Skip to content

Patch management

Most breaches exploit vulnerabilities that already had a patch. Patch management is the process of deploying updates in a timely, controlled way, balancing security and operational stability. It’s the executing arm of vulnerability management (Vulnerability management).

1. INVENTORY know what exists and at what version (foundation of all, see def-bastionado)
2. AWARENESS patch/advisory sources (vendor, CISA KEV, bulletins)
3. PRIORITIZE by risk (EPSS/KEV/exposure, see def-vulnmgmt)
4. TEST in a pre-production ring (avoid breaking production)
5. DEPLOY by rings/waves, with a change window and rollback ready
6. VERIFY confirm the patch applied and the vuln is closed
Emergency KEV / active exploitation / public exploit + exposed asset -> out of cycle
High critical/exposed -> short SLA
Normal monthly cycle (e.g. Microsoft Patch Tuesday)
Context Internet exposure and criticality weigh as much as CVSS

Ring deployment (reduces the risk of breaking)

Section titled “Ring deployment (reduces the risk of breaking)”
Ring 0 pilot/IT (catches patches that break)
Ring 1 a representative subset
Ring 2 the rest of production
-> stop the wave if a ring reveals problems; rollback ready
Windows WSUS, Microsoft Intune, SCCM/MECM, Autopatch
Linux package managers (apt/yum/dnf), unattended-upgrades, Ansible, Satellite/Landscape
Third-party third-party software (browsers, Java, readers) is usually the forgotten one
Firmware routers, switches, IoT/OT (see ot-*): slower and more critical cycles
- legacy/unpatchable systems -> mitigate (segment, virtual patching with IPS/WAF, isolate)
- OT/ICS (ot-ics): can't reboot lightly -> windows and compensations
- a patch that breaks -> that's why the test ring and rollback are non-negotiable
- "patching breaks things" is no excuse not to patch the exposed and exploited
  • Start from inventory and prioritize with def-vulnmgmt (EPSS/KEV/exposure), not just CVSS.
  • Deploy by rings with testing and rollback; clear SLAs and an emergency patch path out of cycle.
  • Verify actual application (don’t assume); measure coverage and mean time to patch.
  • For the unpatchable: compensating mitigation (segmentation Network hardening, virtual patching, hardening).
  • WannaCry/NotPetya (2017): exploited EternalBlue months after the patch existed (MS17-010).
  • Equifax (2017): unpatched Struts (CVE-2017-5638) → massive breach.
  • Log4Shell (2021) and MOVEit (2023): patching speed separated who was spared from who wasn’t.
  • Asset and version inventory (incl. third-party and firmware)
  • Advisory sources and CISA KEV tracking
  • Prioritization by risk (EPSS/KEV/exposure)
  • Test ring before production + rollback
  • Ring deployment with change windows
  • Emergency patch path (KEV/active exploit)
  • Post-deployment verification and time-to-patch metrics
  • Compensating mitigation for the unpatchable