• About
  • Subscribe
  • Contact
Wednesday, May 7, 2025
    Login
  • Management Leadership
    • Growth Strategies
    • Finance
    • Operations
    • Sales and Marketing
    • Careers
  • Technology
    • Infrastructure and Platforms
    • Business Applications and Databases
    • Big Data, Analytics and Intelligence
    • Security
  • Industry Verticals
    • Finance and Insurance
    • Manufacturing
    • Logistics and Transportation
    • Retail and Wholesale
    • Hospitality and Tourism
    • Government and Public Services
    • Utilities
    • Media and Telecommunications
  • Resources
    • Whitepapers
    • PodChats
    • Videos
  • Events
No Result
View All Result
  • Management Leadership
    • Growth Strategies
    • Finance
    • Operations
    • Sales and Marketing
    • Careers
  • Technology
    • Infrastructure and Platforms
    • Business Applications and Databases
    • Big Data, Analytics and Intelligence
    • Security
  • Industry Verticals
    • Finance and Insurance
    • Manufacturing
    • Logistics and Transportation
    • Retail and Wholesale
    • Hospitality and Tourism
    • Government and Public Services
    • Utilities
    • Media and Telecommunications
  • Resources
    • Whitepapers
    • PodChats
    • Videos
  • Events
No Result
View All Result
No Result
View All Result
Home Technology Business Applications & Databases

Software patching too complex and time consuming

FutureCIO Editors by FutureCIO Editors
January 7, 2022
Photo by ThisIsEngineering from Pexels

Photo by ThisIsEngineering from Pexels

An Ivanti study found that 71% of IT and security professionals see patching as being overly complex, cumbersome and time-consuming. Remote work has increased the complexity and scale of patch management, according to 57% of respondents.

Today’s speed of business has shifted user expectations with new impacts on IT. And the rapid shift to remote work has accelerated digital transformation by seven years.

In the Everywhere Workplace, employees connect with various devices to access corporate networks, data and services as they work and collaborate from new and different locations, so patching has never been more challenging.

Unpatched vulnerabilities remain one of the most common points of infiltration for ransomware attacks, which have increased in frequency and impact businesses of all sizes.

The risks that come with not patching

The WannaCry ransomware attack, which encrypted an estimated 200,000 computers in 150 countries, remains a prime example of the severe repercussions that can occur when patches are not promptly applied.

A patch for the vulnerability exploited by the ransomware had existed for several months before the initial attack, yet many organisations failed to implement it. And even now, four years later, two-thirds of companies still haven’t patched their systems.

Yet organisations around the world are still being targeted by WannaCry ransomware attacks; there was a 53% increase in the number of organisations affected with WannaCry ransomware from January to March 2021.

Patching to mitigate vulnerability exposure and ransomware susceptibility is contending with resource challenges and business reliability concerns. 62% of respondents said that patching often takes a back seat to their other tasks and 60% said that patching causes workflow disruption to users.

In addition, 61% of IT and security professionals said that line of business owners ask for exceptions or push back maintenance windows once a quarter because their systems cannot be brought down.

At the same time, the speed of vulnerability weaponization continues to increase.

It’s the perfect storm of poor visibility due to the recently decentralised workforce and the growth of sophisticated threat actors targeting critical vulnerabilities.  

As threat actors are maturing their tactics and weaponising vulnerabilities, especially those with remote code execution, organisations are struggling with attack surface risk and ways to accelerate patch and remediation actions.

IT and security teams simply cannot respond fast enough; 53% said that organising and prioritising critical vulnerabilities takes up most of their time, followed by issuing resolutions for failed patches (19%), testing patches (15%) and coordinating with other departments (10%).

The myriad of challenges that IT and security teams face when it comes to patching may be why 49% of respondents believe their company’s current patch management protocols fail to effectively mitigate risk.

Srinivas Mukkamala

Ivanti’s senior vice president of security products, Srinivas Mukkamala, says these results come at a time when IT and security teams are dealing with the challenges in which workforces are more distributed than ever before and ransomware attacks are intensifying and impacting economies and governments.

