https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

From the Industry


Getty Images

Sponsor Content

Fingerprint login authorization and cyber security concept. Blue integrated circuit with locks on background. Control access and authentication online.

Best Practices for Windows Patch Management

  • Written by Ivanti Guest Blogger
  • October 31, 2019
Implement a Windows patch management process that focuses on third-party application patching, as well as Windows OS patching.

With today’s security landscape, most IT and security professionals are aware of the importance of Windows patch management. However, many organizations choose to neglect the most important part of patch management—patching Windows applications (i.e., third-party applications) in addition to patching the Windows OS. Based on CVSS scores (the “risk score” associated with vulnerabilities), the riskiest applications not to patch are third-party applications and not the Windows OS itself.

Analyzing CVSS scores for Windows products (OS and third-party apps) shows that many of the “riskiest” products are third-party apps. This website provides a list of the top 50 products by total number of “distinct” vulnerabilities. Even though the list is ever changing, I can assume that at the time you will be viewing this page the number of third-party applications in this list will still be significant.

The obvious conclusion? You must implement a Windows patch management process that focuses on third-party application patching, as well as Windows OS patching.

In this post I’ll share my experience as a security product manager and offer some Windows patch management best practices.

  1. Scan your endpoints and servers for missing patches at least weekly—and for all products—even if you don’t intend to patch those products.

Why scan for everything when you only want to patch a smaller set of applications? Simply scanning for everything provides the needed visibility into your environment. Remember, bad guys don’t “care” about your internal Windows patch management processes. They’ll target unpatched applications whether you decide to patch them or not. Understanding your patch state with all applications helps you better understand your security posture and what you can do to improve it. Understanding your “patch” posture also becomes valuable when you get hacked.

  1. Define a set of operating systems and third-party applications that you “want” to patch–as many as you can. Every Patch Tuesday, start to roll out those patches to your endpoints and servers.

Most of the customers I speak with use Patch Tuesday as the “launching” date for a new patch “campaign.” This makes sense as many vendors release patches around the Patch Tuesday timeframe. The key here is to keep track of patches that are released after Patch Tuesday, and to make sure that new patches are always added to your Windows patch management queue.

It’s also very important to patch proactively, on a predefined cadence. Don’t wait for your security team to find vulnerabilities and ask you to patch them. Make sure you patch proactively so your security team doesn’t find un-patched applications in their security scans. Doing so will save time and allow the security team to focus on other security issues that can’t be automated.

Remember, even if you had a bad experience patching third-party applications in the past (Java?) and decided not to patch them, the bad guys most likely already have

  • Page 1
  • Page 2
Tags: MSPs Best Practices From the Industry Intelligence Security Strategy Ivanti Sponsor Content

Most Recent


  • Women in Technology
    National Women’s History Month: Developing a Career in Tech
    To be successful at tech, do tech and do it as well as anyone else.
  • Enterprise Connect 2023
    Enterprise Connect 2023 Expo Hall: RingCentral, VMware, Five9, Cisco, More
    “It’s as exciting as it gets,” a Microsoft official said of generative AI.
  • SMB
    New Comcast Business SD-WAN Solutions Put Focus on SMBs
    The solutions appeal to smaller businesses that don't necessarily need site-to-site connectivity.
  • Co-innovation Is Needed to Effect Energy Transformation
    Co-innovation Is Needed to Effect Energy Transformation
    The planet depends on greenhouse gas emissions going down and those in the ICT sector stepping up.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • M&A
    Why All MSPs Need to Understand the M&A Landscape
  • hurricane season
    4 Things MSPs Should Consider When Prepping for Hurricane Season
  • zero-trust
    The Benefits of Zero-Trust Security over VPNs
  • edge computing
    How to Keep Edge Computing Sites Truly Autonomous

Upcoming Events

View all

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Galleries

View all

Enterprise Connect 2023 Expo Hall: RingCentral, VMware, Five9, Cisco, More

March 31, 2023

HP’s Head of Global Channel Strategy Talks Program Changes, Poly Opportunity

March 31, 2023

National Women’s History Month: Channel Women’s Advice for Newbies

March 31, 2023

Industry Perspectives

View all

Co-innovation Is Needed to Effect Energy Transformation

March 31, 2023

AI Spells the End of End User Security

March 30, 2023

Why You Should Include Audiovisual Solutions in Your UC Services

March 28, 2023

Webinars

View all

Give Customers the Power: How MSPs Can Leverage Cloud Choice

April 4, 2023

DE&I Dialogue: How the Right DE&I Initiatives Can Propel Your Business

April 5, 2023

Meet the 2023 Channel Futures Channel Influencers

April 13, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Kaseya, Post-Acquisition, Expanding ‘Well-Regarded’ Datto Partner Program

Aryaka ‘Driving Value to the Channel Community’ with Throttle

March 24, 2023

Coffee with Craig and James Episode 121: Hewlett Packard Enterprise

March 23, 2023

Real-Life M&A: Advice for a Successful Channel Deal

March 13, 2023

Twitter

ChannelFutures

The shortage of talent in the tech industry gives women a great opportunity to build a career in tech says… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

Check out our images from the expo floor at #EnterpriseConnect: @Microsoft @Zoom @GoTo @Cisco @googlecloud @ujetcx… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

Learn about @comcastbusiness and some of the trends partners are seeing with #SMB customers. @craigschlagbaum… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

🤔 Interested in expanding on your brand or building a business from square one? @SkySwitchSays explains everythin… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

Energy transformation and climate change calls for innovation now @VMware #channelpartners #energycrisis #technews… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

Predictions are important when shaping your 2023 expectations & goals. #ChannelFutures is here to help out. We aske… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

Mary Beth Walker on @HP adapting its partner program in response to partner feedback, and what latest launches mean… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

.@ConnectWise report shows cybercriminals will continue heavily targeting #MSPs in 2023. dlvr.it/Slnlrj https://t.co/eEY0pMLJaQ

March 31, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X