Software Update Management: Problems and Benefits
Patch management is a vital and complex task. Timely and properly managed updating optimizes cybersecurity, regulatory compliance, availability, and capability. Haphazard software update management can cause security gaps, compatibility problems, sluggish or inconsistent performance, unnecessary offline stretches, or loss of key features. Patching entails more than periodic updates of an OS and apps for servers and endpoints. Firmware patches can be an essential for peripheral devices like printers and scanners, network appliances such as routers and wireless APs, and Internet-of-Things (IoT) devices such as sensors and robotics.
Progent's Software Update Management services can cover IoT devices like alarms and health monitors
The update task can present a number of challenges that can differ for various environments. Resources that may require updating can be on-premises, in a public or private cloud, on the road, or in the homes of telecommuters. Networks may include any mix of Windows, Linux, Apple, and Google operating systems and applications. Some updates can be implemented automatically and at scale with management tools like Configuration Manager, Intune, or Azure Update Management. Others must be implemented by hand. Patching for vital resources must be scheduled to avoid business disruption. In some mission-critical systems, updates must be thoroughly validated before being applied to production.
Progent's support services for patch management offer businesses of all sizes a flexible and affordable option for evaluating, validating, scheduling, implementing, and documenting updates to your dynamic information network. In addition to maximizing the security and functionality of your IT network, Progent's software and firmware update management offerings free up time for your in-house IT team to concentrate on strategic projects that return top business value to your network.
Patch management is a closed-loop lifecycle central to your risk management strategy
Progent's Software Update Management Processes
Progent provides standard and custom service packages for software and firmware patching. These services permit you to offload some or all of your company's software update management activity to an IT support firm with more than 20 years of background delivering network design, implementation, and support to companies of all sizes globally. Progent operates closely with your network management team to determine the scope of the managed services you need. Programs available from Progent for patch include:
- Discover network resources: This can include key applications like Microsoft Exchange and SQL Server, web-facing servers, desktops and mobile endpoints, security appliances like VPN controllers, and network appliances like routers and wireless access points.
- Identify assets to be placed under management: Progent will work with you to identify which of your IT resources you pick for continuing patch management services. Progent provides a variety of standard programs that target certain types of assets and Progent can also create custom service programs to meet your particular needs.
- Implement software update management utilities: Progent is experienced with a broad selection of software update platforms and update tracking reporting systems. Available tools include Azure Automation Update Management for cloud-hosted resources, System Center Configuration Manager for on-premises entities, Intune for mobile devices, IT Glue for documentation, as well as an arsenal of advanced anti-virus platforms. Used together, these tools allow you to deploy and track updates for IT assets residing in public and private clouds, on site, on the move, at district offices, and in the houses of telecommuters.
- Analyze patch status and carry out risk assessment of missing updates: Generally, environments with up-to-date patching are more secure and dependable than those subject to inconsistent patching. Still, occasionally software updates are rushed into production and carry the potential to disturb vital business operations by introducing compatibility problems, system instability, or unfamiliar alterations to user experiences. Progent can assist you to determine which patches carry a risk to your organization's IT environment, or which patches should be given an urgent priority because they block an imminent security threat. Progent's background providing patch management support can assist you to maintain a protected computer system without sacrificing business value.
- Create a software update management program: Progent's group of consultants can help in designing and administering a patch management service program that fits your particular requirements. Progent can provide standard and specialized patch management service programs and can assist with programmatic as well as manual patching. Progent can handle mission-critical resources only, all updateable resources, or anything in between.
- Patch validation: Even the world's largest networks including Amazon AWS and Azure have experienced widespread outages that resulted from updates that were insufficiently tested before being applied to live environments. For organizations with no tolerance for downtime, Progent can assist to develop test environments that allow you to verify that the latest patches will not cause stability problems for your IT system.
- Rank and schedule updates: Progent can assist you to decide which updates should be performed immediately and which can be delayed in order to minimize service interruption. Some worldwide regulatory standards, such as the Payment Card Industry Data Security Standard, mandate that critical security updates be implemented inside a specified timeframe.
