Switchfast Blog: The Future of IT
SANS Institute: Unpatched Software is Top Security Risk Worldwide
Friday, September 18, 2009 by Michael Holley
Our CEO, Matt Owen, sent me this link the other day. The article cites
research by the SANS Institute confirming our belief that unpatched
software is, in fact, the number one security risk worldwide for
business.
The reason is simple. Patches are essentially created to do two
things: one is to fix bugs, and the other is to fix security
vulnerabilities. If a patch is available for a particular piece of
software, there's a good chance that there has been a security
vulnerability discovered, likely because some cybercriminal found
it first and exploited it. To still be using an outdated version of
an application with a publicly known security issue is the
equivalent of asking for trouble.
Patching isn't always easy business, however. Sometimes software
vendors, in a hurry to complete a fix of some kind, will release
faulty patches that can render the application unusable. Microsoft
is notorious for this. This can be a major problem for companies
that rely on certain software, as it is often difficult or
impossible to revert to the previous working version once the
damage is done. At this point you can be stuck with nothing until
the software vendor releases a working solution.
If you're one of our MaxPro customers, you don't have to worry
about this because we test all patches before we release them to
our clients. If you aren't, however, you should absolutely have a
reliable automated patching solution in place, whether it's
in-house or outsourced. Not doing so puts your business at risk in
a very big way.
Best,
Michael Holley
Switchfast Technologies
Chicago IT Consulting
& Support
Rochester
IT Consulting & Support
Leave comment: