Trending Topics

CISOs must think about their teams’ mental health after Microsoft’s record-breaking Patch Tuesday
September’s Patch Tuesday saw Microsoft confirm an astonishing 973 security vulnerabilities. You would be correct to think that this is a wake-up call. However, I suggest one alarm needs to sound in the CISO’s office: Are you doing enough to support your security teams as patch counts continue to escalate dramatically?
With 119 critical-rated vulnerabilities, and two already added to the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) Catalog, I am not alone in suggesting that people as well as processes must be front and centre when it comes to your organisation’s response.
“What about your people?” asked Tyler Reguly, Associate Director of Security R&D, at Fortra. “How are they handling the current levels of patches and the tickets that those produce? Are they managing? Are they struggling? Have you even stopped to ask them?”
All excellent questions. While it’s necessary to audit patch processes in the wake of this new normal of AI-discovered vulnerabilities by the bucketload, forgetting the human aspect could prove very costly.
Reguly told me that it is “time to put our CISOs and CSOs on notice”. He argues that it’s imperative for them to be aware of the difficulties that their security teams are facing, and to consult them about how things can be improved.
The human cost of Mythos
The danger, as I see it, is that too much emphasis is being put on process: unblock that patching bottleneck at all costs, no matter how disruptive to the team responsible for doing so.
Reguly agrees, suggesting that some CISO’s may be “eliminating soak tests because some public guidance has suggested ridiculously short patch timeframes”. Something he rightly concludes can load stress onto those teams as they will have no real idea of what outages could be caused as a result.
“If you’re doing this… STOP!” he said.
The truth is that patches need to be tested before being released to production. That has not changed. What has changed is having teams deployed after hours and on weekends to avoid business disruption, but without any real support or reward.
“Time to dig into your budget,” Reguly suggested, “and buy dinner for your teams that are working on Saturday to get patches rolled out before users return to work on Monday.”
Don’t ignore your security team’s mental health
The mental health of your security teams can’t be sacrificed at the altar of AI-inspired hysteria. Of all people, I know only too well the cost of ignoring mental health issues in the cybersecurity space.
Remember that people matter here. Change your processes to best match the needs of the team. They will understand the practical nature of securing the organisation. That’s what you pay them for, after all, right?
I will leave the last word to Reguly, who summed this up perfectly when he told me:
“If you still prioritise based on Common Vulnerability Scoring System (CVSS), you are hurting your organisation and your employees. If you are constantly flip-flopping as guidance changes, you are putting your organisation at risk and jeopardising employee happiness. You are essentially steering a ship through rough waters, and you need a steady hand to accomplish that. If you keep the ship on course, your team will be able to do the rest.”
