This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Vulnerability Management – Lessons Learned & Wisdom Earned

Download resources

About this session

Drawing on eight years running GoSecure's Vulnerability Management as a Service, the presenter shares field lessons on getting patches deployed in organisations that believe it cannot be done. He sets the scene with the Patch Tuesday and Exploit Wednesday cycle, the growing technical debt of cumulative updates, and the point that most attacks pass through a correctable vulnerability; in his experience the average client starts near 6% compliance on critical patches. His method is incremental: choose scanning and deployment tools against real requirements, identify resistance points among understaffed teams early, start with a small low-risk slice of the estate and only the current month's patches, then chip away at backlog once a track record exists. He stresses benchmarking, realistic targets (80 to 88% already raises the attacker's cost), frequent reporting to leadership, and warning end users before mass deployments so the help desk is not flooded. A backlog chart illustrates the 'heartbeat' pattern of a mature programme, and he cautions against using scanners as the progress metric because of false positives and transient devices. He closes on cost: a programme is trivial next to a breach and pushes opportunistic attackers toward easier targets.

Virtually all companies today rely on technology to deliver their products or services, even the old bricks and mortar companies. Despite having various needs for their technology, a retail chain, an energy company, and a bank all share one thing in common. The patch Tuesday, exploit Wednesday monthly cycle. This talk will look at how various companies solve the patch and scan headache and its growing technical debt.  

Key takeaways

  • Start with a low-risk 10% of the estate and only the current month's patches; let small failures happen early and add backlog gradually once the process is proven.
  • Benchmark the starting backlog and set realistic targets: 80 to 88% critical-patch compliance already changes who can breach you.
  • Never push 200 patches and a reboot at once; small increments keep systems stable and make it possible to identify which patch broke something.
  • Warn end users and the help desk before mass deployments, and roll out to user groups of one to two hundred per day.
  • Use vulnerability scanners to validate new builds and discover unknown assets, not as the primary progress metric; false positives and transient devices distort scan-over-scan counts.

Speakers

Randy Martin
Randy Martin
Director of VMaaS · GoSecure

Resources

Tags

More from GoSec 2021

Also from Randy Martin

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.