Patching at Machine Speed Without Breaking the Business With Adaptiva
The Business of CybersecurityAugust 23, 2026
43
00:24:1022.13 MB

Patching at Machine Speed Without Breaking the Business With Adaptiva

What happens when a patch designed to protect the business creates an outage of its own?

In this episode of The Business of Cybersecurity, I speak with David Sowder, Senior Solutions Architect and OneSite Patch product specialist at Adaptiva, about balancing rapid vulnerability remediation with operational control.

David brings 25 years of IT operations and engineering experience to the conversation. He remembers receiving large spreadsheets of vulnerabilities from security teams and being responsible for turning that information into deployed fixes. That experience gives him a practical view of the gap between identifying a vulnerability and safely resolving it across thousands of endpoints.

Adaptiva’s State of Patch Management report argues that speed cannot be the only measure of success. David illustrates the problem with a library cart full of books. Pushing it down the stairs may be the fastest way to reach the lower floor, but the resulting mess defeats the purpose.

The same principle applies to patch management. Urgent deployment can reduce the period when a vulnerability remains exposed, but an inadequately tested update may break applications, interrupt customer services, or affect revenue. David recommends representative pilot groups, defined testing periods, user feedback, staged deployment, monitoring, and the ability to stop a release before it reaches the full production environment.

We also discuss why greater endpoint visibility does not automatically reduce business risk. Dashboards and vulnerability reports provide knowledge, but IT teams must perform the work required to remediate the problem. David believes closer cooperation between InfoSec and IT can reduce the time between identification and action.

Automation introduces another difficult decision. David argues that layers of manual approval frequently add delay without changing which patches are eventually deployed. His proposed alternative is to begin the process automatically, notify the right people, test through pilot groups, and prevent wider deployment when the feedback indicates a problem.

Accountability remains shared. Security leaders set risk policies, InfoSec prioritizes exposure, IT manages deployment, and application owners understand the possible business consequences. These responsibilities need to be agreed before an urgent incident arrives.

Can autonomous patch management help companies respond at machine speed without turning a security fix into a business outage? Listen to the conversation and share your thoughts with me.

Useful Links

[00:00:00] The leading issue of agentic AI in businesses right now is ensuring agents act with compliance guidelines. And Denodo applies guardrails across your entire data estate. By aligning your company's data infrastructure under one system, these guardrails perform consistently across your platform. So start scaling your business and start with Denodo. Simply visit denodo.com to learn more.

[00:00:33] When a serious vulnerability appears, everyone wants one thing. Patch it fast, soon as you can. But there's a problem. The fastest way to get a cart full of books downstairs is to push it down the staircase. Mission accomplished. Although you've also created one hell of a mess. Welcome back to the Business of Cybersecurity podcast, where my guest today is joining me from a company called Adaptiva.

[00:01:01] And we're going to talk about why speed alone isn't enough when tasked with patching thousands of endpoints. AI is helping attackers find and exploit vulnerabilities at machine speed, putting security and IT teams under constant pressure to respond faster. But rushed updates can break applications, interrupt operations, and create yet another business problem entirely.

[00:01:29] Yet we've all been there. The question is, how do you balance speed with testing, control, and accountability? Well, good news. My guest is bringing with him today 25 years of IT operations experience that should enable him to answer that question. And today we're going to discuss autonomous patching, pilot groups, human oversight, and how organizations can reduce cyber risk without breaking the business that they're trying to protect.

[00:02:00] But enough from me. Let me introduce you to my guest right now. Thank you for joining me on the show today. Can you tell everyone listening a little about who you are and what you do? Sure. I'm David Souter. I am a senior solutions architect at Adaptiva. I've been here for about five years. And I am, in addition to a senior solutions architect, I'm a product specialist for our one-site patch product,

[00:02:30] which one-site patch is basically our patch management, our autonomous patch management tool. And what I do here is I get involved with existing customers, onboarding new customers, and then evangelizing our product offering with people that have patch management needs in the industry. Before at Adaptiva, I've got about 25 years of corporate IT under my belt.

[00:02:59] Most of your guests have a rich cybersecurity background. I don't. I come from the IT operations and engineering side. Most of that time was done doing deployment services. So I would have been one of the guys that InfoSec would come to with the massive spreadsheet of vulnerabilities to take actions against. We would have had to go through that spreadsheet and find what are the vulnerabilities that we can address? How can we deploy it?

[00:03:27] Can we even resolve these? And that was one of my jobs for 25 years in corporate IT. Love it. Love it. I've got to ask, if we're going into your origin story there, what was it that made you go to the other side? Was there a story there? So what I really like about being here is the ability to help a broader swath of people. I enjoyed corporate IT. It was fine.

