A practical checklist for software updates
Most teams know this matters. Fewer have decided who owns it. Run through this the next time software updates comes up.
The realistic threat for most small businesses is automated and opportunistic, not targeted. Doing this properly once is usually cheaper than doing it approximately three times.
The checklist
- Most breaches exploit a fix that already existed
- Schedule updates rather than reacting to incidents
- Staging first prevents the update becoming the outage
- Someone is named as the owner
- There is a date to review it again
What it costs to ignore
Most breaches exploit a fix that already existed. It is worth being explicit about, because assumptions differ quietly. The version that survives contact with a real deadline is the simple one.
The short version
Security is a maintenance habit rather than a purchase, which is why it drifts. Three things worth confirming about software updates before you move on:
- Someone can say what the current setup is without going to look
- Schedule updates rather than reacting to incidents — and you know whether that is true here
- There is a way to tell whether the last change to this helped
If you want a second opinion on how yours is set up, ask.