GlossaryAttack surface and pentesting

Patch management

Short answer

Patch management is the process of finding, testing and installing updates that fix security flaws in operating systems, applications, firmware and network devices, within defined timeframes. Unpatched known vulnerabilities remain one of the most common ways attackers get into a company.

The process

It starts with an up to date inventory of devices and software, since what is not inventoried is not patched. New updates are then identified, prioritised, tested where needed, deployed and verified. Exceptions, such as a legacy system that cannot be updated, are documented with compensating measures like isolating it from the network.

Prioritising by real risk

Not every patch is equally urgent. A practical rule combines the CVSS severity, whether the flaw is being exploited (the CISA KEV catalogue is a good signal) and whether the affected system is exposed to the internet. A critical vulnerability on a VPN gateway should be fixed in days, not at the next monthly cycle.

Common gaps

Laptops are usually well covered by automatic updates. The gaps tend to be servers, firewalls, VPN appliances, third party applications, browser extensions and devices nobody owns. Our article on what your company exposes online shows why internet facing systems come first.

Where it shows up in compliance

ISO 27001 requires the management of technical vulnerabilities (Annex A 8.8). The ENS, NIS2 and SOC 2 all expect vulnerabilities to be fixed within defined timeframes, and auditors ask for evidence of patching levels and exceptions.

Related terms

Keep reading on this topic

External and internal attack surface management, cloud configuration and application security: finding exposures and prioritising them by real risk.

Go to the topic hub