Patch management
Most breaches exploit vulnerabilities that already had a patch. Patch management is the process of deploying updates in a timely, controlled way, balancing security and operational stability. It’s the executing arm of vulnerability management (Vulnerability management).
The patching cycle
Section titled “The patching cycle”1. INVENTORY know what exists and at what version (foundation of all, see def-bastionado)2. AWARENESS patch/advisory sources (vendor, CISA KEV, bulletins)3. PRIORITIZE by risk (EPSS/KEV/exposure, see def-vulnmgmt)4. TEST in a pre-production ring (avoid breaking production)5. DEPLOY by rings/waves, with a change window and rollback ready6. VERIFY confirm the patch applied and the vuln is closedPrioritization and urgency
Section titled “Prioritization and urgency”Emergency KEV / active exploitation / public exploit + exposed asset -> out of cycleHigh critical/exposed -> short SLANormal monthly cycle (e.g. Microsoft Patch Tuesday)Context Internet exposure and criticality weigh as much as CVSSRing deployment (reduces the risk of breaking)
Section titled “Ring deployment (reduces the risk of breaking)”Ring 0 pilot/IT (catches patches that break)Ring 1 a representative subsetRing 2 the rest of production-> stop the wave if a ring reveals problems; rollback readyWindows WSUS, Microsoft Intune, SCCM/MECM, AutopatchLinux package managers (apt/yum/dnf), unattended-upgrades, Ansible, Satellite/LandscapeThird-party third-party software (browsers, Java, readers) is usually the forgotten oneFirmware routers, switches, IoT/OT (see ot-*): slower and more critical cyclesSpecial cases
Section titled “Special cases”- legacy/unpatchable systems -> mitigate (segment, virtual patching with IPS/WAF, isolate)- OT/ICS (ot-ics): can't reboot lightly -> windows and compensations- a patch that breaks -> that's why the test ring and rollback are non-negotiable- "patching breaks things" is no excuse not to patch the exposed and exploitedBlue Team / operation
Section titled “Blue Team / operation”- Start from inventory and prioritize with def-vulnmgmt (EPSS/KEV/exposure), not just CVSS.
- Deploy by rings with testing and rollback; clear SLAs and an emergency patch path out of cycle.
- Verify actual application (don’t assume); measure coverage and mean time to patch.
- For the unpatchable: compensating mitigation (segmentation Network hardening, virtual patching, hardening).
Real-world cases
Section titled “Real-world cases”- WannaCry/NotPetya (2017): exploited EternalBlue months after the patch existed (MS17-010).
- Equifax (2017): unpatched Struts (CVE-2017-5638) → massive breach.
- Log4Shell (2021) and MOVEit (2023): patching speed separated who was spared from who wasn’t.
Testing checklist
Section titled “Testing checklist”- Asset and version inventory (incl. third-party and firmware)
- Advisory sources and CISA KEV tracking
- Prioritization by risk (EPSS/KEV/exposure)
- Test ring before production + rollback
- Ring deployment with change windows
- Emergency patch path (KEV/active exploit)
- Post-deployment verification and time-to-patch metrics
- Compensating mitigation for the unpatchable