How important is patch management?
- by James Hill
Problem
I'm trying to sell the idea of organizational patch/update management and antivirus management to my superiors. Thus far, my proposition has been met with two responses:
We haven't had any issues yet (I would add that we know of)
We just don't think it's that big of a risk.
Question
Are there any resources available that can help me sell this idea?
I've been told that 55-85% of all security related issues can be resolved by proper anti-virus and patch/update management but the individual that told me couldn't substantiate the claim. Can it be substantiated?
Additional Information
1/5 of our computers (the ones on the building) have Windows update turned on by default and anti-virus installed. 4/5 of our computers are outside corporate and the users currently have full control over anti-virus and Windows updates (I know this is an issue, one step at a time).