From the Field: Patching

๐Ÿ”Ž ๐—™๐—ฟ๐—ผ๐—บ ๐˜๐—ต๐—ฒ ๐—™๐—ถ๐—ฒ๐—น๐—ฑ โ€” Real-World Findings from Security Assessments

๐Ÿ’ฅ ๐Ÿฏ๐Ÿฏ.๐Ÿฏ%ย of environments I assessed ๐—ฑ๐—ผ ๐—ป๐—ผ๐˜ ๐—ฝ๐—ฎ๐˜๐—ฐ๐—ต ๐˜๐—ต๐—ฒ๐—ถ๐—ฟ ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ ๐—ฑ๐—ฒ๐˜ƒ๐—ถ๐—ฐ๐—ฒ๐˜€ ๐—ฟ๐—ฒ๐—ด๐˜‚๐—น๐—ฎ๐—ฟ๐—น๐˜†

This one is honestly shocking. I still encounter systems that havenโ€™t been patched ๐—ณ๐—ผ๐—ฟ ๐—บ๐—ผ๐—ป๐˜๐—ต๐˜€ โ€” ๐˜€๐—ผ๐—บ๐—ฒ๐˜๐—ถ๐—บ๐—ฒ๐˜€ ๐—ฒ๐˜ƒ๐—ฒ๐—ป ๐˜†๐—ฒ๐—ฎ๐—ฟ๐˜€.

And yes, I know what many administrators think:

โ€œ๐™ˆ๐™ž๐™˜๐™ง๐™ค๐™จ๐™ค๐™›๐™ฉ ๐™ช๐™ฅ๐™™๐™–๐™ฉ๐™š๐™จ ๐™จ๐™ค๐™ข๐™š๐™ฉ๐™ž๐™ข๐™š๐™จ ๐™—๐™ง๐™š๐™–๐™  ๐™ฉ๐™๐™ž๐™ฃ๐™œ๐™จ, ๐™ฉ๐™๐™š๐™ฎ ๐™™๐™ค ๐™ฉ๐™๐™š ๐™ฉ๐™š๐™จ๐™ฉ๐™ž๐™ฃ๐™œ ๐™ค๐™ฃ ๐™ฅ๐™š๐™ค๐™ฅ๐™ก๐™š.โ€

That concern is understandable. โš ๏ธ But avoiding patching entirely is ๐—ณ๐—ฎ๐—ฟ ๐—ฟ๐—ถ๐˜€๐—ธ๐—ถ๐—ฒ๐—ฟย than implementing a proper patching process.

A mature approach ๐—ฑ๐—ผ๐—ฒ๐˜€๐—ปโ€™๐˜ ๐—บ๐—ฒ๐—ฎ๐—ป ๐—ถ๐—ป๐˜€๐˜๐—ฎ๐—น๐—น๐—ถ๐—ป๐—ด ๐˜‚๐—ฝ๐—ฑ๐—ฎ๐˜๐—ฒ๐˜€ ๐˜๐—ต๐—ฒ ๐—บ๐—ผ๐—บ๐—ฒ๐—ป๐˜ ๐—ฃ๐—ฎ๐˜๐—ฐ๐—ต ๐—ง๐˜‚๐—ฒ๐˜€๐—ฑ๐—ฎ๐˜† ๐—ฎ๐—ฟ๐—ฟ๐—ถ๐˜ƒ๐—ฒ๐˜€. It means:

๐Ÿ”น Monitoring early feedback and known issues

๐Ÿ”น Testing patches in a lab or pilot group

๐Ÿ”น Rolling updates to production in phases/waves

๐Ÿ”น Gradually including critical systems once stability is confirmed

๐—ง๐—ต๐—ถ๐˜€ ๐—ฏ๐—ฎ๐—น๐—ฎ๐—ป๐—ฐ๐—ฒ๐˜€ ๐˜๐—ต๐—ฒ ๐—ฟ๐—ฒ๐—ฎ๐—น ๐—ฟ๐—ถ๐˜€๐—ธ:

unpatched vulnerabilities ๐Ÿ†š potential update issues.

In many environments I assess, the real problem isnโ€™t technology โ€” itโ€™s the ๐—ฎ๐—ฏ๐˜€๐—ฒ๐—ป๐—ฐ๐—ฒ ๐—ผ๐—ณ ๐—ฎ ๐—ฑ๐—ฒ๐—ณ๐—ถ๐—ป๐—ฒ๐—ฑ ๐—ฝ๐—ฎ๐˜๐—ฐ๐—ต๐—ถ๐—ป๐—ด ๐—ฝ๐—ฟ๐—ผ๐—ฐ๐—ฒ๐˜€๐˜€. With tools like WSUS, Windows Update for Business, or MECM, implementing structured patch management is not that complicated.

๐—ฃ๐—ฒ๐—ฟ๐˜€๐—ผ๐—ป๐—ฎ๐—น๐—น๐˜†, after Patch Tuesday I closely follow community reports, test updates in a demo environment, and then roll them out gradually across environments. This approach ๐—ฎ๐˜ƒ๐—ผ๐—ถ๐—ฑ๐˜€ ๐˜‚๐—ป๐—ป๐—ฒ๐—ฐ๐—ฒ๐˜€๐˜€๐—ฎ๐—ฟ๐˜† ๐˜€๐˜๐—ฟ๐—ฒ๐˜€๐˜€ while keeping systems secure.

If you prefer having this research and early ๐˜๐—ฒ๐˜€๐˜๐—ถ๐—ป๐—ด ๐—ฑ๐—ผ๐—ป๐—ฒ ๐—ณ๐—ผ๐—ฟ ๐˜†๐—ผ๐˜‚, thatโ€™s exactly what ๐—œ ๐—ฝ๐—ฟ๐—ผ๐˜ƒ๐—ถ๐—ฑ๐—ฒ ๐˜๐—ต๐—ฟ๐—ผ๐˜‚๐—ด๐—ต ๐—›๐—ผ๐—ฟ๐—ถ๐˜‡๐—ผ๐—ป ๐—”๐—น๐—ฒ๐—ฟ๐˜ โ€” but many of you already know that. You can subscribe here:

๐Ÿ”— https://horizon-secured.com/newsletter/

How mature is your patching process today?