Endpoint

Patch Management PATCH

A system that centrally tests and deploys updates for the operating system and third-party applications (browser, PDF reader, Java, VPN client) and reports patch coverage.

When you need it

  • Every organization. Most attacks exploit flaws whose patches were released months earlier.
  • Updates are left to users
  • Only Windows gets updated, and other applications are forgotten

When you do not need it

  • You may not need a separate product: your existing device management tool, the operating system's built-in update management or your EDR's patch module may be enough. What matters is the process and measurement, not the tool.

Set target times for critical patches (e.g., 7 days for internet-facing systems, 30 days for others). Pilot group first, then general rollout. The scope is not just employee computers: servers, network and security appliances (VPN, firewall) and phones are included too.