By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Current approaches to patching unsustainable, report says | Computer Weekly
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Current approaches to patching unsustainable, report says | Computer Weekly
News

Current approaches to patching unsustainable, report says | Computer Weekly

News Room
Last updated: 2025/07/15 at 4:50 PM
News Room Published 15 July 2025
Share
SHARE

Cyber security professionals tasked with vulnerability patch management and roll-out duties say they are struggling to effectively prioritise critical updates and tend to fall back on the approach of describing ‘everything’ as a priority, an approach described as completely unsustainable, according to a new report compiled by Ivanti.

In its new 2025 Risk-based patch prioritisation report, released this week, Ivanti lamented a lack of industry standard ratings for vulnerabilities and patches, meaning users are left to compare and prioritise updates based on isolated recommendations.

Against factors influencing patch prioritisation, such as a vulnerability’s impact to critical systems, whether or not it is being actively exploited or has been detected by a vulnerability scanner, its CVSS score or vendor severity score, whether or not it needs to be patched for compliance reasons like inclusion in the CISA KEV database, or whether or not it has been identified as a priority by management, a majority of cyber pros said they rated all of the above as having either a high or moderate impact on their urgency.

“But when everything is a priority, nothing is a priority,” wrote the report’s authors, who said in light of these stats it was no surprise whatsoever that 39% of cyber pros said they struggle to prioritise risk remediation and patch deployment, and 35% said they struggled to maintain compliance.

Chris Goettl, vice president of product management for endpoint security at Ivanti, said that most vulnerabilities he saw being actively targeted in the wild are not, in fact, the ones that security teams are prioritising.

“Which is why we need a risk-based approach to patch prioritisation and remediation,” he said. “Organisations need to manage multiple distinct tracks of remediation: routine monthly maintenance, higher-priority updates for commonly targeted applications like browsers and communication tools, and urgent zero-day responses as an example.

“By properly configuring systems, all continuous updates are assigned to one of these tracks and handled as part of continuous patch management processes versus once a month,” he said.

Data gaps and siloed teams

Security professionals also said they lacked sufficient data to help them make informed decisions about what to patch, with the most frequent gaps arising in areas such shadow IT, contextual gaps about what vulnerabilities are exposing their systems, and blind spots linked to patch configuration, compliance status, or meeting patch service level agreements.

“If we think about organisations that really want to elevate their remediation efforts, there’s some important contextual data they’ll need to have to do so,” said Daren Goeson, senior vice president of product management for Ivanti’s secure unified endpoint management (UEM) lines.

“Number one is visibility of their attack surface, second is the context of vulnerabilities within the organisation’s attack surface, third is thread intelligence to determine how risk is evolving, and fourth is compliance view that focuses on the real risk within the organisation.”

Organisations also found existing silos between cyber security and IT teams were creating problems, with cyber teams prone to blaming IT teams for lacking a sense of urgency and failing to understand the organisation’s risk appetite. Ivanti said there was often a push-pull dynamic in play where security teams say they need to respond rapidly but IT teams say they need stability, the two being at odds with one another.

Additionally, the report said, the ‘everything is urgent’ mentality causes more problems by pressuring IT teams to push updates without properly testing them, while the interplay between silos and misaligned priorities leads to miscommunication and unclear ownership of patch duties, introducing yet more risk.

Does AI hold the key?

Ivanti suggested that advances in artificial intelligence (AI) and automation could hold the key to helping overcome the problems outlined in the report, although it also noted that organisations said they saw multiple barriers – including cost and skills – preventing them from taking advantage of these capabilities.

The report highlighted two ways in which AI solutions could offer organisations a way to improve their patch management strategy – through fast analysis of vulnerabilities based on factors like threat and risk context, and by automating patch testing and deployment workflows.

“If you’re using a risk-based prioritisation system, AI can pull in massive amounts of information from a variety of different sources and tools, analyse that information and use predictive models to make risk-based scoring as efficient as possible,” said Goettl.

“After you identify your risk appetite, the next step is configuring automation to continuously monitor and remediate any needed updates in alignment with your risk prioritisation,” he concluded.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Google’s NotebookLM now features AI notebooks on curated topics
Next Article Xiaomi obtains EV production license, prepares for third model · TechNode
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Google Chrome 138 Will Be Last Version to Support macOS Big Sur
News
iPhone 17 Air: Will Apple’s ultra-thin iPhone bend?
News
Intel Media Driver 2025Q2 Ships Panther Lake Video Encoding Support
Computing
Wallpaper Wednesday: More great phone wallpapers for all to share (July 16)
News

You Might also Like

News

Google Chrome 138 Will Be Last Version to Support macOS Big Sur

5 Min Read
News

iPhone 17 Air: Will Apple’s ultra-thin iPhone bend?

5 Min Read
News

Wallpaper Wednesday: More great phone wallpapers for all to share (July 16)

5 Min Read
News

CPI Data Is Still Soft; Is It Enough for a Rate Cut?

13 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?