws. When discovered, these vulnerabilities are used by cyber criminals to steal confidential information directly or to create a transmission platform to infect another computer with malware. Reputable software vendors all provide fixes or ‘patches’ for their vulnerabilities. Users are advised to update the applications as soon as possible. Patch management refers to the systematic update of software applications to ensure they are resistant to cyber attack in the future.

 

Why is patch management poorly delivered?

Modern IT systems use multiple operating systems, on-premise applications, web applications and cloud-based services to support the needs of users. The number of applications and their complexity makes it is increasingly difficult to reduce the ‘attack surface’ of software vulnerabilities. This issue is made worse by the frequent use of third-party internet applications such as Java, Adobe, Mozilla, Firefox, Chrome, Flash, and OpenOffice.

Software patches from vendor companies are released frequently and often on a weekly basis. The task of updating this software and ensuring the productive use of an IT system is complex, time -consuming and often expensive. Patches could close ports, disable critical pieces of infrastructure, crash systems or cut availability – all potential scenarios that could leave businesses without the systems they need to operate or handle transactions.

 

Published for good and bad

Software vendor companies will also announce and release the details of their respective application vulnerabilities. These often include detailed instructions on how to compromise systems and applications. This information together with examples of related cyber security exploits is collated and freely published by hacker groups and Dark Web websites.

 

How to manage software patching

 

Comodo recommends the following tactics to deliver effective patch management:

 

Define the scope

All hardware and software owned and used by an organisation should be recorded in an asset inventory. This list should also include any SAS services provided by cloud providers. Particular attention should be paid to web browsers and their related plug-in web-applications.

 

Prioritise security risks

Security patches are usually of two types: highly critical ones and not-so-critical ones. Enterprise-critical security patches should be applied immediately without any delay. Essential but not so critical updates can be scheduled for completion within a weekly cycle.

 

Rollback options

Rollback is the process of reverting to old security patches if a newly deployed security patch is having a harmful effect.

 

Patch testing

Major security patches must be tested before they are deployed over the enterprise. Testing reduces the number of unexpected errors and the time and cost of any rollbacks.

 

Employ automation

Patch management or vulnerability management tools should be used to automate the delivery of mundane update tasks. Highly critical patches are identified and manually performed if required.

 

Patch management tools

There are many free and paid-for patch management software applications from vendors that include GFI Software, Panda Security, Comodo, ManageEngine and Microsoft. Most will handle the inventory, prioritisation, rollbacks and patch testing of software inside and outside the corporate network. The best tools aim to provide centralised, real-time visibility into the security status of software vulnerabilities, missing patches, updates and unsupported end-of-life (EOL) software. The very best will also offer immediate patching in the event of a breach and integration into the detection and correlation of threats using an Endpoint Detection and Response system.

 

—————–

 

Patch management is a key feature of the unique Wizard Cyber CYBERSHIELD-MDR service packages. We use Comodo and Panda Security applications to deliver manual and automated security updates to our customers.

Abdallah Alhajeid

WordPress Developer

WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-27001-scaled.png
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-9001-scaled.png
WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry

Copyright by Wizard Cyber. All rights reserved.

Copyright by Wizard Cyber. All rights reserved.

Contact Us
×
Contact Us
Need Cybersecurity Guidance? Get in touch with us!

Our experts are ready to help with your cybersecurity questions—book a conversation with us by clicking the button.

Book a Meeting
Funded Workshops
×
Funded Workshops
Explore Our Funded Microsoft Security Workshops

Click to learn more about each Microsoft-supported engagement

Book a Consultation