{"id":4634,"date":"2024-02-27T09:35:17","date_gmt":"2024-02-27T09:35:17","guid":{"rendered":"https:\/\/mintivo.co.uk\/?p=4634"},"modified":"2024-02-28T13:38:31","modified_gmt":"2024-02-28T13:38:31","slug":"what-is-patch-management","status":"publish","type":"post","link":"https:\/\/mintivo.co.uk\/news\/what-is-patch-management\/","title":{"rendered":"What is Patch Management?"},"content":{"rendered":"\n

Patch Management is essential to your organisation\u2019s security and productivity, but what exactly is patch management and why do you need a patch management strategy?<\/p>\n\n\n\n

What is patching?<\/h2>\n\n\n\n

Similar to a medical patch, or plaster put on a cut to the skin to make it better, a software patch will correct errors in software code. These errors are sometimes called vulnerabilities or bugs and they can cause various issues with your servers and operating systems, but most seriously, if they are not patched, they can enable threat actors to exploit them, and therefore damage your business. Once a software vulnerability has been detected in firmware, operating systems or third-party applications they are published (often called a \u2018known vulnerability\u2019). Criminal hackers take advantage of these known vulnerabilities if they are not properly patched or updated quickly.<\/p>\n\n\n\n

Patching is the process of activating the updates provided by the software provider. Software patch management can include code changes and other software updates. Server patch management specifically updates servers. There are different types of patching, usually referred to as security patches, bug fix patches and feature update patches.<\/p>\n\n\n\n

Patches therefore ensure your system is as secure as possible. They can also add new functionality, and fix other issues such as software optimising performance and productivity. In addition to your servers and operating systems; applications and embedded systems, such as network equipment, may also require patching.<\/p>\n\n\n\n

Why is patch management important?<\/h2>\n\n\n\n

Software Patch Management is key to any organisation for the following business critical reasons:<\/p>\n\n\n\n

Security: <\/strong>Patch management fixes vulnerabilities within your software and any applications that are susceptible to cyberattacks. They will help reduce security risks.<\/p>\n\n\n\n

System uptime: <\/strong>By keeping your software and applications up-to-date and running smoothly, Patch Management will prevent downtime and loss of revenue.<\/p>\n\n\n\n

Compliance: <\/strong>Regulatory bodies increasingly expect organisations to maintain a certain level of compliance to reduce the likelihood of a cyber-attack. Larger organisations may also insist that their supply chain adheres to certain security levels. A robust Patch Management Strategy can illustrate this and having one is part of achieving Cyber Essentials accreditation.<\/p>\n\n\n\n

Feature improvements:<\/strong> Patches will provide you with the latest and best features and functionality that a product has to offer.<\/p>\n\n\n\n

Is Patch Management the same as Vulnerability Management?<\/h2>\n\n\n\n

Patch Management is similar to Vulnerability Management and the phrases are often used interchangeably; however, patching is the act of solving or mitigating the vulnerability that has been identified in your software or systems.<\/p>\n\n\n\n

Vulnerability Management is a continuous process of identifying, prioritising, remedying and reporting vulnerabilities within systems and especially the software that runs in them. When a vulnerability is identified, the management strategy will decide whether to install a patch (if one is available); implement some form of mitigating action to ease the issue (often until a patch is available) or it could be decided to accept the risk. Patching any vulnerability is the \u2018gold standard\u2019 and is recommended.<\/p>\n\n\n\n

You could say that Patch Management forms part of your Vulnerability Management Strategy, especially as unpatched software applications or operating systems are one of the leading causes of security breaches. Shockingly, in a recent Ponemon Institute study, 62% of organisations<\/a> had no idea that they were vulnerable before they were attacked by cyber criminals, and perhaps worse, 60% stated that they knew about a vulnerability but had not applied the patch.<\/p>\n\n\n\n

What does a Patch Management process include?<\/h2>\n\n\n\n

Any strategy within your business needs to be developed and defined. The impact of any activity needs to be assessed. Any patch management strategy, therefore, should be implemented with a detailed process that is cost-effective as well as being security-focused.<\/p>\n\n\n\n

1. Create an up-to-date inventory of all your systems<\/h3>\n\n\n\n

You need to understand what assets you hold – operating systems, version types, and IP addresses that exist, along with their physical and geographic locations. Identify who \u2018owns\u2019 these assets and regularly update your asset inventory, ideally monthly or quarterly. You may wish to highlight those critical to your organisation to make patch and risk management easier.<\/p>\n\n\n\n

2. Devise a plan to standardise systems and operating systems to the same version type<\/h3>\n\n\n\n

If all your assets run on the same versions, it makes patching faster and more efficient. Where possible, reduce the number of assets to a manageable number so that remediation can be accelerated as new patches are released. This will help save both users and the technical team\u2019s time.<\/p>\n\n\n\n

