https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

From the Industry


Getty Images

Sponsor Content

Group of businessman working plan the business and analysis many chart graph for executive meeting consulting , vintage tone sunlight

7 Steps to Developing a Strong Patch Management Strategy

  • Written by Webroot Guest Blogger
  • February 28, 2020
Your patching strategy can make or break your—and your customers’—business.

We’ve all been there before. You log into your laptop, only to be greeted by a pop-up reading “Updates are ready to install.” If you’re like most people, you either click the “Remind Me Later” button or simply ignore the message. But system updates are designed to patch important security flaws in your operating system; by ignoring them, you create new security gaps that open your network up to vulnerabilities. This is why Windows 10 has removed the option for users to ignore or repeatedly delay updates.

Unpatched systems are playgrounds for hackers, especially those using automated exploit kits to secretly launch attacks. As an SMB or MSP, you might believe your company or clients safe, but, in reality, 43% of cyberattacks target small businesses. It’s therefore vital that they take initiative in applying preventative measures, and one of the simplest ways to do this is by keeping systems up to date with software patches. This is especially important to keep in mind if you’re running operating systems older than Windows 10.

How Cybercriminals Probe and Exploit Systems

Exploit kits are a quick and efficient way for hackers to find vulnerabilities in your unpatched software. In a recent Webroot podcast, Joe Panettieri compared exploit kits to the probe droids from “Star Wars: Empire Strikes Back” that scan the planet looking for any sign of a Rebel base. Similarly, exploit kits can “probe” or audit machines in search of vulnerabilities. When a flaw is discovered, they can automatically deliver malicious payloads like malware, ransomware or cryptomining scripts.

The EternalBlue attacks of 2017, which exploited an unpatched flaw in Windows XP’s file sharing protocol, were a good example of this strategy. Unfortunately, Windows systems make formidable targets for exploit kits. In fact, our research revealed that the number of IPs hosting Windows exploits grew 75% between January and June 2019 alone.

Microsoft itself has issued several major patch warnings for Windows 7, Windows 10 and Windows XP, noting that it’s “highly likely malicious actors will write an exploit” for older Windows systems. With the end of support for Windows 7 in January, now is the time to create a patch management strategy.

A Solid Patch Management Strategy Is Vital

An effective patch management strategy gives you a clear-cut process for deploying all missing software and application patches as soon as they’re announced. And when it comes to protecting against exploit kits, speed is crucial. Patch warnings often disclose the vulnerability, which can prompt cybercriminals to create exploit kits for out-of-date machines. This means that, as soon as you know about the security flaw, so do hackers. Currently, the average time to patch is 102 days. That gap is simply too large to be considered safe.

With the right patch management strategy, you’ll be less likely to delay or ignore important fixes when released.

Tips for Developing a Strong Patch Management Strategy

Ready to protect your business against exploits? Here are some steps every patch management strategy should include:

Step 1: Take an inventory of your IT devices, operating systems, OS versions and third-party applications.

Step 2: Categorize by risk and priority (using a high, medium or low score for each).

Step 3: Utilize virtual machines (VMs), and run patches on those environments first to perform patch validation. Back up your test data.

Step 4: Develop patch management policies by establishing when you will patch and what will be patched first. For example, “Every Friday, we patch Windows OS.”

Step 5: Roll out your patches and apply them as soon as possible. Use your RMM to patch and manage your own network and/or your SMB clients’ networks.

Step 6: Document your patch management processes and procedures.

Step 7: Keep up to date with vendor patch announcements.

What’s Next?

I encourage you to learn more about “locking down” your MSP business and your customers against exploit kits and other cybersecurity attacks by checking out our Lockdown Lessons series.

Start a free Webroot Endpoint protection trial and see for yourself how our solutions can help you prevent threats and maximize growth.

Tim Sheahen is senior director of sales.

This guest blog is part of a Channel Futures sponsorship.

