Software updates: the questions we get asked most
This is cheap to get right at the start and expensive to retrofit. The questions about software updates that come up most often on our calls.
Security is a maintenance habit rather than a purchase, which is why it drifts. Write the reasoning down alongside the decision, because the reasoning is what changes first.
Do we need to care about this?
Most breaches exploit a fix that already existed. There is a version of this that is over-engineered, and it is worth avoiding. Write the reasoning down alongside the decision, because the reasoning is what changes first.
Can it wait until after launch?
Occasionally. More often the post-launch version costs several times the pre-launch one. Where this goes wrong is almost never a lack of knowledge.
How do we know it is working?
Staging first prevents the update becoming the outage. It is worth being explicit about, because assumptions differ quietly. Assume whoever inherits this will have half your context and none of your patience.
What this looks like day to day
The cheapest security work is the boring kind done on a schedule. Three things worth confirming about software updates before you move on:
- Someone can say what the current setup is without going to look
- Most breaches exploit a fix that already existed — and you know whether that is true here
- There is a way to tell whether the last change to this helped
If you are not sure where your systems currently stand on this, it takes us about an hour to find out.