Patch Management: Challenges and Benefits
Patch management is a critical and complicated task. Prompt and correctly managed updating optimizes cybersecurity, compliance, uptime, and functionality. Haphazard patch management can cause security gaps, compatibility problems, sluggish or erratic performance, excessive downtime, or loss of important features. Patching involves more than occasional updates of operating systems and apps for servers and endpoints. Firmware patches can be an essential for peripheral devices such as printers and scanners, network appliances like switches and wireless access points, and IoT devices such as alarms and robotics.
Progent's Patch Management programs can cover IoT devices such as alarms and health monitors
The patching task can present a number of complications that vary from network to network. Resources that may require patching can be on site, in the cloud, on the road, or in the homes of remote workers. Environments may include a mix of Microsoft Windows, Linux, Apple macOS, and Google operating systems and apps. Some updates can be installed automatically and at virtually any scale using tools like Microsoft Configuration Manager, Microsoft Intune, or Azure Automation Update Management. Other updates must be performed manually. Patching for core systems must be timed to avoid business interruption. In certain line-of-business environments, patches must be carefully tested prior to being approved for production.
Progent's support services for patch management provide businesses of all sizes a versatile and affordable solution for assessing, testing, scheduling, applying, and documenting software and firmware updates to your ever-evolving information system. Besides optimizing the security and functionality of your information system, Progent's patch management offerings free up time for your IT staff to focus on strategic projects and tasks that deliver top business advantage to your information system.
Patch management is a closed-loop process critical to your risk management plan
Progent's Patch Management Processes
Progent provides standard and custom service programs for patch management. These services permit you to outsource some or all of your company's software update management activity to a network consulting organization with over two decades of background providing network design, deployment, and support to companies of all sizes worldwide. Progent works in close conjunction with your IT management team to define the scope of the managed services you require. Services offered by Progent for software update include:
- Discover system resources: This can cover key applications such as Microsoft Exchange and SQL, web-facing servers, desktops and mobile endpoints, security products like VPN controllers, and network infrastructure appliances such as routers and Wi-Fi APs.
- Select resources to be managed: Progent will work with your IT team to identify which of your network assets you pick for continuing patch management services. Progent offers a variety of regular service programs that target specific types of items and Progent can also create specialized programs to accommodate your unique requirements.
- Implement software update management utilities: Progent is familiar with a broad range of patch installation tools and update inventory reporting systems. Available tools include Azure Automation Update for cloud-based resources, Microsoft Configuration Manager for on-premises assets, Microsoft Intune for mobile computers, IT Glue for IT asset documentation, as well as a selection of modern AV platforms. Combined, these tools enable you to automate and track updates for network assets located in public and private clouds, on site, on the move, at branch offices, and in the houses of telecommuters.
- Determine patch status and perform risk analysis of uninstalled updates: Generally, systems with up-to-date patching are more secure and dependable than those with inconsistent updates. However, some software updates are rushed into distribution and carry the ability to disrupt vital business processes by introducing compatibility issues, system instability, or unfamiliar changes to end-user environments. Progent can help clients to assess which patches carry a risk to your organization's IT environment, or which updates should be given a high priority because they block an imminent cybersecurity threat. Progent's background with patch management services can help your organization to administer a protected network without compromising productivity.
- Pick a software update management service program: Progent's team of experts can help in designing and administering a patch management program that aligns with your business and security needs. Progent offers standard and custom software update management service programs and can help with both programmatic as well as manual patching. Progent can manage business-critical resources exclusively, all updateable resources, or somewhere in between.
- Patch testing: Even the biggest networks like Amazon AWS and Azure have experienced widespread outages that resulted from software updates that were not thoroughly tested before being applied to production environments. For businesses with zero room for service disruption, Progent can assist to develop test systems that permit you to verify that new updates will not introduce stability issues for your network.
- Rank and schedule updates: Progent can assist you to decide which patches should be implemented quickly and which can be delayed so as to minimize business disruption. Certain key regulatory standards, like the PCI Data Security Standard, require that critical security updates be implemented within a specified time period.
