4 reasons why organisations can’t “just patch”

It’s time to take a clear-eyed look at what the WannaCry debacle uncovered, and also the most recent MaybeNotPetya attack….
Digital grid lines on dark background

Share this article:

Now that most of us have dried our tears, it’s time to take a clear-eyed look at what the WannaCry debacle uncovered, and the most recent MaybeNotPetya attack.

Taken by themselves, there were no new elements: ransomware; a known vulnerability; a worm spreading via a protocol that we knew should not be exposed to the Internet; abuse of operating system utilities; and an anti-sandboxing function in the WannaCry malware. We knew there were countless vulnerable systems running software that was out of support, out of date, or simply unpatched. None of this was a surprise to anyone in security.

What always seems to take some by surprise, however, is that no matter how much we talk about patching, it doesn’t happen in many cases. In fact, organizations with the most critical functions appear to struggle with software updates. It’s almost as if talking about the problem and “raising awareness” isn’t enough to actually solve it. Like the old joke about the scientist and the frog, if you cut off all four legs, the frog mysteriously loses its hearing.

So what’s keeping these organizations vulnerable, and what can we do about it, other than scolding harder until morale improves? Here are some of the factors:

If the system isn’t under your control, you can’t update it. The issue is widespread, especially among organizations below the security poverty line, but it applies just as much to financial trading terminals and banks as it does to the network run by a centralized higher education system. Voiding the warranty and licensing terms by doing your own patching is not an option for most enterprises, even assuming you know how to do it.

Organizational constraints, particularly in the public sector. Taxpayers aren’t going to pay to update hardware and software that are working just fine. Legislative mandates, spending cuts and administrative rules designed to place controls on government also interfere with the agility necessary to keep up with security threats.

“Built to last” directly conflicts with “update early and often.” When you’re paying millions of dollars for an MRI machine and suite, you expect it to last for decades, and indeed it was built for that purpose. The idea of changing it by updating the software on a weekly or monthly basis was unthinkable when most of these were built. Because patient safety is paramount, healthcare systems cannot be updated if doing so will threaten their availability. Even if the software is patched, it requires a new round of safety certifications that take months.

Any system with external, highly entangled dependencies will take longer to update— even years, as integration testing, certifications, regulatory alignment in multiple countries, and staged deployment must all be carefully scheduled. Such entangled systems will also tend to have a longer tail, as trailing populations of users with more restrictions take longer to catch up. Microsoft discovered this with Windows XP, a perfectly functional operating system that works so well that it’s been deployed in everything from kiosks to equipment, and has been running for years. Acknowledging this reality, the company has issued updates for the large and critical body of legacy systems out there.

Expecting every company to adopt DevOps and be a Netflix isn’t practical; we go to war against malware with the systems we have, not the ones we wish to have, or that security principles state we ought to have. We need to address decades of legacy systems and organizational constraints, as well as the plain fact that nobody knows today how much effective security should cost a given enterprise; we don’t even know whether it’s affordable.

But we know we have to make changes, and we have to help critical industries that are trapped by their circumstances. Some ideas being floated around include a “cash for clunkers” program for healthcare; standing up more secure infrastructure to which SMBs could migrate, with help, is another one.

Educating non-IT vendors and manufacturers so that they start building in security will take a long time, and in the meantime, the number of truck rolls to fix legacy equipment is probably staggering. Re-aligning security incentives, both financial and legal, could affect the economy on the same scale as affordable healthcare. There is no “just” about it, but it’s time to do it.

In the meantime, there are some short-term measures that enterprises can take to address these and similar threats. One list is here; another is here; there are others in varying degrees of practicality. Good luck, and keep the hankies handy.

About Security Buyer

Security Buyer is the leading authority in global security content, delivering expert news, in-depth articles, exclusive interviews, and industry insights across print, digital, and event platforms. Published 10 times a year, the magazine is a trusted resource for professionals seeking updates and analysis on the latest developments in the security sector.

To submit an article, or for sponsorship opportunities, please contact our team below.

Rebecca Spayne Picture

Rebecca Spayne

Group Managing Editor

Georgina Turner Picture

Georgina Turner

Sales Manager

Afua Akoto Picture

Afua Akoto

Marketing Manager

Related News

Eun-Kyung-Hong_- securitybuyer.com

How AI Manages Mixed Surveillance Workloads

Eun-Kyung Hong, HDD Product Manager at Toshiba Electronics Europe GmbH discusses AI optimisation in mixed surveillance workloads
ASSA ABLOY - securitybuyer.com

ASSA ABLOY Door Group highlights importance of BS 8214:2026

ASSA ABLOY Door Group is supporting Fire Door Safety Week 2026 by raising awareness of the latest update to BS 8214:2026
OPTEX at Essen - securitybuyer.com

OPTEX to showcase perimeter solutions at Security Essen

OPTEX will present its latest perimeter and asset protection solutions at Security Essen 2026, one of Europe’s leading security trade fairs.
Dallmeier

Building Trust in Modern Video Security

Rebecca Spayne, Managing Editor of Security Buyer, speaks with Josua Braun, Chief Revenue Officer at Dallmeier electronic, about cyber resilience, trusted supply chains, the practical value of artificial intelligence and what security professionals should consider when investing in modern video technology. 
Verkada

Verkada Expands AI Security Platform

Verkada, a provider of AI-powered physical security and operations, has unveiled new capabilities for vehicle fleets, enterprise sound systems, and building operations during its annual customer conference, VerkadaOne.
Assa Abloy

“Mobile-first” access 

David Moser, of ASSA ABLOY Opening Solutions EMEIA explores how mobile digital access unlocks new possibilities for organizations everywhere.
Traka - securitybuyer.com

Integrating Digital and Physical Security

Tom Smith, Vice President and Head of EMEIA for Traka, discusses convergence and the expanding role of integrated key and asset management. 
Traka GSX

GSX Exhibitor Spotlight – Traka

Traka, an ASSA ABLOY company and the global leader in intelligent management solutions for keys and equipment, returns to GSX 2026 at Booth #1233. Traka experts will be available to provide personal demonstrations of how smart asset management systems are streamlining operations in numerous industry verticals. 
Rhombus GSX

GSX Exhibitor Spotlight – Rhombus

When it comes to modernising physical security, Rhombus stands out by making it smarter, simpler, and genuinely easier to manage; no matter the size or complexity of the business. 
Keynetics at Essen - securitybuyer.com

Keynetics to Debut at Security Essen 2026

The UK-based Keynetics will exhibit at Security Essen for the first time, showcasing SentriGuard, its smart key-management
Scroll to Top