Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Cyber resilience»Understanding the roadblocks to effective patch management (Page 5)
Cyber resilience

Understanding the roadblocks to effective patch management

Patch management is a basic requirement for cyber resilience but many organizations continue to struggle with this area. Muhammad Yahya Patel delves into why this is the case and what can be done about it.
May 23, 20247 Mins Read
safety cones illustrate the concept of roadblocks

The landscape of cybersecurity is fraught with challenges, not least of which is the daunting task of maintaining an up-to-date and secure network infrastructure. While there may be temptation to view patch management as a simple cost-benefit equation, this perspective overlooks the nuanced and often severe repercussions of inadequate vulnerability management. The failure to implement a robust patch management strategy can result in outcomes as damaging to business operations as any direct cyberattack. The roots of this inaction lie in a complex mix of risk aversion, financial considerations, and a stark shortage of skilled professionals equipped to navigate the intricacies of cybersecurity threats.

According to a survey backed by the Ponemon Institute, the average organization in 2024 has 3,000 applications stored on its endpoints, and almost two-thirds (59%) say that it takes at least two weeks to begin deployment after a patch has been released. Only 31% of patches are distributed via automation, putting an increased burden on manual human-led processes.

Central to the dilemma faced by many organizations is the issue of legacy systems – vital to the day-to-day operations yet notoriously difficult to update or replace without causing significant disruption. These systems, often running on outdated software that cannot easily be patched, present a unique challenge. The very processes that are critical to the organization’s success are the ones that make it most vulnerable. Vendors of such systems may offer limited or no support, leaving businesses in a precarious position: either depending on potentially insecure third-party solutions or placing an undue burden on already overstretched internal IT staff.

Real-world examples of patch vulnerabilities

The exploitation of known vulnerabilities can lead to devastating cyberattacks, as illustrated by the widespread impact of the Log4j vulnerability and the significant breach involving MOVEit Transfer and MOVEit Cloud (CVE-2023-34362). In May 2023, Progress identified a critical flaw in these systems that, if exploited, could allow attackers to gain escalated privileges and unauthorised access. Despite a rapid response that included the launch of an investigation, the provision of mitigation steps, and the release of a security patch within 48 hours, cybercriminals were quick to leverage this window of vulnerability. The Russian-affiliated ransomware group Clop executed a supply chain attack, targeting users of MOVEit and compromising the data security of prominent organizations, including Shell and British Airways.

The consequences of such attacks are far-reaching and severe, underscoring the critical importance of timely and effective patch management. Emsisoft reported that the Clop-initiated attack led to the exposure of personal information for more than 62 million individuals, marking it as the most significant hack of 2023. This incident not only highlights the tangible risk of data loss and corruption but also demonstrates the broader implications for operational integrity, regulatory compliance, and organizational reputation. The MOVEit incident serves as a stark reminder of the potential for significant harm that known vulnerabilities can cause when not promptly and adequately addressed.

Barriers to effective vulnerability management

Automated patch management has been a boon for businesses, but while efficient for routine upkeep, it harbors significant risks when it becomes the sole strategy. Automated systems are adept at handling standard patching tasks but falter in the face of the unexpected, particularly with complex or outdated legacy systems where compatibility and stability are crucial. The absence of rigorous testing before patch deployment can lead to a series of consequences, from operational disruptions and data integrity issues to the introduction of new security vulnerabilities.

The scarcity of resources and skilled professionals dedicated to vulnerability management is also a significant shortcoming. Viewing investment in cybersecurity as a sunk cost reflects a short-term mindset that prioritises immediate financial savings over long-term security benefits. This approach often breeds complacency and a willingness to tolerate risks that could be mitigated with appropriate resources. The reality is that patching is not only costly but also demands considerable time and expertise, with manual processes prone to error due to their complexity and repetitiveness. For large organizations, the challenge is magnified by the need to secure tens of thousands of systems across a diverse array of technologies, a task further complicated by the increasing prevalence of remote work. This environment demands a more comprehensive approach to resource allocation, where the value of investment is measured by the enhancement of organizational security, not just its immediate financial impact.

Back to basics: how and when to patch effectively

The best patch management strategy is a dual-focused one that leverages automation and manual upkeep together to keep an organization’s digital estate secure. Here is a breakdown of how and when patching should take place…

How to patch:

  • Prioritise critical systems: identify and update systems critical to business operations first to minimise potential impact on essential services. This ensures that the most vulnerable points in your network receive immediate attention.
  • Establish patch management policies: develop comprehensive policies that outline the procedures for patch management, including timelines for implementation. This creates a structured approach, ensuring consistency and accountability across the IT department.
  • Use automated tools with manual oversight: leverage automation for efficiency but supplement with manual checks to catch issues automation may miss. This dual approach balances speed with thoroughness, covering more ground without compromising on diligence.
  • Test patches in a controlled environment: deploy patches in a test environment to evaluate their impact before applying them broadly. This step helps avoid widespread issues by identifying potential conflicts or problems in a controlled setting.
  • Implement rollback procedures: prepare for the possibility of patch-induced problems by having a rollback plan in place. This ensures you can quickly revert changes, minimising downtime and preserving data integrity.
  • Coordinate with vendors: maintain open lines of communication with software and hardware vendors for up-to-date patch information. Vendors can offer crucial insights and support, aiding in a smoother patching process.

When to patch:

  • Adhere to a regular patching schedule: implement a consistent schedule for patching to ensure systems are routinely updated and secure. Regularity helps in mitigating risks proactively rather than reacting to threats after they’ve been exploited.
  • Prioritise based on risk: assess and prioritise patches based on the severity of the vulnerability and its relevance to your organization. This strategy ensures resources are allocated effectively, focusing efforts where they are needed most.
  • Emergency patching: act swiftly on critical vulnerabilities that could immediately jeopardise system security. Emergency patching is essential for closing potentially devastating security gaps without delay.
  • Conduct risk assessments: regular risk assessments help identify vulnerabilities and guide the prioritisation of patching efforts. Understanding your risk landscape allows for informed decision-making and more effective patch management.
  • Meet compliance requirements: ensure your patching strategy aligns with regulatory and compliance standards to avoid legal penalties and maintain trust. Compliance is not just a legal obligation but a component of maintaining operational and security standards.
  • Plan and communicate: effective planning and clear communication are vital for successful patch management. Coordination ensures all team members are informed of their responsibilities, reducing the risk of oversight and enhancing the efficiency of the patching process.

As well as the above steps, building robust relationships with vendors, actively engaging with their updates, and inquiring about prevalent vulnerability exploitations will fortify an organization’s knowledge base, enabling proactive defense measures. Investing in dedicated vulnerability management personnel ensures continuous scanning and assessment, while integrating threat intelligence becomes instrumental in prioritising responses effectively. Quick evaluation of vulnerabilities, especially in security products and devices exposed to the internet, is also crucial due to their potential for widespread impact. Above all, maintaining an incident response plan and embracing the evolving nature of vulnerability management underscore the importance of adaptability and vigilance, essential traits for safeguarding organizational assets against the ever-changing tide of cybersecurity threats.


The author

Muhammad Yahya Patel is lead security engineer at Check Point Software.

Africa Asia Asia Pacific Australasia Europe Middle East North America UK
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleCloud protection and backup trends explored
Next Article Key considerations and techniques for AI chatbot risk management

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
A digital twin test bay showing a large screen displaying a virtual boiler model synchronised with the physical unit during operational testing.

International cyber agencies publish guidance for isolating critical infrastructure systems during times of crisis

July 29, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?