Light Mode Dark Mode
August 25, 20262 min read

Tech Talks Network Podcast: Patching at Machine Speed Without Breaking the Business

Adaptiva's David Sowder, Sr Solutions Architect, was recently featured on The Business of Cybersecurity Podcast where he and host Neil Hughes discussed stats from the State of Patch Management Report, cooperation between InfoSec and IT, and pushing books down stairs. Read below for the recap from Neil and listen to the interview above. 

"What happens when a patch designed to protect the business creates an outage of its own?

In this episode of The Business of Cybersecurity, I [Neil C. Hughes] speaks with David Sowder, Senior Solutions Architect and OneSite Patch product specialist at Adaptiva, about balancing rapid vulnerability remediation with operational control.

David brings 25 years of IT operations and engineering experience to the conversation. He remembers receiving large spreadsheets of vulnerabilities from security teams and being responsible for turning that information into deployed fixes. That experience gives him a practical view of the gap between identifying a vulnerability and safely resolving it across thousands of endpoints.

Adaptiva’s State of Patch Management report argues that speed cannot be the only measure of success. David illustrates the problem with a library cart full of books. Pushing it down the stairs may be the fastest way to reach the lower floor, but the resulting mess defeats the purpose.

The same principle applies to patch management. Urgent deployment can reduce the period when a vulnerability remains exposed, but an inadequately tested update may break applications, interrupt customer services, or affect revenue. David recommends representative pilot groups, defined testing periods, user feedback, staged deployment, monitoring, and the ability to stop a release before it reaches the full production environment.

We also discuss why greater endpoint visibility does not automatically reduce business risk. Dashboards and vulnerability reports provide knowledge, but IT teams must perform the work required to remediate the problem. David believes closer cooperation between InfoSec and IT can reduce the time between identification and action.

Automation introduces another difficult decision. David argues that layers of manual approval frequently add delay without changing which patches are eventually deployed. His proposed alternative is to begin the process automatically, notify the right people, test through pilot groups, and prevent wider deployment when the feedback indicates a problem.

Accountability remains shared. Security leaders set risk policies, InfoSec prioritizes exposure, IT manages deployment, and application owners understand the possible business consequences. These responsibilities need to be agreed before an urgent incident arrives.

Can autonomous patch management help companies respond at machine speed without turning a security fix into a business outage? Listen to the conversation and share your thoughts with me."

-Tech Talks Network

AdobeStock_488605053

Ready to Get Started?

Schedule a one-on-one demo today.

Request a Demo