By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Marketing In Asia
  • Marketing
    • Viral
    • Expert Opinions
    • News & Trends
    • Research
    • Market Podcasts
    • Market Videos
    Marketing
    This category deals with best news and updates on marketing and branding news and events.
    Show More
    Top News
    Sangeeta Mudnal
    How conversational commerce benefits marketers
    1 month ago
    Andrew Monu, VP of Marketing, LinkedIn
    Marketing in Asia Presents an Exclusive Interview with Andrew Monu, VP of Marketing, LinkedIn
    1 month ago
    Ankita Thakur
    Marketing in Asia Presents an Exclusive Interview with Ankita Thakur, Group Head of Marketing, MoneyHero Group
    1 month ago
    Latest News
    Marketing in Asia Presents an Exclusive Interview with Cris Tan, Associate Director, Publisher Development (SEA)
    3 weeks ago
    Time for ASEAN to Rethink a Single Currency Amid Global Trade Tensions
    3 weeks ago
    Marketing in Asia Presents an Exclusive Interview with Carine Chin, Head of Corporate Marketing, Etiqa Insurance Singapore
    3 weeks ago
    Marketing in Asia Presents an Exclusive Interview with April Tayson, Regional VP INSEAU at Adjust
    1 month ago
  • Startup
    • News from Startup world
    • Startup Stories
    • Trends and Opinions
    • Startup Podcasts
    • Startup Videos
    Startup
    News and articles from startup and venture investment world
    Show More
    Top News
    Japan’s Evolving Booze Culture: A Market in Transformation
    Japan’s Evolving Booze Culture: A Market in Transformation
    8 months ago
    text
    Safe Space™ announces partnership with National Healthcare Group as it continues to boost employee support and wellbeing
    9 months ago
    Sakshi Kalani Founder & CEO of Savy Click and Jaipur Unfolded
    AI-Powered Analytics: Sakshi Kalani on Influencer Marketing in 2025
    9 months ago
    Latest News
    Byron J. Fernandez: Minimize the stress of business crises with strong CX
    6 months ago
    Vedant Mahajan Acquires Stake in Flite: Transforming Event Technology with Innovation
    6 months ago
    Navigating the Digital Economy and Tax Challenges for SMEs
    7 months ago
    sehatUP Launches India’s First Integrated Digital Health Clinic, Pioneering Holistic Healthcare
    8 months ago
  • Business
    • Feature Stories
    • News
    • Business Podcasts
    • Business Videos
    Business
    News and press releases from business world of Asia
    Show More
    Top News
    Andrew Monu, VP of Marketing, LinkedIn
    Marketing in Asia Presents an Exclusive Interview with Andrew Monu, VP of Marketing, LinkedIn
    1 month ago
    Ankita Thakur
    Marketing in Asia Presents an Exclusive Interview with Ankita Thakur, Group Head of Marketing, MoneyHero Group
    1 month ago
    Mary Reschar, Head of Product Marketing, Fluent Commerce
    How retailers can prepare for the rise of Gen Zalpha
    1 month ago
    Latest News
    Marketing in Asia Presents an Exclusive Interview with Cris Tan, Associate Director, Publisher Development (SEA)
    3 weeks ago
    Time for ASEAN to Rethink a Single Currency Amid Global Trade Tensions
    3 weeks ago
    Marketing in Asia Presents an Exclusive Interview with Carine Chin, Head of Corporate Marketing, Etiqa Insurance Singapore
    3 weeks ago
    Marketing in Asia Presents an Exclusive Interview with April Tayson, Regional VP INSEAU at Adjust
    1 month ago
  • Society
    • Inspiration
    • Destinations & Travel
    • Food & Gourmet
    • People
    • Young Voices
    • Society Videos
    • Society Podcasts
    Society
    News and articles from and for societies around us
    Show More
    Top News