- Track patch history and status: Progent's regular update management service programs include creating a centralized knowledge base for following the update level of every subscribed asset. This streamlines the job of locating where software, firmware, or driver updates can be downloaded and specifies release dates, release advisories, and additional useful information needed for a complete update management solution.
- Fix patch failures: Updates to some core items like an OS or application server can result in unexpected compatibility or reliability problems, most commonly with legacy or home-grown applications or older hardware. Progent has the breadth of knowledge to help you to understand and resolve issues that may crop up as a result of applying a patch.
Software Update Management for Network Infrastructure Appliances from Cisco and Other Vendors
Software and firmware updates are regularly released for infrastructure devices such as firewalls, routers, wireless controllers, and Wi-Fi access points. These patches usually are designed to improve security, add or fix functionality, or mitigate reliability issues. Managing patches for these network infrastructure appliances can pose a hassle, especially in multi-vendor networks and systems that include a mixture of on-premises datacenters, at-home workers, branch offices, and cloud-based assets. In addition to tracking and acquiring updates, IT managers must ensure that infrastructure appliances have enough free disk storage and that patches are loaded uncorrupted and work correctly.
Progent has delivered advanced support for Cisco networking products for more than twenty years and also offers expertise for products from other major network companies such as Juniper, Fortinet, and CheckPoint. Progent's services for software update management can assist you to consolidate your software update system to include infrastructure appliances along with servers, desktop and mobile endpoints, applications software, and IoT devices.
Progent can provide patch management support for network infrastructure appliances from Cisco and other leading vendors
Progent's Standard and Custom Patch Management Programs
Progent has developed a range of regular software update management packages that include scheduled backup, extensive reporting, and documentation. Cost is determined by the type and quantity of entities covered. Additional services including building environments for pre-installation patch testing are billed at normal rates. Custom plans are also available and usually cover unique hardware and/or apps.
PROACTIVE Server Patch Management
On Premises or Private Cloud Server:
Microsoft Azure Cloud-hosted Servers Patch Management:
- Compliance scan of Windows and Linux servers
- Update compliance evaluation results for enrolled machines
- Scheduled Patching and Preventative Maintenance
- License & Resource reporting and management
- Managed Anti-Virus - Current AV system
- Initiate server backup once scanned
- Additional Support Invoiced at time and material Rates
- IT Glue access management and asset documentation
Onsite or Virtual Workstation:
- ProSight Availability Tracking
- OS & 3rd Party Patch Management
- Scheduled Patching and Maintenance Maintenance
- Managed Anti-Virus - current AV system
- Hosted Anti-Spam - Spam Hero
- Additional Support Invoiced at time and material Rates
- IT Glue access management and asset documentation
BASIC Server Patch Management
Managed Patch both Physical and Virtual Servers:
On Premises or Virtual Workstation Patch Management:
Server or Workstation Security SLA - Add on service
Security Critical Patches - applied within 48 hours of Progent being notified - invoiced only when needed
PROACTIVE Network Device Patching
Internet Facing Hardware - Managed Devices (Security appliances, firewalls, routers):
Internal Network Hardware - Managed devices (wireless controllers, Wi-Fi access points, switches):
Network Device Security Service-Level Agreement - Add-on service
Security Critical Patches - applied within 48 hours of Progent being notified - invoiced only when needed
Original Patching Process Extra Costs:
First-time patching will be subject to an additional cost per server or network item to provide for capture and recording of current patch level as well as any more documentation necessary for effectively providing the ongoing patching as described above. If many patches are needed that demand extra time for the first-time patching, Progent will present any estimates above the standard patching cost.
Additional Services Offered:
Download the Patch Management Services Datasheet
To download a datasheet about the features and benefits of Progent Patch Management Services, select:
Progent Software Update Managed Services Datasheet. (PDF - 330 KB)
Contact a Progent Expert about Software/Firmware Update Management Services
To learn more about Progent's patch management offerings, call Progent at 800-993-9400 or see Contact Progent.