Software Update Management: Challenges and Benefits
Software update management is a vital and complex process. Timely and correctly managed patching optimizes security, regulatory compliance, availability, and functionality. Haphazard software update management can cause security gaps, compatibility issues, sluggish or inconsistent responsiveness, excessive downtime, or unavailability of important features. Patching involves more than occasional updates of an OS and apps for servers and user machines. Firmware patches can be a critical for peripheral devices like printers and scanners, network appliances like routers and wireless access points, and Internet-of-Things devices such as sensors and health monitors.
Progent's Software Update Management services can oversee IoT devices like alarms and health monitors
The update process can pose a number of challenges that can differ from network to network. Assets that could need updating can be located on site, in the cloud, on the road, or in the offices of telecommuters. Networks may include a mix of Microsoft Windows, Linux, Apple, and Google operating systems and apps. Some patches can be installed automatically and at virtually any scale using tools like Configuration Manager, Intune, or Azure Update Management. Other updates must be performed manually. Patching for vital resources must be scheduled to avoid business disruption. For certain line-of-business systems, patches must be thoroughly tested before being approved for production.
Progent's support services for patch management provide organizations of all sizes a versatile and affordable alternative for assessing, validating, scheduling, applying, and tracking updates to your ever-evolving IT network. In addition to maximizing the security and functionality of your network, Progent's update management services free up time for your in-house IT staff to concentrate on strategic initiatives that deliver maximum business value to your network.
Patch management is a closed-loop lifecycle critical to your risk management strategy
Progent's Patch Management Activities
Progent offers regular and custom service packages for software and firmware patching. These managed services allow you to outsource a portion or all of your company's patch management tasks to a network support organization with over 20 years of experience providing solution design, deployment, and support to companies of all sizes worldwide. Progent operates closely with your IT management team to define the critical managed services you need. Programs offered by Progent for software update include:
- Discover network resources: This can include key platforms like Microsoft Exchange and SQL, web-facing physical and virtual servers, desktops and mobile endpoints, security devices such as VPN controllers, and infrastructure appliances like switches and wireless APs.
- Select resources to be placed under management: Progent will confer with your IT team to select which of your network resources you choose for ongoing patch management services. Progent provides a variety of standard programs that cover specific classes of items and Progent can also provide specialized service programs to meet your particular needs.
- Deploy patch management tools: Progent is experienced with a wide range of software update tools and update inventory reporting systems. Available utilities include Azure Update for cloud-based assets, System Center Configuration Manager for on-premises entities, Intune for mobile computers, IT Glue for IT asset documentation, plus a selection of advanced AV platforms. Together, these products enable you to automate and track patches for network resources residing in cloud environments, on-premises, on the move, at district offices, and in the residences of at-home workers.
- Analyze patch status and perform risk analysis of uninstalled patches: For the most part, environments with current patching are more secure and stable than those with inconsistent patching. Still, some patches are hurried into distribution and carry the potential to disturb vital network operations by causing compatibility issues, system shutdowns, or confusing changes to end-user experiences. Progent can help you to assess which updates pose a risk to your organization's IT environment, or which patches should be given an urgent priority because they defend against an imminent cybersecurity threat. Progent's background with update management services can help your organization to administer a protected computer system without compromising productivity.
- Create a software update management service program: Progent's team of consultants can help in devising and managing a software update management program that aligns with your business and security requirements. Progent offers standard and custom patch management service programs and can assist with automated and manual updating. Progent can manage business-critical assets exclusively, all updateable assets, or anything in between.
- Patch testing: Even the biggest networks such as Amazon AWS and Microsoft Azure have experienced major outages that resulted from software updates that were not sufficiently tested before being applied to live systems. For organizations with no room for downtime, Progent can help create test systems that allow you to verify that new updates will not introduce reliability issues for your network.
- Prioritize and schedule updates: Progent can help you to decide which patches should be implemented immediately and which can be postponed in order to minimize service disruption. Some key regulatory standards, such as the Payment Card Industry (PCI) Data Security Standard, require that critical security updates be implemented within a defined timeframe.
