Software Update Management: Problems and Solutions
Software update management is a critical and complicated process. Prompt and properly managed patching maximizes security, regulatory compliance, uptime, and functionality. Haphazard patch management can cause security gaps, compatibility issues, slow or inconsistent responsiveness, needless downtime, or loss of important functions. Patching entails more than periodic updates of an OS and applications for servers and endpoints. Firmware patches can be a vital for peripherals like printers and scanners, network appliances like switches and Wi-Fi access points, and IoT devices like alarms and health monitors.
Progent's Patch Management programs can cover IoT devices like alarms and health monitors
The patching task can pose a number of challenges that can differ for various environments. Assets that could need patching can be on site, in the cloud, on the road, or in the homes of remote workers. Networks may support any combination of Windows, Linux, Apple, and Google operating systems and apps. Some patches can be installed automatically and at virtually any scale using tools such as Configuration Manager, Microsoft Intune, or Azure Automation Update Management. Others must be performed manually. Updating for vital systems must be scheduled to minimize business interruption. In some line-of-business systems, patches must be thoroughly validated before being applied to production.
Progent's managed services for software and firmware patch management provide businesses of all sizes a flexible and affordable option for evaluating, testing, scheduling, applying, and tracking updates to your dynamic IT system. Besides optimizing the security and functionality of your information system, Progent's patch management offerings open up time for your IT team to focus on strategic initiatives and tasks that return maximum business value to your network.
Patch management is a closed-loop lifecycle central to your risk management plan
Progent's Patch Management Activities
Progent provides standard and specialized service packages for software and firmware patching. These managed services allow you to offload a portion or all of your software update management activity to an IT consulting organization with over 20 years of experience providing network design, deployment, and support to businesses of all sizes worldwide. Progent operates in close conjunction with your network managers to define the critical services you require. Programs offered by Progent for patch include:
- Inventory network assets: This can include key applications such as Exchange and SQL Server, web-facing physical and virtual servers, desktops and mobile endpoints, security appliances like firewalls, and infrastructure appliances like routers and wireless APs.
- Identify resources to be placed under management: Progent's experts will confer with you to identify which of your network assets you pick for continuing software update management services. Progent provides a selection of standard service programs that target specific types of items and Progent can also create custom programs to meet your particular requirements.
- Implement patch management tools: Progent is experienced with a broad selection of software update platforms and update inventory databases. Available utilities include Azure Update Management for cloud-hosted assets, Microsoft Configuration Manager for on-premises assets, Intune for mobile devices, IT Glue for documentation, plus a selection of modern anti-virus platforms. Combined, these tools enable you to deploy and monitor patches for IT assets residing in cloud environments, on-premises, on the road, at branch offices, and in the houses of telecommuters.
- Determine update currency and carry out risk assessment of uninstalled updates: Generally, systems with up-to-date patching are more secure and stable than those subject to sporadic updates. Still, some patches are hurried into distribution and have the potential to disturb vital network processes by causing compatibility issues, system instability, or unfamiliar changes to user environments. Progent can assist clients to assess which updates pose a risk to your company's IT environment, or which updates should be assigned an urgent priority because they block an imminent security threat. Progent's background with patch management services can assist your organization to maintain a protected computer system without sacrificing business value.
- Pick a patch management program: Progent's group of experts can help in devising and administering a software update management service program that fits your business and security needs. Progent offers standard and custom patch management service programs and can help with automated and manual patching. Progent can handle business-critical resources only, all patchable assets, or anything in between.
- Patch validation: Even the biggest networks including Amazon AWS and Microsoft Azure have experienced widespread outages that resulted from updates that were not thoroughly tested prior to being rolled out to live environments. For businesses with zero room for service disruption, Progent can help create pilot environments that allow you to make sure that the latest updates will not introduce reliability issues for your network.
- Rank and schedule updates: Progent can help you to decide which updates should be implemented immediately and which can be postponed in order to minimize business disruption. Some worldwide industry standards, like the PCI Data Security Standard, mandate that the most critical cybersecurity updates be installed within a defined time period.