3. Software Health Check<\/h3>\n\n\n\n

Check that all software used is licensed and supported (where the creator or vendor of the software provides support and updates for it). If it is not, remove it from your assets.<\/p>\n\n\n\n

4. List all security controls that are in place<\/h3>\n\n\n\n

It is helpful to identify all your firewalls, antivirus, and vulnerability management tools. Consider where these are situated, what they\u2019re protecting and which assets are associated with them.<\/p>\n\n\n\n

5. Implement scanning of your assets to identify missing patches<\/h3>\n\n\n\n

The easiest way to do this is by utilising vulnerability management software or working with an external partner<\/p>\n\n\n\n

6. Compare reported vulnerabilities against your inventory<\/h3>\n\n\n\n

Utilise a vulnerability management tool to assess which of your assets are affected by the vulnerabilities reported. This will help you understand the security risk to your organisation.<\/p>\n\n\n\n

7. Classify the risk<\/h3>\n\n\n\n

Having already classified your assets (in point 1), you can prioritise the critical assets requiring remedial action. Your vulnerability management tools can help identify the software, systems and networks affected whilst you decide on the prioritisation.<\/p>\n\n\n\n

8. Test<\/h3>\n\n\n\n

Applying patches to a sample of assets will identify if the patches will cause issues or not. By stress testing in this way, if there are any adverse changes to any systems, you won\u2019t have disrupted your entire organisation.<\/p>\n\n\n\n

9. Apply the patches<\/h3>\n\n\n\n

If you are happy with the results of the sample group, start patching the rest of your assets in priority order. It is still suggested that you roll out patching in batches to avoid any unexpected results to your processes. It\u2019s worth noting that some advanced vulnerability management tools will offer the ability to automate parts of the patching process.<\/p>\n\n\n\n

9. Check and track your progress<\/h3>\n\n\n\n

Once completed, reassess your assets to ensure patching was successful.<\/p>\n\n\n\n

How often to apply patches and can Mintivo help?<\/h2>\n\n\n\n

It is recommended that patches are applied within 14 days of the patch being issued, particularly if a vendor describes it as a \u2018critical\u2019 or \u2018high risk\u2019 fix. You may also wish to implement a Risk Review and Disaster Recovery Plan<\/a> to consider the implications of a vulnerability not being identified in time; a patch update not delivering the expected result or how you would cope should a vulnerability be exploited and a cyber-attack occurs. <\/p>\n\n\n\n

If you would like Mintivo to help you with patch management, get in contact<\/a> with us today and one of our team can talk you through how we can help.<\/p>\n","protected":false},"excerpt":{"rendered":"

