15.06.2023
Blog
Cyber Security

Why patching IT systems is so important!

Patching operating systems and software on personal and company computers and servers makes a significant contribution to IT security – no ifs, ands or buts. In this article, we aim to demonstrate why regular updates must be an integral part of IT today.

Thorsten Kuhles
Cyber Security Incident Manager

The ‘never touch a running system’ mindset is a thing of the past when it comes to the security of IT systems. At ever-shorter intervals, security vulnerabilities are not only being uncovered – they are also being exploited in an increasingly automated manner. Malware scans its environment and often exploits existing vulnerabilities without any manual intervention by a ‘hacker’. Critical security vulnerabilities can only be closed promptly through planned – and, above all, automated – ‘patching’ as part of a patch management programme.

Patching – coordinated and organised!

The most common areas requiring patches include operating systems, applications and embedded systems (such as network devices). Given the diversity and complexity of the various areas and applications, scheduled and automated system updates are almost essential. This is because the different manufacturers do not, of course, release their security updates in a coordinated manner; they all have their own ‘patch days’. Keeping track of this would be a task taking well over a full day for manual system maintenance. Of course, there will always be systems or system areas that cannot be subjected to this automated process due to technical limitations. However, this can be identified through planning within patch management, allowing appropriate action to be taken. The introduction of patch management not only addresses vulnerabilities through patches but also improves system availability, enhances the functionality of operating systems and other software, and ensures compliance with regulatory requirements imposed on organisations, for example, by public authorities.

Patch Management vs. Vulnerability Management

Patch management is an essential component of any vulnerability management solution. The terms ‘patch management’ and ‘vulnerability management’ are sometimes used interchangeably, but it is important to understand the difference. Vulnerability management is the process used to identify, assess, address and report security vulnerabilities in systems and in the software running on those systems. Patch management, on the other hand, is the process of keeping operating system and software versions up to date and managing them. Although both strategies aim to mitigate risks, patch management therefore has its limitations and should be viewed more as a ‘supporting’ element. This gives rise to three courses of action, which may need to be assessed and documented on a case-by-case basis:

  1. Where technically feasible, the patch for an identified vulnerability is installed to resolve the problem.
  2. In the event of technical and/or regulatory issues, compensatory measures are required, which are implemented via a ‘workaround’. Such an approach is common where no suitable patch is yet available, in order to buy time until the problem is finally resolved.
  3. Accept the risk/residual risk posed by this vulnerability and document this decision in the relevant security policies so that it can be traced during audits or incidents, thereby providing initial leads for in-depth investigations.

Detect attacks earlier

The speed at which potential attackers discover security vulnerabilities in common software solutions and seek to exploit them for their own purposes is constantly increasing. However, this also means that the roll-out of patches within an organisation must become ever faster and smoother. On average, organisations today take around 100 to 120 days to roll out new patches. By contrast, attackers are around five times as fast! On average, they take only around 22 days to discover new security vulnerabilities and thus become a threat to organisations. This brings us full circle to our previously published article on early detection in organisations, for example through a Security Operations Centre (SOC). Here, too, the interface between monitoring by the SOC and IT operations is clearly evident.

Conclusion
The pace of the race between manufacturers of software, firmware and operating systems on the one hand, and hackers on the other, is constantly increasing. The development of vulnerability-free software is a long time coming, and unfortunately gives attackers the opportunity to stay one step ahead of users on the ‘light side of the force’. It is therefore all the more important to make use of the available resources – for example, in the form of a patch. Systems must be maintained in order to meet standards and to provide the necessary functions for users. The problems highlighted can only be overcome through the joint efforts of manufacturers, organisations and users. Here, too, the saying applies: ‘The first line of defence is YOU’.

Thorsten Kuhles
Cyber Security Incident Manager

Thorsten Kuhles verantwortet als Cyber Security Incident Manager bei Materna die interne und externe Vorfallsbearbeitung. Zuvor war er langjährig u.a. im Bereich Pentesting und IT-Forensik bei der Bundeswehr sowie in Führungspositionen im Bereich Cyber Security bei namhaften Unternehmen tätig.