Skip to content
Artwork for Security Intelligence Podcast
Security Intelligence Podcast · June 26 · 22 min

Patch management is dead. Here’s what’s taking it place

Patch management, as most organizations practice it, is fundamentally broken. It treats what should be a strategic, risk-informed decision as a checkbox item. And checkboxes don't get done. The fix isn't better patching. It's exposure management: a risk-based approach that connects your vulnerabilities to your business context, your attack surface and the real-world threat landscape. In this episode of Security Intelligence, IBM X-Force North America Leader of Incident Response Ryan Anschutz walks us through why patch management fails, what exposure management does differently and what it all means for defenders right now. Ryan shares war stories from the field, including a firmware vulnerability that turned into a multi-continent ransomware outbreak and a MOVEit response that kept one organization out of the headlines while its competitors made them for all the wrong reasons. The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity. Follow the Security Intelligence podcast on your preferred platform: https://www.ibm.com/think/podcasts/security-intelligence Subscribe to the IBM Think newsletter: https://www.ibm.com/forms/news-mkt-52954 Follow the Security Intelligence podcast on your preferred platform: https://www.ibm.com/think/podcasts/security-intelligence Learn more about cybersecurity: https://www.ibm.com/think/security "How IBM Can help" component at the bottom driving to www.ibm.com/products/guardium-ai-security and www.ibm.com/solutions/data-security

0:00-22:07

transcript

No transcript — this publisher did not publish one.

show notes

Patch management, as most organizations practice it, is fundamentally broken. It treats what should be a strategic, risk-informed decision as a checkbox item. And checkboxes don't get done.

The fix isn't better patching. It's exposure management: a risk-based approach that connects your vulnerabilities to your business context, your attack surface and the real-world threat landscape.

In this episode of Security Intelligence, IBM X-Force North America Leader of Incident Response Ryan Anschutz walks us through why patch management fails, what exposure management does differently and what it all means for defenders right now.

Ryan shares war stories from the field, including a firmware vulnerability that turned into a multi-continent ransomware outbreak and a MOVEit response that kept one organization out of the headlines while its competitors made them for all the wrong reasons.

The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity.

Follow the Security Intelligence podcast on your preferred platform: https://www.ibm.com/think/podcasts/security-intelligence

Subscribe to the IBM Think newsletter: https://www.ibm.com/forms/news-mkt-52954

Follow the Security Intelligence podcast on your preferred platform: https://www.ibm.com/think/podcasts/security-intelligence

Learn more about cybersecurity: https://www.ibm.com/think/security

"How IBM Can help" component at the bottom driving to www.ibm.com/products/guardium-ai-security and www.ibm.com/solutions/data-security

links5