Tags: MSPs Best Practices From the Industry Intelligence RMM/PSA Security Strategy Webroot Sponsor Content

Most Recent


  • HP's Dave McQuarrie at Amplify 2023
    HP Apologizes, Thanks Partners for Sticking with Them, Promises Improvements
    “We know it has not been easy,” HP chief commercial officer Dave McQuarrie told partners.
  • online survey
    Kaseya MSP Survey: Growing Importance of Automation, Cybersecurity Remains Top Challenge
    MSPs will need to be up to speed on their security offerings to meet SMB demand.
  • Cloud Roundup
    Google Cloud Lashes Out at Microsoft, New Hurdle for Broadcom-VMware
    This cloud computing wrap-up showcases some big news and happenings at more under-the-radar cloud firms.
  • Dell Precision Tower Feature
    Dell Adds Apex Managed Device Service to New Commercial PCs
    Dell is refreshing its Latitude and OptiPlex PCs and Precision workstations.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • human centered design
    Human-Centered Design Drove Design of New Management Console
  • Scary hacker
    Hacker Personas: A Deeper Look into Cybercrime
  • cyber resilience
    Why MSPs Need to Shift from Cyber Security to Cyber Resilience
  • Ransomware
    3 Ransomware Myths SMBs Unfortunately Believe

Upcoming Events

View all

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Galleries

View all

Kaseya MSP Survey: Growing Importance of Automation, Cybersecurity Remains Top Challenge

March 30, 2023

Google Cloud Lashes Out at Microsoft, New Hurdle for Broadcom-VMware

March 30, 2023

Dell Adds Apex Managed Device Service to New Commercial PCs

March 30, 2023

Industry Perspectives

View all

AI Spells the End of End User Security

March 30, 2023

Why You Should Include Audiovisual Solutions in Your UC Services

March 28, 2023

Selling Your MSP: Strategic vs. Financial Buyers

March 22, 2023

Webinars

View all

Give Customers the Power: How MSPs Can Leverage Cloud Choice

April 4, 2023

DE&I Dialogue: How the Right DE&I Initiatives Can Propel Your Business

April 5, 2023

Meet the 2023 Channel Futures Channel Influencers

April 13, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Kaseya, Post-Acquisition, Expanding ‘Well-Regarded’ Datto Partner Program

Aryaka ‘Driving Value to the Channel Community’ with Throttle

March 24, 2023

Coffee with Craig and James Episode 121: Hewlett Packard Enterprise

March 23, 2023

Real-Life M&A: Advice for a Successful Channel Deal

March 13, 2023

Twitter

ChannelFutures

.@Dell launches #DellLatitude and OptiPlex PCs, and Precision #workstations, adds Apex Managed Device Service.… twitter.com/i/web/status/1…

March 30, 2023
ChannelFutures

.@KaseyaCorp #MSP survey shows growing significance of automation, #cybersecurity remains clients' top challenge.… twitter.com/i/web/status/1…

March 30, 2023
ChannelFutures

.@HP thanks partners, promises to reduce wait times and complexity across organization. #HPAmplify… twitter.com/i/web/status/1…

March 30, 2023
ChannelFutures

.@Kyndryl #layoffs impacting a percentage of workforce. dlvr.it/SllFbF https://t.co/Bo77KdJMpx

March 30, 2023
ChannelFutures

[email protected] makes #DE&I a priority year-round, not just for @womenshistmonth. “A constant cadence of activism… twitter.com/i/web/status/1…

March 30, 2023
ChannelFutures

📺 Tune into the latest CFTV episode, brought to you by @HitachiVantara, all about how you can identify your competi… twitter.com/i/web/status/1…

March 30, 2023
ChannelFutures

“Things that are not possible are possible,” said @Google's @behshad_behzadi at #EnterpriseConnect about generative… twitter.com/i/web/status/1…

March 30, 2023
ChannelFutures

📺 We asked 2023 #ChannelInfluencer @peter_kujawa from Service Leadership what his secret sauce is- his work philoso… twitter.com/i/web/status/1…

March 30, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X