    Smashers Sports Acquires Delhi Franchise of WPBL: A Game-Changer in India’s Sports Entertainment
    Smashers Sports Acquires Delhi Franchise of WPBL: A Game-Changer in India’s Sports Entertainment
    6 months ago
    Resorts World Cruises Sets Sail from Dubai with New Luxury Gulf Voyages
    Resorts World Cruises Sets Sail from Dubai with New Luxury Gulf Voyages
    8 months ago
    Australia luxury property
    Australia’s Luxury Real Estate Market Soars as Affluent Buyers Seek Waterfront Dreams
    8 months ago
    Latest News
    From Taboo to Triumph: How Malaysians Are Transforming Their Intimate Health Journey
    3 months ago
    Top 5 Misconceptions About Antibiotics Malaysians Need to Stop Believing
    3 months ago
    Eagle Eye Reveals Impact of Loyalty Programs on APAC Retailers
    3 months ago
    Elevate Your Haircare in 2025 with Jung Beauty’s Luxurious Camellia Edition Treatment
    6 months ago
  • Press Release
  • Awards
    • MIA Impact Circle Stellar CxO 2023 Malaysia
    • MIA Impact Circle Stellar CxO 2023 India
    • MIA Impact Circle Stellar CxO 2023 Philippines
    • Australian Women in Business Excellence Awards
    • MIA Impact Circle Stellar CxO 2024 Singapore
    • Mia Impact Circle Stellar Cxo 2024 Hongkong Award 
    • Mia Impact Circle Stellar Cxo 2024 Indonesia Award 
Search
Technology
  • Hot
  • Trending
  • Editor’s Choice
  • NSFW
  • Reactions
  • Authors
  • Viral on Internet
Other Pages
  • My Bookmarks
  • Customize Interests
  • About Marketing In Asia
  • Business Register & Login
  • Web Stories
  • Videos
  • Disclaimer
  • Terms of Service
  • Privacy Policy
© 2024 Marketing In Asia Sdn Bhd. All Rights Reserved.
Reading: The Infosec Clock is Ticking: Why Enterprise Users Can’t Wait for Patch Updates
Share
Sign In
Notification Show More
Latest News
CleverTap
CleverTap Launches ‘Promos’ – The Industry-First All-In-One Rewards Management Platform
Press Release
Cherry So
HKTDC Maintains 3% Export Growth Forecast
Press Release
adyen
Puma and Adyen Showcase the Speed and Flexibility of Unified Commerce
Press Release
Amazon
Amazon Singapore’s Prime Day Returns in July with First-Ever Week-Long Event from 8 to 14 July
Press Release
HOY
The Trade Desk and HOY Expand Strategic Partnership to Advance Programmatic CTV Advertising in Hong Kong
Press Release
Aa
Marketing In Asia
Aa
  • Hot
  • Trending
  • Editor’s Choice
  • NSFW
  • Reactions
  • Authors
  • Viral on Internet
  • My Bookmarks
  • Customize Interests
  • About Marketing In Asia
  • Business Register & Login
  • Startup Register & Login
Search
  • Marketing
    • Viral
    • Expert Opinions
    • News & Trends
    • Research
    • Market Podcasts
    • Market Videos
  • Startup
    • News from Startup world
    • Startup Stories
    • Trends and Opinions
    • Startup Podcasts
    • Startup Videos
  • Business
    • Feature Stories
    • News
    • Business Podcasts
    • Business Videos
  • Society
    • Inspiration
    • Destinations & Travel
    • Food & Gourmet
    • People
    • Young Voices
    • Society Videos
    • Society Podcasts
  • Press Release
  • Awards
    • MIA Impact Circle Stellar CxO 2023 Malaysia
    • MIA Impact Circle Stellar CxO 2023 India
    • MIA Impact Circle Stellar CxO 2023 Philippines
    • Australian Women in Business Excellence Awards
    • MIA Impact Circle Stellar CxO 2024 Singapore
    • Mia Impact Circle Stellar Cxo 2024 Hongkong Award 
    • Mia Impact Circle Stellar Cxo 2024 Indonesia Award 
Have an existing account? Sign In
Follow US
© 2023 Marketing In Asia Sdn Bhd. All Rights Reserved.
Marketing In Asia > Blog > Business > Feature Stories > The Infosec Clock is Ticking: Why Enterprise Users Can’t Wait for Patch Updates
Feature Stories

The Infosec Clock is Ticking: Why Enterprise Users Can’t Wait for Patch Updates

profile
Last updated: 2022/07/29 at 5:57 PM
Priority Consultants
Share
6 Min Read
the-infosec-clock-is-ticking:-why-enterprise-users-can’t-wait-for-patch-updates
SHARE

Sound security policies have always been important but with the interconnected state of modern business, IT leaders are concerned more than ever before. However, this rising tide has also led to misguided panic and a doomed bid to cover all bases with some unfortunate by-products.

Many think there are no alternatives to the carousel of paying the annual maintenance “tax” and applying continuous disruptive software patches. But this ignores the nature of the modern security threatscape and that starts with the realisation that most enterprise software companies are not security companies and likely never will be. ERP vendor-supplied software patches are usually simply bug fixes and bug fixing is almost always a glorified (and lucrative) form of bad code Whac-A-Mole.

 

Can you wait so long for a security patch?

Typically, software vendors review bugs to determine their validity and significance, which can be an arduous and lengthy process. Vendors must identify all of the possible areas where the affected library or codebase was used, what platforms are affected, and its history. This is the point where vendors may figure out that a bug has existed for quite some time, often up to 20 or even 30 years. In fact, many times the same issue is patched again even years after as it’s very common to “miss a spot.”

 

Get off the security patching hamster wheel

But eventually, a patch is released, and this is where the true pain begins for organizations.  Patching is typically a very lengthy and convoluted process, especially for large enterprise platforms where a company’s extensive customisations are likely to break due to some of the unexpected by-products of that patch’s behaviour.  Even if a company has a policy of immediate patching (which is very rare and more likely annual or at best monthly), it can easily be a year before the patch is downloaded, installed, tested through the landscape and eventually put into production. 

Customers must wait for the patches to be released, perform rigorous regression testing, run Quality Assurance, do end-user testing, and repair the things the patches break multiplied by every single database or application instance in the company. This is all massively time-consuming, risky, disruptive, and expensive. Oh, and then when something very similar pops up again, it’s time to revive the entire hamster wheel all over again, because software vendors are commonly only blacklisting commands, which are frequently bypassed by the next command in the list, and customers are forced to repeat this cycle hundreds of times over.

For example, the Apache Struts vulnerability that led to the Equifax breach was due to an Insecure Deserialization flaw (CWE-502, one of many further CWE:20, Improper Input Validation flaws) heavily prevalent in most applications today. And THE patch that was released to address the issue still doesn’t solve the weakness of either CWE-502 or CWE-20, it only addresses the one exposure (CVE-2017-5638), around the same time, another patch was released to address the same type of weakness (CVE-2017-9805). This is why there have been hundreds of patches released to address Insecure Deserialization most of which are bypassed time and time again. Beyond the things that have been patched, think of the big headline security cases over the years: Marriott, Target, AdultFriendFinder, eBay… not one was solved by a vendor patch. These companies and others are more likely to have been undone by inattention to weak configurations, insider threats, lax admin actions, unenforced policies and the like. These modern threat landscapes are causing ERP customers to question if they are really safe relying on vendor patches for their security policies.

The simple fact is that vendor patches are complex and even when applied, they tend to be limited in scope because they only address the issue that was discovered in the wild, and do not address the weakness as a whole.

 

The bigger security picture

Modern security solutions address almost all of the applicable common weakness enumerations, and not just individual exposure points.  For example, instead of dismantling a single SQL injection issue and keying on individual syntax vulnerabilities (vendor patch strategy), modern solutions mitigate SQL injection weaknesses as a whole.

Today, CISOs require modern and more cost-effective security strategies such as In-memory database protections, or real-time self-protection for middleware and applications, and other modern techniques that offer far more effective and proactive ways to address the security hygiene of enterprise software stacks, all with massive reductions in downtime and business disruption. The smartest CISOs leverage the use of these technologies as a common control or compensating control as applicable to meet or exceed security auditors expectations where patching is just too impractical or even not possible for the business.

You Might Also Like

Modern retail marketing technology solution allows businesses to deliver mind-blowing numbers of offers in real time

Unpacking the power of personalisation in your tech stack

How Malaysian Brands Can Turn Holiday Shoppers into Loyal Customers: A Data-Driven Strategy

Dow Jones Unveils AI-Powered Korean Language Service to Transform Financial News Access in South Korea

Charting a revolutionary approach to customer service with GenAI

MIA
Get Latest Job Updates on Whatsapp and Telegram
SCIKEY Logo
Whatsapp
Telegram
TAGGED: IT, security, securitypatch, securitypolicy

Sign Up For MIA Newsletter

Be keep up! Get the latest updates about the Marketing world delivered straight to your inbox.

    By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
    Priority Consultants July 29, 2022 October 26, 2021
    Share This Article
    Facebook Twitter LinkedIn Email Copy Link Print
    Share
    What do you think?
    Love0
    Happy0
    Joy0
    Surprise0
    Sad0
    Angry0
    Cry0
    Previous Article cnn-and-samsung-partner-for-a-global-campaign-exploring-the-positive-power-of-technology CNN And Samsung Partner For A Global Campaign Exploring The Positive Power Of Technology
    Next Article get-to-know-chai-zhi-ying,-founding-member-and-chief-commercial-officer-of-youadme Get To Know Chai Zhi Ying, Founding Member and Chief Commercial Officer of YouAdMe
    Leave a comment Leave a comment

    Leave a Reply Cancel reply

    You must be logged in to post a comment.

    9.5k Followers Follow
    3.4k Followers Like
    1.1k Followers Follow
    214 Followers Follow
    208 Subscribers Subscribe

    Latest News

    CleverTap
    CleverTap Launches ‘Promos’ – The Industry-First All-In-One Rewards Management Platform
    Press Release 2 days ago
    Cherry So
    HKTDC Maintains 3% Export Growth Forecast
    Press Release 2 days ago
    adyen
    Puma and Adyen Showcase the Speed and Flexibility of Unified Commerce
    Press Release 3 days ago
    Amazon
    Amazon Singapore’s Prime Day Returns in July with First-Ever Week-Long Event from 8 to 14 July
    Press Release 3 days ago

    PropertyGuru

    property guru

    You Might also Like

    Aaron Crowe
    AnalysisBusinessFeature Stories

    Modern retail marketing technology solution allows businesses to deliver mind-blowing numbers of offers in real time

    1 month ago
    Sarah Jarvis
    Feature StoriesInterviews

    Unpacking the power of personalisation in your tech stack

    3 months ago
    Jan Wong Founder of OpenMinds Group
    Feature StoriesOpinionResearchTrends

    How Malaysian Brands Can Turn Holiday Shoppers into Loyal Customers: A Data-Driven Strategy

    7 months ago
    Elayne Gan, APAC General Manager
    Feature StoriesNewsTechnology

    Dow Jones Unveils AI-Powered Korean Language Service to Transform Financial News Access in South Korea

    7 months ago
    //

    Get Asia to Notice You

    Quick Link

    • Contact
    • RSS Terms of Service
    • Policies & Standards
    • About Us
    • FAQ
    • Disclaimer
    • Terms Of Service
    • Privacy Policy

    Top Categories

    • Marketing
    • Startup
    • Feature Stories
    • News
    • People
    • Inspiration

    Sign Up for Our Newsletter

    Subscribe to our newsletter to get our newest articles instantly!

      Marketing In AsiaMarketing In Asia
      Follow US
      © 2024 Marketing In Asia. All Rights Reserved.
      • Disclaimer
      • Terms of Service
      • Privacy Policy