- Track update history and status: Progent's standard patch management programs include creating a centralized database for following the patch level of every monitored resource. This streamlines the task of locating where updates can be found and includes release dates, release notes, and other useful data needed for a complete update management solution.
- Troubleshoot patch problems: Updates to some key entities like an OS or application server can cause unforeseen compatibility or reliability issues, especially with outdated or home-grown applications or older hardware. Progent has the breadth of experience to assist you to understand and resolve issues that may crop up due to applying a software update.
Patch Management for Network Appliances from Cisco and Other Providers
Software and firmware patches are frequently developed for network infrastructure devices such as firewalls, routers, switches, and Wi-Fi access points. These updates usually are designed to improve cybersecurity, enhance functionality, or correct reliability problems. Managing updates for these network infrastructure appliances can be a hassle, particularly in mixed-vendor environments and systems that include a mixture of on-site datacenters, at-home workers, branch offices, and cloud-hosted resources. Besides tracking and accessing updates, network managers have to ensure that network appliances have sufficient free disk space and that updates are transferred cleanly and operate correctly.
Progent has delivered advanced assistance for Cisco networking products for over two decades and also can provide technical guidance for products from other top vendors including Juniper, SonicWall, and CheckPoint. Progent's services for patch management can assist your organization to consolidate your software update system to cover network appliances along with servers, desktop and mobile endpoints, applications, and IoT items.
Progent offers patch management support for network appliances from Cisco and other vendors
Progent's Standard and Custom Patch Management Programs
Progent offers a variety of regular patch management plans that include backup, reporting, and documentation. Cost is determined by the class and number of entities enrolled. Extra services including building environments for pre-installation patch validation are billed at normal rates. Specialized plans are also offered and usually handle unique devices and/or applications.
PROACTIVE Server Patch Management Services
Onsite or Private Cloud Server:
Microsoft Azure Cloud-hosted Servers Patch Management:
- Compliance scan of Windows and Linux servers
- Update compliance assessment report for enabled machines
- Scheduled Patching and Preventative Maintenance
- License & Asset documentation and management
- Managed Anti-Virus - Current AV system
- Begin server backup once scanned
- Additional Services Billed at time and material Rates
- IT Glue access management and asset documentation
Onsite or Virtual Workstation:
- ProSight Availability Tracking
- OS & Third Party Patch Management
- Scheduled Patching and Preventative Maintenance
- Managed Anti-Virus - current AV system
- Hosted Anti-Spam - Spam Hero
- Additional Services Invoiced at time and material Rates
- IT Glue access control and asset documentation
BASIC Server Patch Management
Managed Patch both Physical and Virtual Servers:
On Site or Virtual Workstation Patch Management:
Server or Workstation Security Service-Level Agreement (SLA) - Add on service
Security Critical Patches - applied within 48 hours of Progent being notified - invoiced only when needed
PROACTIVE Network Device Patching
Internet Facing Hardware - Managed Devices (Security appliances, firewalls, routers):
Internal Network Hardware - Managed devices (wireless controllers, Wi-Fi access points, switches):
Network Device Security Service-Level Agreement - Add-on service
Security Critical Patches - applied within 48 hours of Progent being notified - invoiced only when needed
Original Patching Process Additional Costs:
First-time patching will have an extra cost per server or network device to provide for review and recording of current patch level and any other documentation necessary for effectively managing the ongoing patching as defined previously. If multiple updates are needed that require additional work for the first-time updating, Progent will present any cost estimates above the standard patching cost.
Additional Services Available:
Download Progent's Software Update Managed Services Datasheet
For a datasheet describing Progent Software Update Managed Services, select:
Progent Patch Management Services Datasheet. (PDF - 330 KB)
Talk to a Progent Expert about Patch Management Solutions
To find out more about Progent's software/firmware update management services, call Progent at 800-993-9400 or visit Contact Progent.