[00:03:53] But here at Adaptiva, I get to work with a lot of different customers, a lot of different industries, different sectors. And it's just very interesting for me to work with a broader swath of people where I'm being exposed to different challenges that they're having. And I love the challenges. I love the challenges of people that have manufacturing has their own set of challenges. Healthcare has their own set of challenges.

[00:04:23] Banks, they have regulatory and their own challenges that are unique to them. And here at Adaptiva, I get exposed to all of those things. And I feel like it's building a more well-rounded Dave. And Dave likes being well-rounded. And I don't talk about myself in third person the whole time. Don't worry about that. Brilliant.

[00:04:44] For anybody listening and hearing about Adaptiva for the first time, tell me a little bit more about what the company does and the kind of cybersecurity challenges that you're helping organizations solve across large distributed endpoint environments. What are you seeing out there? Yeah. So Adaptiva is the best little company you may not have heard of. So we've been around doing endpoint management for roughly 20 years.

[00:05:11] Most of that time, we have been buttering our bread with content delivery. Safe, secure, highly scalable content that we deliver. We use our technology to deliver content for technologies like Configuration Manager, Intune, Workspace ONE, which is now Omnisa. And recently, we have entered into the patch management space.

[00:05:36] We realized that there are a lot of gaps and a lot of challenges to deploying patches to endpoints. So we're using our platform and our technology to enter into this patch management space. And our efforts have gone well so far. We have been included in Gartner's inaugural Magic Quadrant for endpoint management tools, autonomous endpoint management tools. And so things are going very well there.

[00:06:06] And again, we're engaging with customers that we didn't really necessarily engage with before. We're now very much a concern for the InfoSec crowd, whereas before we had more of an IT focus. So I think that's where we come in, is that we're sort of bridging that gap between IT and InfoSec and providing a tool that can deploy patches at scale, at speed, and do so autonomously.

[00:06:35] And it was you guys entering that patch management space that put you on my radar when I saw the report you released earlier this year called the State of Patch Management. So based on the findings in there, you guys advised that speed should not be the only goal when it comes to patching vulnerabilities. So tell me more about that and why that is so. So that's not to say that speed isn't important.

[00:07:01] If we've learned anything this year, AI is introducing machine speed into the way that vulnerabilities are being found and being exposed. And so speed is really the number one thing that needs to be addressed. But you can't just rely on speed. I like to tell the story of imagine that you have a library cart and it's full of books and you need to get it from the upstairs level to the downstairs level.

[00:07:30] You could argue that the fastest way to get that cart of books down the stairs is to walk up to the edge of the stairs and push it down the stairs. And that's great. You will have succeeded in finding the absolute fastest way to get those books to the bottoms of the stairs, but you would have created quite a mess in doing so. And so what we preach is that control is also an important factor here.

[00:07:57] You need to be able to decide which patches are worth deploying in a rapid fashion, right? You need to have that decision. You need to have that methodology to decide that this patch is important enough that it needs to be deployed right away. But then it's also important to make sure that you're introducing pilot phases into your testing.

[00:08:20] You need to make sure that you have a feedback loop with your testers, with your pilot users to make sure that the patches that you're deploying, you're getting them out quickly. But you also need to collect that feedback and make sure that you're not causing damage. You're not causing friction to the business. You don't want to cause issues with business and revenue just because you're trying to ramrod patches out into your environment. Yeah, I completely agree.

[00:08:49] Let's look together at a very real-world problem that every organization would have had at some point. And that is a serious vulnerability is discovered. From that point, how should leaders decide whether to patch immediately, as they're told to do, or spend more time testing the update for any risks or knock-on effects it could create? And what factors should determine the acceptable level of risk on either side? It's always been a balancing act. It always has been.

[00:09:16] But how do you approach this now, and how would you recommend others approach this? So criticality is important when it comes to patching activities. Obviously, the highly critical patches need to be deployed with speed. We need to use that pilot phase, though, to make sure that we're not breaking anything as we deploy these.

[00:09:40] Your organization needs to decide what is an acceptable amount of time for burn-in when you're deploying these patches. And this doesn't just go for your criticals. This also goes for highs and mediums. And there's a lot of exposures that are related to medium patches just as much as they are critical patches.

[00:09:57] And I think it's important for you to make sure that you have a patching methodology that addresses that burn-in time and exposing those patches to your pilot users before you push them onto your production environment. Maybe the determining factor there is how long that burn-in period is. For critical patches, maybe that's a day or two days. For highs and mediums, maybe that's a little bit longer.

[00:10:27] But I think you need to have that methodology in mind, that philosophy of how are we going to address this? We need to have those rules in place that says, this patch is going to go through this process. This other patch is going to go through this other process. Because it doesn't carry as high a risk, but it's still important. We need to get it into the system. We need to start the wheels turning so that we have a shorter mean time to patch for your entire environment.

