https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • MSP 501 Rankings
    • NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Channel Futures 20: Top Tech Providers
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • MSP 501 Rankings
    • NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Channel Futures 20: Top Tech Providers
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

From the Industry


Getty Images

Sponsor Content

Fingerprint login authorization and cyber security concept. Blue integrated circuit with locks on background. Control access and authentication online.

Best Practices for Windows Patch Management

  • Written by Ivanti Guest Blogger
  • October 31, 2019
Implement a Windows patch management process that focuses on third-party application patching, as well as Windows OS patching.

automated tools that can leverage the vulnerabilities in those applications.

As a guideline, we recommend that our customers aim for 14 days SLA–to get ahead of most exploits. The Verizon DBIR from 2016 states that “Half of all exploitations happen between 10 and 100 days after the vulnerability is published.” The same report from 2019 states, “Every time a vulnerability is disclosed or a system update or patch is released, a hacker sees an opportunity. They research the disclosure or update notes to learn if they can exploit the vulnerability and where, searching for their best opportunity to monetize the vulnerability.”

At Ivanti, we recognize the challenge our customers are facing with the need to patch more in less time. One of our patch product goals is to provide tools that will allow our customers to reduce the operational risk associated with third-party application patching. Utilizing those tools one can predict the impact of deploying a patch before deploying it–minimizing the uncertainty involved in deploying patches.

  1. Start by deploying patches to pilot groups and extend your target groups as you get positive feedback about the patch’s quality.

This is the most common way customers patch. Yes, there are highly security-oriented customers that deploy patches to all their endpoints with minimal testing. For these customers, time-to-patch is more important than anything else. But for most of us, we have to balance security risk and operational risk. For example, we need to make sure patches don’t break applications before we deploy them to all our endpoints/servers.

The Windows patch-management best practice here is “simple”–start with a small pilot group of endpoints that represents the full set of applications that might be impacted by the patches. If the relevant users don’t report problems after their machines have been patched, expand the group to more users/application owners. Assuming you don’t receive negative feedback, move forward and deploy the patch to all endpoints and servers.

Please note that there are hidden challenges with this step. Most customers I speak with define their pilot groups based on what I call “friends of IT”–i.e., their friends in IT who are willing to volunteer as “guinea pigs” for testing those new patches. The challenge here is that, in most cases, there is no way of knowing in advance if those “testers” actually cover all the patch dependencies. For example, if you deploy a Java patch, can you tell for sure which applications depend on Java and, as a result, may break because of this Java patch?

Perhaps you had a bad experience with Java before, so you know about Java-dependent applications. But what about .NET dependencies or other low- or high-level technologies? Can you list all applications in your environment that depend on those patches? IT professionals use their experience and try to guess which users/endpoints should be part of the initial or secondary pilot groups. In some cases it works, but in others it doesn’t.

Fortunately, new Windows patch management technologies have been developed to remove the guesswork from this process and find the best candidates for each pilot group automatically. This allows a more accurate testing cycle, which in turn reduces the risk of business applications breaking when a third-party application patch is deployed.

One last tip: Make sure that every machine gets patched, including remote machines and machines that are rarely online.

Not all endpoints are always on—and not all endpoints are connected to the network all the time. An important Windows patch-management best practice is to ensure those devices get patched as soon as they go online or turn on. This can be managed and controlled with the right Windows patch management tools.

This guest blog is part of a Channel Futures sponsorship.

 

  • Page 1
  • Page 2
Tags: MSPs Best Practices From the Industry Intelligence Security Strategy Ivanti Sponsor Content

Most Recent


  • Choice of direction for Cisco partners
    Opportunities, Challenges Facing Cisco Partners
    Cisco Live was this week's event headliner. Reps from Computacenter, Molaprise, NTT and WWT weigh in on their experiences.
  • AWS partners get generative AI
    Jeff Kratz, Ruba Borno on Generative AI, More News for AWS Partners
    With AWS’ Public Sector Summit in full swing and an interview with Ruba Borno on hand, here’s a big update.
  • Pride Month 2023
    Pride Month 2023: Best Places to Work in Tech
    These companies are designated as 2022 “Best Places to Work for LGBTQ+ Equality.”
  • New details about NetApp Partner Sphere
    NetApp Reveals New Partner Sphere Program Details Ahead of Launch
    NetApp offers a glimpse into what partners can expect from its new slimmed down partner program.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • M&A
    Why All MSPs Need to Understand the M&A Landscape
  • hurricane season
    4 Things MSPs Should Consider When Prepping for Hurricane Season
  • zero-trust
    The Benefits of Zero-Trust Security over VPNs
  • edge computing
    How to Keep Edge Computing Sites Truly Autonomous

Upcoming Events

View all

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Channel Partners Conference & Expo

March 11, 2024 - March 14, 2024

Galleries

View all

Opportunities, Challenges Facing Cisco Partners

June 8, 2023

Jeff Kratz, Ruba Borno on Generative AI, More News for AWS Partners

June 8, 2023

Pride Month 2023: Best Places to Work in Tech

June 8, 2023

Industry Perspectives

View all

Identity Is Increasingly Valuable – and Targeted

May 18, 2023

Gaining a Competitive Advantage through AV Managed Services

May 10, 2023

How to Build an Organization That Attracts and Retains Talent

May 1, 2023

Webinars

View all

From Problem to Profit: Mastering the Science of Selling Using Business Outcomes

May 9, 2023

Meet the 2023 Channel Futures Channel Influencers

April 13, 2023

DE&I Dialogue: How the Right DE&I Initiatives Can Propel Your Business

April 5, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Coffee with Craig and James Episode No. 123: MartinWolf M&A Advisors, CP Expo Preview

UScellular Takes On Rivals with Partner Program Simplicity

April 21, 2023

OpenText Simplifying Deal Registration, Doubling Down on MDF

April 21, 2023

Everything-as-a-Service: CloudBlue Touts Critical Customer Transition

April 18, 2023

Twitter

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X