12
The pentest guy made me question my patch Tuesday routine
Last month, a contractor doing our annual pentest asked why we still batch patching on the first Tuesday. He showed me our own logs where a critical CVE sat exposed for 11 days after the patch dropped. I always figured the cadence was fine, but he broke down the blast radius with real numbers from our firewall. Has anyone else shifted to rolling patches or am I overreacting to one pentest's opinion?
0 comments
Log in to join the discussion
Log In0 Comments
No comments yet
Be the first to share your thoughts on this discussion.