Unpatched software is the root cause of a significant share of successful breaches, and most of those breaches exploit vulnerabilities for which a patch already existed at the time of the attack. A disciplined patch management program closes that window before attackers can use it.
Why Patch Management Fails in Practice
Most organizations patch eventually. The problem is “eventually” often means weeks or months after a vendor releases a fix, which is long after threat actors begin scanning for and exploiting that exact CVE. Common failure modes include:
- No asset inventory. You cannot patch what you do not know exists. Shadow IT, remote employee laptops, and decommissioned servers that are still reachable are frequent blind spots.
- Inconsistent testing cycles. Applying a patch the day it drops without testing can break line-of-business applications. Waiting too long to test creates exposure.
- No prioritization. Treating a CVSS 4.0 cosmetic bug the same as a CVSS 9.8 remote-code-execution vulnerability wastes effort and delays critical fixes.
- No verification. Assuming a patch deployed is a patch applied. Failed deployments, incompatible endpoints, and reboots that never completed are common and easy to miss without confirmation reporting.
The NIST Framework for Patch Management
NIST SP 800-40 Revision 4, “Guide to Enterprise Patch Management Planning,” is the clearest public standard available. Its core guidance translates into four operational stages:
- Identify. Maintain a complete software and firmware inventory, tied to your asset management system. Every endpoint, server, network device, and application needs to be in scope.
- Evaluate. Score vulnerabilities using the Common Vulnerability Scoring System (CVSS) and cross-reference with CISA’s Known Exploited Vulnerabilities (KEV) catalog. A vulnerability on the KEV list demands faster action regardless of CVSS score, because active exploitation is already confirmed.
- Remediate. Apply patches within defined service-level windows based on severity. NIST recommends aiming for critical patches within 15 days of release. High-severity patches should follow within 30 days, and medium/low within 60 to 90 days.
- Verify. Run compliance reports after each patch cycle to confirm deployment success rates. Any endpoint below 100 percent needs follow-up, not just a note in a ticket.
Windows Patch Management: Specific Controls That Work
Windows environments need more than Windows Update turned on. Microsoft releases patches on the second Tuesday of each month (Patch Tuesday), with occasional out-of-band releases for critical zero-days.
Practical controls for Windows patch management:
- Use a centralized patch management platform. ManageEngine Endpoint Central (formerly Desktop Central) is widely deployed in SMB environments and gives technicians a single console to deploy, track, and report patches across Windows, macOS, and Linux. Qualys Patch Management integrates directly with Qualys vulnerability scan data, so discovered vulnerabilities and patch deployment live in the same workflow.
- Separate patch rings. Deploy patches to a pilot group (5 to 10 percent of endpoints) first. If no application breakage appears within 48 to 72 hours, expand to the full fleet.
- Enable automatic patching for third-party apps. Windows Update only covers Microsoft products. Browsers (Chrome, Firefox, Edge), PDF readers, Java, and media players are frequent attack vectors and require separate patching coverage.
- Force reboots on a schedule. Patches that require a reboot are not fully applied until the reboot completes. Configure enforced restart windows during off-hours with adequate user notification.
Vulnerability Management: Beyond the Patch Cycle
Patch management is one part of a broader vulnerability management program. Vulnerability management adds continuous scanning and risk-based decision-making on top of the patch cycle.
Key components:
- Authenticated vulnerability scans. Tools like Qualys VMDR or Tenable Nessus, run with domain credentials, surface vulnerabilities that unauthenticated scans miss, including misconfigurations, weak cipher suites, and end-of-life software.
- Risk-based prioritization. Not every vulnerability has a patch available. Compensating controls, network segmentation, or disabling an unused service may be the appropriate remediation for vulnerabilities where no vendor patch exists.
- Remediation SLA tracking. Define and enforce timelines in writing. If a critical CVE goes 30 days without remediation, your vulnerability management process needs an escalation path, not just a continued open ticket.
- Dealership-specific note. Auto dealerships run DMS platforms (like CDK Global or Reynolds and Reynolds), F&I software, and OEM-connected systems alongside standard Windows infrastructure. Those specialized applications often have their own patch cadences set by the vendor and may require coordination with your dealer group’s IT or the DMS vendor’s support team before updates are applied.
Building a Patch Management Policy
A policy does not need to be long, but it does need to be written down and followed. At minimum it should define:
- Asset inventory scope and update frequency
- Patch severity tiers and corresponding remediation windows
- Testing and pilot rollout procedures
- Verification and reporting requirements
- Roles: who approves emergency patches, who confirms deployment, who escalates failures
If your team does not have the bandwidth to maintain this cycle consistently, a managed IT services provider running a 24/7 patch management program can enforce it as a continuous service rather than a periodic project.
Get Help from COMNEXIA
COMNEXIA has been managing IT security for businesses across the Southeast for 35 years, including dealerships with complex, vendor-specific infrastructure requirements. Our managed IT services include continuous patch management and vulnerability scanning, and our cybersecurity practice handles the risk-based prioritization and remediation tracking that keeps clients off breach headlines. Call us at (877) 600-6550 or contact us to discuss where your patch program stands today.