He opined that most organisations do not have the bandwidth or resources to map active threats such as those tied to ransomware, with the vulnerabilities they exploit.

The good news is that the combination of risk-based vulnerability prioritisation and automated patch intelligence can bring to light vulnerabilities that are being actively exploited and have ties to ransomware.

“With unique patch reliability, IT and security teams can seamlessly deploy patches and solve common challenges that are putting organisations at risk,” he concluded.

Recommendations

Top industry leaders, practitioners and analyst firms recommend a risk-based approach to identify and prioritise vulnerability weaknesses and then accelerate remediation.

The White House recently released a memo encouraging organisations to use a risk-based assessment strategy to drive patch management and bolster cybersecurity against ransomware attacks.

Gartner listed risk-based vulnerability management as a top security project that security and risk management professionals should focus on in 2021 to drive business value and reduce risk.

Related:  Defending in isolation inadequate for healthcare supply chain
Tags: Everywhere workplaceIvantirisk-based vulnerability managementsoftware patchingvulnerability managementWannacry ransomware
FutureCIO Editors

FutureCIO Editors

No Result
View All Result

Recent Posts

  • Agentic AI-powered AppSec platform launched for the AI era
  • IDC forecasts GenAI alone will grow at a 59.2% CAGR
  • Dataiku brings new AI capabilities to create and control AI agents
  • Microsoft reveals the rise of a new kind of organisation in the AI era
  • St Luke’s ElderCare enhances data security and user experience with Juniper

Live Poll

Categories

  • Big Data, Analytics & Intelligence
  • Business Applications & Databases
  • Business-IT Alignment
  • Careers
  • Case Studies
  • CISO
  • CISO strategies
  • Cloud, Virtualization, Operating Environments and Middleware
  • Computer, Storage, Networks, Connectivity
  • Corporate Social Responsibility
  • Customer Experience / Engagement
  • Cyber risk management
  • Cyberattacks and data breaches
  • Cybersecurity careers
  • Cybersecurity operations
  • Education
  • Education
  • Finance
  • Finance & Insurance
  • FutureCISO
  • General
  • Governance, Risk and Compliance
  • Government and Public Services
  • Growth Strategies
  • Hospitality & Tourism
  • HR, education and Training
  • Industry Verticals
  • Infrastructure & Platforms
  • Insider threats
  • Latest Stories
  • Logistics & Transportation
  • Management Leadership
  • Manufacturing
  • Media and Telecommunications
  • News Stories
  • Operations
  • Opinion
  • Opinions
  • People
  • Process
  • Remote work
  • Retail & Wholesale
  • Sales & Marketing
  • Security
  • Tactics and Strategies
  • Technology
  • Utilities
  • Videos
  • Vulnerabilities and threats
  • White Papers

Strategic Insights for Chief Information Officers

FutureCIO is about enabling the CIO, his team, the leadership and the enterprise through shared expertise, know-how and experience - through a community of shared interests and goals. It is also about discovering unknown best practices that will help realize new business models.

Quick Links

  • Videos
  • Resources
  • Subscribe
  • Contact

Cxociety Media Brands

  • FutureIoT
  • FutureCFO
  • FutureCIO

Categories

  • Privacy Policy
  • Terms of Use
  • Cookie Policy

Copyright © 2022 Cxociety Pte Ltd | Designed by Pixl

Login to your account below

or

Not a member yet? Register here

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Management Leadership
    • Growth Strategies
    • Finance
    • Operations
    • Sales and Marketing
    • Careers
  • Technology
    • Infrastructure and Platforms
    • Business Applications and Databases
    • Big Data, Analytics and Intelligence
    • Security
  • Industry Verticals
    • Finance and Insurance
    • Manufacturing
    • Logistics and Transportation
    • Retail and Wholesale
    • Hospitality and Tourism
    • Government and Public Services
    • Utilities
    • Media and Telecommunications
  • Resources
    • Whitepapers
    • PodChats
    • Videos
  • Events
Login

Copyright © 2022 Cxociety Pte Ltd | Designed by Pixl

Subscribe