- Document patch history and status: Progent's regular update management programs include the creation of a centralized database for tracking the update level of every monitored asset. This simplifies the job of locating where updates can be downloaded and specifies patch release dates, release notes, and other important data needed for a complete update management system.
- Repair patch failures: Updates to some key resources such as an operating system or app server can result in unforeseen compatibility or stability problems, particularly with outdated or custom applications or older hardware. Progent has the scope of knowledge to help you to understand and resolve issues that may crop up as a result of implementing a patch.
Patch Management for Network Devices from Cisco and Other Providers
Software and firmware patches are frequently developed for infrastructure appliances like firewalls, routers, wireless controllers, and wireless access points. These updates usually are designed to harden cybersecurity, enhance functionality, or mitigate reliability problems. Managing patches for these network infrastructure appliances can pose a challenge, particularly in mixed-vendor environments and systems that include a mixture of on-premises data centers, telecommuters, regional offices, and cloud-based resources. Besides tracking and accessing the latest updates, IT managers must verify that network appliances have sufficient free disk storage and that patches are transferred cleanly and work correctly.
Progent has delivered high-end help for Cisco infrastructure products for over twenty years and also offers technical guidance for devices from other leading vendors such as Palo Alto Networks, Fortinet, and WatchGuard. Progent's services for patch management can help you to expand your software update system to include network appliances as well as physical and virtual servers, endpoints, applications software, and Internet-of-Things items.
Progent offers software update management support for network appliances from Cisco and other vendors
Progent's Regular and Custom Software Update Management Services
Progent offers a variety of standard patch management plans that include backup, reporting, and thorough documentation. Pricing is based on the type and quantity of devices enrolled. Extra services such as creating systems for initial software update validation are billed at time and material rates. Custom packages are also available and typically handle unique hardware and/or applications.
PROACTIVE Server Patch Management
On Premises or Private Cloud Server:
Azure Cloud-hosted Servers Patch Management:
- Compliance scan of all Windows and Linux servers
- Update compliance evaluation report for enrolled machines
- Scheduled Patching and Maintenance Maintenance
- License & Resource documentation and management
- Managed Anti-Virus - Current AV system
- Begin server backup once complete
- Additional Services Invoiced at time and material Rates
- IT Glue access management and resources documentation
Onsite or Virtual Workstation:
- ProSight Availability Tracking
- Operating System & Third Party Patch Management
- Scheduled Patching and Preventative Maintenance
- Managed Anti-Virus - current AV system
- Hosted Anti-Spam - Spam Hero
- Additional Support Invoiced at T&M Rates
- IT Glue access control and asset documentation
BASIC Server Patch Management
Managed Patch both Physical and Virtual Servers:
On Premises or Virtual Workstation Patch Management:
Server or Workstation Security SLA - Add on service
Security Critical Patches - completed within 48 hours of Progent being notified - invoiced only when required
PROACTIVE Network Device Patching
Internet Facing Hardware - Managed Devices (Security appliances, firewalls, routers):
Internal Network Hardware - Managed devices (wireless controllers, Wi-Fi access points, switches):
Network Device Security SLA - Add-on service
Security Critical Patches - applied within 48 hours of Progent being notified - invoiced only when needed
Original Patching Process Extra Costs:
Initial updating will be subject to an extra cost for each server or network device to provide for review and documentation of current update level as well as any more information required for effectively managing the patching services as defined above. If many patches are needed that require extra time for the first-time updating, Progent will provide any cost estimates beyond the regular patching cost.
Other Services Available:
Download the Software Update Managed Services Datasheet
To download a datasheet describing Progent Software Update Managed Services, select:
Progent Software Update Managed Services Datasheet. (PDF - 330 KB)
Contact Progent about Patch Management Solutions
To find out additional information about Progent's software/firmware update management offerings, call Progent at 800-993-9400 or see Contact Progent.