Patch management is the process of identifying, testing, deploying and verifying software and firmware updates that fix vulnerabilities and bugs across an organisation’s systems.
How patch management works
A typical patch management cycle, as described in NIST SP 800-40 Rev. 4, includes:
- Inventory – knowing which operating systems, applications, firmware and cloud services are in use;
- Monitoring – tracking vendor advisories, such as Microsoft’s monthly Patch Tuesday on the second Tuesday of each month;
- Prioritisation – ranking fixes by severity (CVSS), exposure and whether a flaw is already exploited in the wild;
- Testing and deployment – piloting updates on a small group, then rolling them out with automated tools;
- Verification – confirming that updates are installed and handling systems that cannot be patched.
Why patch management matters
Exploitation of known vulnerabilities is one of the most common ways into a network. Two well-known examples:
- WannaCry (May 2017) spread through the SMB flaw fixed by Microsoft in bulletin MS17-010 two months earlier.
- Equifax (2017) was breached through an Apache Struts vulnerability for which a fix had been available for weeks; data of about 147 million people was stolen.
Attackers increasingly weaponise flaws within days of disclosure, especially in VPN gateways, firewalls and file transfer software. The US CISA maintains the Known Exploited Vulnerabilities (KEV) catalog to help organisations focus on what attackers actually use.
Best practices
- Patch internet-facing systems and actively exploited flaws first, within days rather than weeks.
- Automate deployment and reporting wherever possible.
- Include firmware, network appliances and third-party applications, not only Windows.
- Apply mitigations or isolation when a patch is not yet available, as for a zero-day, and retire unsupported software.