September Patch Tuesday Commentary From Fortra

By Tyler Reguly, Associate Director, Security R&D, Fortra

I think it is safe to say that, as long as Microsoft is playing catch-up on patching vulnerabilities, numbers have lost all meaning. This is not a Microsoft specific problem… we see the same issue with Oracle and other large vendors that are being proactive. We need to remember that these large CVE counts are a good thing as we’re reducing attack surface before attackers get a chance to find and utilize the vulnerabilities. Eventually, all those long-standing, hard to find vulnerabilities will be fixed and Patch Tuesday will return to its typical cadence. Until that happens, prioritization is key and gift cards for extra coffee for your admins would likely be appreciated.

Even though I think it is temporary and we will return to manageable Patch Tuesday’s, I think it’s important that we acknowledge our current normal. Specifically, have you considered your people and processes during what could easily be called trying times? This is a great time to consider if your processes are designed to handle major changes and potential patching bottlenecks. While the number of patches may not have increased greatly (due to cumulative updates), they have increased as we see more and more one-off patches. How do you handle those one-off patches that may require a manual reinstall of the software or the extraction of a zip file to a specific location to overwrite a vulnerable version? These last few months may have disrupted your normal processes, so this is a great time to step back and really look at them. Are there places for improvement? What about your people. How are they handling the current levels of patches and the tickets that those produce. Are they managing? Are they struggling? Have you even stopped to ask them?

It’s time to put our CISOs and CSOs on notice. How are you helping your teams through these difficult times? Are you eliminating soak tests because some public guidance has suggested ridiculously short patch timeframes? Does that put added stress on your teams because they don’t know what outages they may see as a result? If you’re doing this… STOP! Patches still need to be tested because not all vendors can be trusted and many have broken the trust they had previously gained. Test your patches before you deploy them. Then, think about your deployment. Do you have your teams deploy after hours and on weekends to avoid disruption to the business environment? Do you reward them for that effort? Time to dig into your budget and buy dinner for your teams that are working on Saturday to get patches rolled out before users return to work on Monday.

Right now, if you are in charge of teams managing patches, you are probably struggling with what to do. Support your team, be aware of the difficulties they face, and ask them how things can be improved. If you still prioritize based on CVSS, you are hurting your organization and your employees. If you are constantly flip-flopping as guidance changes, you are putting your organization at risk and jeopardizing employee happiness. You are essentially steering a ship through rough waters, and you need a steady hand to accomplish that. If you keep the ship on course, your team will be able to do the rest.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading