Startup DreamersStartup Dreamers
  • Home
  • Startup
  • Money & Finance
  • Starting a Business
    • Branding
    • Business Ideas
    • Business Models
    • Business Plans
    • Fundraising
  • Growing a Business
  • More
    • Innovation
    • Leadership
Trending

UFC Veteran Announces Retirement 2 Days Before Her 30th Birthday

July 4, 2025

How an Accident at Age 18 Led to a Business With $35M Sales

July 4, 2025

Venice Braces for Jeff Bezos and Lauren Sanchez’s Wedding

July 4, 2025
Facebook Twitter Instagram
  • Newsletter
  • Submit Articles
  • Privacy
  • Advertise
  • Contact
Facebook Twitter Instagram
Startup DreamersStartup Dreamers
  • Home
  • Startup
  • Money & Finance
  • Starting a Business
    • Branding
    • Business Ideas
    • Business Models
    • Business Plans
    • Fundraising
  • Growing a Business
  • More
    • Innovation
    • Leadership
Subscribe for Alerts
Startup DreamersStartup Dreamers
Home » 5 Essential Features For Integrated Vulnerability And Patch Management
Innovation

5 Essential Features For Integrated Vulnerability And Patch Management

adminBy adminSeptember 21, 20230 ViewsNo Comments5 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email

Brent McCarty is president of ESET.

Zero-day attacks may be headline grabbers, but cybersecurity researchers have long reported that unpatched known vulnerabilities are directly responsible for an even higher percentage of data breaches than unknown vulnerabilities. For example, the 2021 IBM X-Force Threat Intelligence Index reported that one-third of all data breaches resulted from unpatched vulnerabilities.

Known exploitable vulnerabilities are always among the top causes of cyber incidents because hackers actively scan for them. This drives a quicker, easier and more predictable attack vector versus developing zero-days. But when zero-day hacks emerge, or new high-risk vulnerabilities are disclosed, patching becomes an extremely high priority.

The recent MOVEit Transfer vulnerabilities, which enabled a ransomware group to exfiltrate data and extort money from hundreds of organizations before the vendor could even issue a fix, illustrates the urgency of being able to patch on demand or have the ability to quickly implement other mitigating steps if no patch is available.

Patch Management Challenges

Patch management is an aspect of vulnerability management that automates the deployment of vendor-issued patches to remediate security vulnerabilities and other bugs in software. It can be implemented on a regular schedule or upon triggering policies and procedures for newly identified vulnerabilities. Ad hoc patching can be prone to errors and omissions. In this way, teams can better verify that all recommended patches are applied correctly and that no endpoints are inadvertently left exposed—an extremely common issue.

Most organizations routinely scan their environments for vulnerabilities. But with over 23,000 new vulnerabilities identified in 2022 alone, backlogs and “patch fatigue” are commonplace, and patching activities should be prioritized according to organizational risk. In addition, patches often need to be tested in corporate environments for compatibility with existing solutions, both commercial and in-house applications.

Computing and/or network resource constraints can also impact an organization’s ability to successfully identify and combat threats. According to Ponemon, over 80% of security leaders admit delaying patches to reduce impacts on business operations.

The Importance Of Automation

These common challenges make integration, automation and flexibility across vulnerability and patch management essential for companies looking to improve cyber hygiene and IT efficiency. But many of today’s vulnerability and patch management solutions stop at the basics.

For companies looking to implement automated patch management, which features are most critical and why? These five top the list for businesses of all sizes.

1. Patching With Minimal Operational Impact

Many organizations need to factor the immediate demands of business operations into their patching schedules. Yet some vulnerabilities, like the recent Microsoft Outlook Elevation of Privilege Vulnerability, must be addressed on a wide scale immediately.

Teams need flexibility and control to simplify complex patching processes and dynamically balance competing demands. Being able to automatically prioritize the most critical updates and schedule the rest for off-peak times is a big productivity and potentially bottom-line boost.

2. Comprehensive Automated Patching Across Most Applications And Vulnerabilities

Patch management automation is only as good as the portfolio of third-party applications and common vulnerabilities and exposures (CVEs) a tool supports. Coverage for thousands of the most popular applications and most of the hundreds of thousands of numbered vulnerabilities is key to automating patching for both current and future applications.

This includes Microsoft Windows, Windows Server, Linux and macOS operating systems as well as Microsoft Office products, Adobe software, VMware tools, popular browsers, Zoom clients and other endpoint-based applications. Many patch management solutions support just a few hundred applications, which can complicate endpoint management with manual steps to patch unsupported systems.

3. Centralized Patch Management

A centralized, web-based management console for all patch management tasks can be essential for resource-limited IT teams. This can help quickly and easily assess vulnerabilities, monitor completion status, identify non-compliant systems and manage patching across a company’s entire IT infrastructure, ideally in concert with other endpoint management activities.

4. Vulnerability Filtering And Prioritization

Many companies have fallen victim to ongoing exploits that target years-old vulnerabilities because they can’t readily identify the systems that need patching. To efficiently align available patch management resources with company-specific risks, the ability to automatically filter, sort and prioritize vulnerabilities based on risk exposure score, severity and type is important. Being able to customize exception settings, such as scheduling lower priority patches during off-peak times, is also important in reducing manual effort, errors/omissions, unplanned application downtime and service level issues.

5. A Real-Time Patch Inventory

Knowing exactly what you’ve patched and when, what you’ve yet to patch, what you’ve decided not to patch and what you thought you patched but didn’t are all essential to patch management.

For example, you need the ability to register and track patching exceptions for specific applications, including patch name/number, associated CVEs, patch criticality, impacted applications, etc. An accurate real-time patch inventory lays the groundwork for compliance reporting, due diligence in incident response and planning and prioritizing your efforts as you bring backlogged patches up to date, coordinate patching around planned IT downtime or slow periods, etc.

Final Thoughts

Without robust patch management, data cannot be kept secure. But patching has historically been one of the most time-consuming tasks that IT admins face, and remote work and more cloud utilization make IT environments more diversified and harder to patch than ever.

For companies looking toward managed service providers (MSPs) and managed security service providers (MSSPs) to operationalize their patch management along with other core security and privacy needs, the five considerations above can help guide your search. This can help maximize risk reduction and business value for overworked IT teams while ensuring increasingly strict cyber insurance, regulatory, audit and market requirements are confidently met.

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Read the full article here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Articles

UFC Veteran Announces Retirement 2 Days Before Her 30th Birthday

Innovation July 4, 2025

Today’s NYT Mini Crossword Clues And Answers For Thursday, July 3

Innovation July 3, 2025

Today’s NYT Mini Crossword Answers For Wednesday, July 2

Innovation July 2, 2025

AI Investor Stuck At A Standstill? 3 Strategic Paths To Buy, Build, Or Partner With AI Vendors

Innovation July 1, 2025

First Pill For Obstructive Sleep Apnea Shows Promise In Phase 3 Study

Innovation June 30, 2025

Tick Problem Is Getting Worse, This Risk Index At Highest Level, 10/10

Innovation June 29, 2025
Add A Comment

Leave A Reply Cancel Reply

Editors Picks

UFC Veteran Announces Retirement 2 Days Before Her 30th Birthday

July 4, 2025

How an Accident at Age 18 Led to a Business With $35M Sales

July 4, 2025

Venice Braces for Jeff Bezos and Lauren Sanchez’s Wedding

July 4, 2025

Today’s NYT Mini Crossword Clues And Answers For Thursday, July 3

July 3, 2025

Before You Start Day Trading, Know These Stages

July 3, 2025

Latest Posts

Cloudflare Is Blocking AI Crawlers by Default

July 3, 2025

Today’s NYT Mini Crossword Answers For Wednesday, July 2

July 2, 2025

Why Entrepreneurs Should Stop Obsessing Over Growth

July 2, 2025

How the D’Amelios Turned TikTok Stardom Into a Snack Empire

July 2, 2025

AI Investor Stuck At A Standstill? 3 Strategic Paths To Buy, Build, Or Partner With AI Vendors

July 1, 2025
Advertisement
Demo

Startup Dreamers is your one-stop website for the latest news and updates about how to start a business, follow us now to get the news that matters to you.

Facebook Twitter Instagram Pinterest YouTube
Sections
  • Growing a Business
  • Innovation
  • Leadership
  • Money & Finance
  • Starting a Business
Trending Topics
  • Branding
  • Business Ideas
  • Business Models
  • Business Plans
  • Fundraising

Subscribe to Updates

Get the latest business and startup news and updates directly to your inbox.

© 2025 Startup Dreamers. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Press Release
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.

GET $5000 NO CREDIT