In this episode of Cyber Security Inside, Tom and Camille dive into managing and securing patch updates with Gabe Frost, Group Project Manager at Microsoft. The conversation covers:

  • How conversations about patches and updates have changed over the past few years as we have become increasingly digital and hybrid.

  • How the wide variety of hardware and software combinations makes it difficult to predict how a patch will run.

  • New technology that is being developed to collect information to make patches and updates work in such a diverse landscape.

  • How to manage risk and security when sending an update to large numbers of people.

... and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • With how the world has changed to become so much more digital and so much more hybrid over the past few years, thinking about patches and updates has changed significantly.

  • There are now so many different combinations of hardware and software that it is nearly impossible to know everything that could happen and everything that might need to be built into updates. This is why many people in the industry, including Microsoft, are focusing so much on analytics.

  • Because there are so many softwares interacting with each other, there is no way to predict all the possible scenarios. Sometimes, a device might not update like expected, and people want to know why. IT then has to use logs and tools and try to debug what happened and why the intent of the programmer is not being carried out. This is very challenging, especially remotely.

  • In terms of waiting to run a patch, the answer is not always clear cut. Sometimes there are patches that apply to every user that have to do with broad organization risk and security. But sometimes there are security issues that only affect a certain combination of factors. There is no one-size-fits-all-answer.

  • There is a risk with every part of this. From waiting to run an update to having everything on auto updates, there will always be the possibility of creating a vulnerability. This is partially why not all users will always get an update at the same time. Some updates are pushed in “rings,” or groups of people that get updates in a roll-out way.

  • When they roll out updates, there is more that goes into that than one might think. How do you decide which devices to put in the first ring for updates? Perhaps it’s the people that will be more accommodating to risk. So it is often the tech folks, who will understand if something happens.

  • Because the hardware and software can vary so drastically from device to device, when rolling out an update teams have to look really carefully at signals coming back from those devices and error reports and crashes. And that requires building machine learning and AI models to do.

  • Because updates and patches can really affect productivity and sometimes the economy, there is a lot of impact on the world that can happen with these updates. Deployment has to be carefully planned and consideration has to go to spreading out the risk and leveraging the capabilities to manage the risk.

  • There are tools, even ones that Microsoft provides and is testing, to help manage risk. They can select the smallest number of devices in your company as possible that have the highest concentration of hardware and software combinations so that you can pull as much data as possible while putting the fewest devices possible at risk.

  • Governments are starting to encourage populations to update. It could be that they get more involved in this in the future.

Some interesting quotes from today’s episode:

“Figuring out how to do this together in a way, and deliver solutions and tech that address the broad set of problems, because they’re all intertwined, you know?” - Gabe Frost on people collaborating to address new developments in updates and patches

“We’ve spent a long time making sure that the human sitting behind the PC attached to a device is really the human we think they are. But we haven’t spent as much time saying, ‘Is that device really the device we expect it to be?’” - Tom Garrison on shifting focus

“IT has been given this monumental task of just somehow knowing everything, right? And figuring out how to overcome all the obstacles that are presented to them, oftentimes blindly.” - Gabe Frost

“You need to have some sense of what compliance means to you and what software revisions are on that machine, when there’s umpteen amount of updaters that are floating around.” - Gabe Frost

“The biggest challenge is the balance between user experience and security.” - Gabe Frost on waiting to patch or patches that don’t apply to every user

“Is there risk? Yes. The question is what are the tools that you have to manage that risk so that you’re transferring unknowns to knowns.” - Gabe Frost on if there is a risk on having everything auto update

“What we’ve had to learn when we roll out updates to the billions of devices on Windows is: how do we determine the probability on a per device basis that this update is going to be successful on this device?” - Gabe Frost on the unknowns of updates on different devices with different hardware and software

“It’s an economy, and they’re changing all the time. How you reason through that risk is super challenging” - Gabe Frost on rolling out to devices

“If you turn on device telemetry and you authorize Microsoft service - our deployment service - to process that information in a compliant data boundary for you, then it will actually determine: of this big group of devices you handed me, what is the smallest number of devices that have the highest concentration of hardware and software combinations? And it will only pick those. So I can get you the broadest coverage with the least amount of devices.” - Gabe Frost on using tools to determine rings

“There’s just more and more on-ramps for malicious activity and it just presents that much more of a challenge for our partners - in IT, customers. It’s never been more important to be thinking about patch compliance and what it means.” - Gabe Frost

“It’s not only the tools and the flexibility in terms of how to update these things, but also how to reason over it, how to reason over your success, and how to reason over opportunities to actually improve and get better.” - Gabe Frost on what success looks like in patch compliance