O
12

The pentest guy made me question my patch Tuesday routine

Last month, a contractor doing our annual pentest asked why we still batch patching on the first Tuesday. He showed me our own logs where a critical CVE sat exposed for 11 days after the patch dropped. I always figured the cadence was fine, but he broke down the blast radius with real numbers from our firewall. Has anyone else shifted to rolling patches or am I overreacting to one pentest's opinion?
0 comments

Log in to join the discussion

Log In
0 Comments

No comments yet

Be the first to share your thoughts on this discussion.