- Track update history and status: Progent's standard patch management service programs include the creation of a centralized database for tracking the update level of every monitored resource. This streamlines the task of locating where updates can be downloaded and includes patch release dates, release advisories, and additional useful information needed for a complete update management system.
- Debug update problems: Patches to some core items such as an operating system or application server can cause unexpected compatibility or stability issues, most commonly with outdated or custom software or older devices. Progent has the scope of knowledge to assist you to identify and mitigate issues that may crop up due to applying a software update.
Patch Management for Network Infrastructure Devices from Cisco and Other Providers
Software and firmware updates are regularly released for network devices like firewalls, routers, switches, and Wi-Fi APs. These patches usually are designed to improve cybersecurity, add or fix functionality, or mitigate stability and compatibility issues. Managing patches for these network appliances can be a challenge, particularly in mixed-vendor environments and systems that have a mixture of on-premises datacenters, at-home workers, branch offices, and cloud-hosted assets. Besides monitoring and accessing updates, IT managers must verify that network devices have sufficient free disk storage and that patches are transferred uncorrupted and work correctly.
Progent has delivered advanced assistance for Cisco networking appliances for over two decades and also offers expertise for devices from other leading network companies including Juniper, SonicWall, and CheckPoint. Progent's services for software update management can assist you to expand your patching solution to cover network appliances along with physical and virtual servers, endpoints, applications, and IoT devices.
Progent offers software update management support for infrastructure devices from Cisco and other leading vendors
Progent's Standard and Custom Software Update Management Programs
Progent has developed a variety of standard patch management packages that include backup services, reporting, and thorough documentation. Pricing is determined by the class and number of entities covered. Extra services such as creating environments for initial software update validation are invoiced at time and material rates. Specialized plans are also offered and usually cover unusual devices and/or apps.
PROACTIVE Server Software Update Management
On Premises or Private Cloud-hosted Server:
Azure Cloud Servers Patch Management:
- Compliance scan of Windows and Linux servers
- Update compliance assessment results for enabled machines
- Scheduled Patching and Maintenance Maintenance
- License & Asset documentation and management
- Managed Anti-Virus - Current AV system
- Begin server backup once complete
- Additional Support Invoiced at T&M Rates
- IT Glue access management and resources documentation
Onsite or Virtual Workstation:
- ProSight Availability Tracking
- OS & Third Party Patch Management
- Scheduled Patching and Preventative Maintenance
- Managed Anti-Virus - current AV system
- Hosted Anti-Spam - Spam Hero
- Additional Support Billed at time and material Rates
- IT Glue access control and asset documentation
BASIC Server Patch Management
Managed Patch both Physical and Virtual Servers:
On Premises or Virtual Workstation Patch Management:
Server or Workstation Security SLA - Add on service
Security Critical Patches - applied within 48 hours of Progent being notified - invoiced only when needed
PROACTIVE Network Device Patching
Internet Facing Hardware - Managed Devices (Security appliances, firewalls, routers):
Internal Network Hardware - Managed devices (wireless controllers, Wi-Fi access points, switches):
Network Device Security Service-Level Agreement - Add-on service
Security Critical Patches - applied within 48 hours of Progent being notified - invoiced only when needed
Initial Patching Process Additional Costs:
Initial patching will have an additional cost per server or network item to provide for review and recording of current patch level as well as any other information necessary for effectively managing the ongoing patching as described previously. If multiple updates are needed that demand extra time for the initial updating, Progent will present any cost estimates beyond the standard patching cost.
Additional Services Offered:
Download the Software Update Managed Services Datasheet
To download a datasheet about the features of Progent Patch Management Services, click:
Progent Software Update Managed Services Datasheet. (PDF - 330 KB)
Talk to Progent about Patch Management Solutions
To find out additional information about Progent's software/firmware update management services, call Progent at 800-993-9400 or go to Contact Progent.