Patch management is often an overlooked aspect of cybersecurity. Patches address security vulnerabilities within programs and products. As such, a city’s cybersecurity procedures should include a regular patching schedule to apply updates.
What are patches?
Patches are software and operating system updates that are used to address performance bugs and provide enhanced security features. The performance updates allow systems to run faster and fix bugs that may be slowing or stopping programs. Enhanced security features can be used to block hackers, stop malware and reduce weak spots in systems which reduces the risk of cyber-attacks.
When should patches occur?
Organizations should implement a regular patch schedule which can occur monthly or quarterly. The schedule should be determined by the type of update that is being applied, and scheduled patch deployments should occur during times outside of peak hours to reduce disruptions to critical business processes. Patches should be applied as soon as possible after release.
Who should apply software patches?
IT administrators and cities’ security teams should work together to determine what updates should be installed and develop a schedule for installation. The schedule can include automatic software updates.
Best practices for patch updates
- Test patches in a controlled environment before applying them to production systems.
- Document details on which patches are applied, when they are deployed as well as testing results.
- Maintain an inventory of all software and hardware assets.
- Enable automatic software updates when possible.
- Use automated vulnerability scanning tools to identify missing patches.
- Establish a recovery and rollback plan to revert software to the previous state if patches cause any problems.
- Avoid using end-of-life software that may no longer be supported by vendors.
Adhering to a regular patch schedule can save a city from increased risk of cyber-attacks which can lead to data breaches and financial losses. SC Municipal Insurance and Risk Financing Fund members can learn more about the importance of patching and other cybersecurity resources by logging into the Municipal Association’s website and clicking on eRiskHub on the member home page under “SCMIRF.”