Patch Management is essential to your organisation\u2019s security and productivity, but what exactly is patch management and why do you need a patch management strategy? What is patching? Similar to a medical patch, or plaster put on a cut to the skin to make it better, a software patch will correct errors in software code. […]<\/p>\n","protected":false},"author":6,"featured_media":4635,"parent":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"yoast_head":"\nWhat is Patch Management? - Mintivo<\/title>\n<meta name=\"description\" content=\"Patch Management is an essential part of your organisation\u2019s security and productivity, but what exactly is patch management?\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/mintivo.co.uk\/news\/what-is-patch-management\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What is Patch Management? - Mintivo\" \/>\n<meta property=\"og:description\" content=\"Patch Management is an essential part of your organisation\u2019s security and productivity, but what exactly is patch management?\" \/>\n<meta property=\"og:url\" content=\"https:\/\/mintivo.co.uk\/news\/what-is-patch-management\/\" \/>\n<meta property=\"og:site_name\" content=\"Mintivo\" \/>\n<meta property=\"article:published_time\" content=\"2024-02-27T09:35:17+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-02-28T13:38:31+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/mintivo.co.uk\/wp-content\/uploads\/2024\/02\/What-is-patch-management.png\" \/>\n\t<meta property=\"og:image:width\" content=\"600\" \/>\n\t<meta property=\"og:image:height\" content=\"400\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Meg Fenner-Jamieson\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Meg Fenner-Jamieson\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/mintivo.co.uk\/news\/what-is-patch-management\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/mintivo.co.uk\/news\/what-is-patch-management\/\"},\"author\":{\"name\":\"Meg Fenner-Jamieson\",\"@id\":\"https:\/\/mintivo.co.uk\/#\/schema\/person\/bfe6cda04a900406cd95501793a3c91e\"},\"headline\":\"What is Patch Management?\",\"datePublished\":\"2024-02-27T09:35:17+00:00\",\"dateModified\":\"2024-02-28T13:38:31+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/mintivo.co.uk\/news\/what-is-patch-management\/\"},\"wordCount\":1138,\"publisher\":{\"@id\":\"https:\/\/mintivo.co.uk\/#organization\"},\"image\":{\"@id\":\"https:\/\/mintivo.co.uk\/news\/what-is-patch-management\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/mintivo.co.uk\/wp-content\/uploads\/2024\/02\/What-is-patch-management.png\",\"articleSection\":[\"Blog\"],\"inLanguage\":\"en-GB\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/mintivo.co.uk\/news\/what-is-patch-management\/\",\"url\":\"https:\/\/mintivo.co.uk\/news\/what-is-patch-management\/\",\"name\":\"What is Patch Management? - Mintivo\",\"isPartOf\":{\"@id\":\"https:\/\/mintivo.co.uk\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/mintivo.co.uk\/news\/what-is-patch-management\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/mintivo.co.uk\/news\/what-is-patch-management\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/mintivo.co.uk\/wp-content\/uploads\/2024\/02\/What-is-patch-management.png\",\"datePublished\":\"2024-02-27T09:35:17+00:00\",\"dateModified\":\"2024-02-28T13:38:31+00:00\",\"description\":\"Patch Management is an essential part of your organisation\u2019s security and productivity, but what exactly is patch management?\",\"breadcrumb\":{\"@id\":\"https:\/\/mintivo.co.uk\/news\/what-is-patch-management\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/mintivo.co.uk\/news\/what-is-patch-management\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/mintivo.co.uk\/news\/what-is-patch-management\/#primaryimage\",\"url\":\"https:\/\/mintivo.co.uk\/wp-content\/uploads\/2024\/02\/What-is-patch-management.png\",\"contentUrl\":\"https:\/\/mintivo.co.uk\/wp-content\/uploads\/2024\/02\/What-is-patch-management.png\",\"width\":600,\"height\":400,\"caption\":\"Man engineering laptop and data center server room inspection or system solution coding and business network IT person on computer for tech upgrade gdpr programming and hardware problem solving\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/mintivo.co.uk\/news\/what-is-patch-management\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/mintivo.co.uk\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"What is Patch Management?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/mintivo.co.uk\/#website\",\"url\":\"https:\/\/mintivo.co.uk\/\",\"name\":\"Mintivo\",\"description\":\"IT support and services in England\",\"publisher\":{\"@id\":\"https:\/\/mintivo.co.uk\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/mintivo.co.uk\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/mintivo.co.uk\/#organization\",\"name\":\"Mintivo\",\"url\":\"https:\/\/mintivo.co.uk\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/mintivo.co.uk\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/mintivo.co.uk\/wp-content\/uploads\/2022\/05\/mintivo-white.svg\",\"contentUrl\":\"https:\/\/mintivo.co.uk\/wp-content\/uploads\/2022\/05\/mintivo-white.svg\",\"caption\":\"Mintivo\"},\"image\":{\"@id\":\"https:\/\/mintivo.co.uk\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/mintivo.co.uk\/#\/schema\/person\/bfe6cda04a900406cd95501793a3c91e\",\"name\":\"Meg Fenner-Jamieson\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/mintivo.co.uk\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/068f6d7eb581e3673cd56db995497eb1?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/068f6d7eb581e3673cd56db995497eb1?s=96&d=mm&r=g\",\"caption\":\"Meg Fenner-Jamieson\"},\"url\":\"https:\/\/mintivo.co.uk\/news\/author\/meg-fenner-jamieson\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"What is Patch Management? - Mintivo","description":"Patch Management is an essential part of your organisation\u2019s security and productivity, but what exactly is patch management?","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/mintivo.co.uk\/news\/what-is-patch-management\/","og_locale":"en_GB","og_type":"article","og_title":"What is Patch Management? - Mintivo","og_description":"Patch Management is an essential part of your organisation\u2019s security and productivity, but what exactly is patch management?","og_url":"https:\/\/mintivo.co.uk\/news\/what-is-patch-management\/","og_site_name":"Mintivo","article_published_time":"2024-02-27T09:35:17+00:00","article_modified_time":"2024-02-28T13:38:31+00:00","og_image":[{"width":600,"height":400,"url":"https:\/\/mintivo.co.uk\/wp-content\/uploads\/2024\/02\/What-is-patch-management.png","type":"image\/png"}],"author":"Meg Fenner-Jamieson","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Meg Fenner-Jamieson","Estimated reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/mintivo.co.uk\/news\/what-is-patch-management\/#article","isPartOf":{"@id":"https:\/\/mintivo.co.uk\/news\/what-is-patch-management\/"},"author":{"name":"Meg Fenner-Jamieson","@id":"https:\/\/mintivo.co.uk\/#\/schema\/person\/bfe6cda04a900406cd95501793a3c91e"},"headline":"What is Patch Management?","datePublished":"2024-02-27T09:35:17+00:00","dateModified":"2024-02-28T13:38:31+00:00","mainEntityOfPage":{"@id":"https:\/\/mintivo.co.uk\/news\/what-is-patch-management\/"},"wordCount":1138,"publisher":{"@id":"https:\/\/mintivo.co.uk\/#organization"},"image":{"@id":"https:\/\/mintivo.co.uk\/news\/what-is-patch-management\/#primaryimage"},"thumbnailUrl":"https:\/\/mintivo.co.uk\/wp-content\/uploads\/2024\/02\/What-is-patch-management.png","articleSection":["Blog"],"inLanguage":"en-GB"},{"@type":"WebPage","@id":"https:\/\/mintivo.co.uk\/news\/what-is-patch-management\/","url":"https:\/\/mintivo.co.uk\/news\/what-is-patch-management\/","name":"What is Patch Management? - Mintivo","isPartOf":{"@id":"https:\/\/mintivo.co.uk\/#website"},"primaryImageOfPage":{"@id":"https:\/\/mintivo.co.uk\/news\/what-is-patch-management\/#primaryimage"},"image":{"@id":"https:\/\/mintivo.co.uk\/news\/what-is-patch-management\/#primaryimage"},"thumbnailUrl":"https:\/\/mintivo.co.uk\/wp-content\/uploads\/2024\/02\/What-is-patch-management.png","datePublished":"2024-02-27T09:35:17+00:00","dateModified":"2024-02-28T13:38:31+00:00","description":"Patch Management is an essential part of your organisation\u2019s security and productivity, but what exactly is patch management?","breadcrumb":{"@id":"https:\/\/mintivo.co.uk\/news\/what-is-patch-management\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/mintivo.co.uk\/news\/what-is-patch-management\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/mintivo.co.uk\/news\/what-is-patch-management\/#primaryimage","url":"https:\/\/mintivo.co.uk\/wp-content\/uploads\/2024\/02\/What-is-patch-management.png","contentUrl":"https:\/\/mintivo.co.uk\/wp-content\/uploads\/2024\/02\/What-is-patch-management.png","width":600,"height":400,"caption":"Man engineering laptop and data center server room inspection or system solution coding and business network IT person on computer for tech upgrade gdpr programming and hardware problem solving"},{"@type":"BreadcrumbList","@id":"https:\/\/mintivo.co.uk\/news\/what-is-patch-management\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/mintivo.co.uk\/"},{"@type":"ListItem","position":2,"name":"What is Patch Management?"}]},{"@type":"WebSite","@id":"https:\/\/mintivo.co.uk\/#website","url":"https:\/\/mintivo.co.uk\/","name":"Mintivo","description":"IT support and services in England","publisher":{"@id":"https:\/\/mintivo.co.uk\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/mintivo.co.uk\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/mintivo.co.uk\/#organization","name":"Mintivo","url":"https:\/\/mintivo.co.uk\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/mintivo.co.uk\/#\/schema\/logo\/image\/","url":"https:\/\/mintivo.co.uk\/wp-content\/uploads\/2022\/05\/mintivo-white.svg","contentUrl":"https:\/\/mintivo.co.uk\/wp-content\/uploads\/2022\/05\/mintivo-white.svg","caption":"Mintivo"},"image":{"@id":"https:\/\/mintivo.co.uk\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/mintivo.co.uk\/#\/schema\/person\/bfe6cda04a900406cd95501793a3c91e","name":"Meg Fenner-Jamieson","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/mintivo.co.uk\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/068f6d7eb581e3673cd56db995497eb1?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/068f6d7eb581e3673cd56db995497eb1?s=96&d=mm&r=g","caption":"Meg Fenner-Jamieson"},"url":"https:\/\/mintivo.co.uk\/news\/author\/meg-fenner-jamieson\/"}]}},"_links":{"self":[{"href":"https:\/\/mintivo.co.uk\/wp-json\/wp\/v2\/posts\/4634"}],"collection":[{"href":"https:\/\/mintivo.co.uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mintivo.co.uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mintivo.co.uk\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/mintivo.co.uk\/wp-json\/wp\/v2\/comments?post=4634"}],"version-history":[{"count":2,"href":"https:\/\/mintivo.co.uk\/wp-json\/wp\/v2\/posts\/4634\/revisions"}],"predecessor-version":[{"id":4640,"href":"https:\/\/mintivo.co.uk\/wp-json\/wp\/v2\/posts\/4634\/revisions\/4640"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mintivo.co.uk\/wp-json\/wp\/v2\/media\/4635"}],"wp:attachment":[{"href":"https:\/\/mintivo.co.uk\/wp-json\/wp\/v2\/media?parent=4634"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mintivo.co.uk\/wp-json\/wp\/v2\/categories?post=4634"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mintivo.co.uk\/wp-json\/wp\/v2\/tags?post=4634"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}