[00:10:55] Yeah, 100% with you. And elsewhere in cybersecurity teams, across both sides of the pond here, organizations now have more security dashboards, alerts, vulnerability data, and endpoint visibility than they ever have before. But rather than being better informed, very often there can be fine rocking back and forth, talking about alert fatigue. No, not another dashboard is the kind of things people say now.

[00:11:24] So why doesn't greater visibility automatically translate into lower business risk like you think it would? And what should leaders be doing differently with all this information, do you think? Visibility is great, but you still have to be able to do something with that. And that's where my background is IT operations and engineering. Your InfoSec community still needs to embrace the IT capabilities to be able to do something about that.

[00:11:54] You still have to get those patches deployed. You still have to affect your end users. You still have to do the work. Having the knowledge is one thing, but doing the work is probably 90% of the effort on this.

[00:12:09] And again, not to overpreach what we're doing, but with OneSitePatch, I think that's where we come in and we kind of bridge together the IS and the IT communities to allow us to bridge together where we're detecting, we're getting the information about the vulnerabilities. We know what's out there, but then we're also using that information to do something about it.

[00:12:32] We're trying to make that transition from IS to IT a little easier so that we can get some action taken off of all of that information that you're consuming. And you mentioned AI a few moments ago and any tech podcast, it has to be mentioned at least once and possibly many more. But seriously though, AI and automation are things that can dramatically reduce the time between identifying a vulnerability and indeed remediating it.

[00:12:59] But where should organizations draw the line between autonomous action and that human approval when a mistake could affect thousands of devices? How do you approach this? A great many of our customers, when we engage with them, their existing processes are always just rife with approvals. And I think historically, we're used to that. We like having that control.

[00:13:24] We like having, and that was like our best way to control was the approval, right? And maybe you have layers of approvals. We're going to have this group over here approve and we're going to have business approve and we're going to have possibly the CTO approve it. And you go through all these layers of approvals, but all you're really doing is you're introducing friction to the entire process. What I would say is let's replace the approvals with just being notified.

[00:13:52] Because are you actually looking at this list of patches that need to be deployed and deciding that we're not going to do this one or this one? They're still important. Are you going to decide to not deploy critical patches? Instead, replace that with a notification. And then I keep going back to the importance of your pilot. Communicate with your pilot users and use that experience to validate your patches. You can always remove them.

[00:14:20] If you have good controls in your patching environment, if something doesn't go well in your pilot, you can always get rid of it and not release that to your production population. But all you're really doing is you're slowing things down with the approvals. I just spent a week in Panama City Beach recently. And when I'm out of the office, because I'm a technologist at heart and I have several labs that I have running and their labs are running our product.

[00:14:50] While I'm in Panama City Beach, I'm not looking at my labs. I'm not looking at my environment. But I don't have approvals with my patching strategies. So I was continuing to deploy patches to my endpoints even while I'm sitting on the beach and taking in the sun and the waves. So why would you want to have that thing that sits out there and waits for you?

[00:15:16] Why do you want anything to be sitting and waiting on you in order to start taking remediation actions in your environment? Yeah, completely agree. And if we look across every large enterprise out there, I'm curious, who do you think should ultimately be accountable for the decision to deploy a high risk security update? Is it the CISO? Is it IT operations, application owners, business leaders, or a combination of all of them?

[00:15:43] And how do you prevent maybe unclear ownership from slowing down the response and falling into that analysis paralysis trap? Who should be owning this stuff here? Yeah, I think it's truly a group effort. Because, I mean, the CISO is ultimately going to answer, right? Right. He's going to go in the boardroom and he has to talk to the risk and the exposures and all that. And ultimately, he needs to set the policies that are going to be followed.

[00:16:11] But then it's up to the InfoSec team and your IT teams to actually carry these things out. And that's where we see. And if you look in our state of patch management report, and then there's several other reports that are validating this as well. There's a Gartner report on accelerating endpoint patching. There's the Verizon Data Breach Investigations Report. There's the IBM Cost of Data Breach Report that just came out this week.

[00:16:36] And they're all saying the same thing, is that organizations are not moving fast enough. There's too many people involved in the entire end-to-end process. You've got your CISO that's setting your policies. You have your InfoSec team that's trying to decide what to patch. You have your IT teams that are trying to get these patches deployed. And you have all of these opportunities to slow down the process.

[00:17:03] And when those groups can all work together and possibly even use one tool to do that, you can really start to create some efficiencies. You can start to bring your time to patch down from weeks to days. If you can create some better efficiencies in that entire process. And we started our conversation today talking about that state of patch management report. And the weeks and months that are following, it's been validated and echoed by so many different bodies too.

[00:17:33] And it's easy to see why. Because if we look back over the last 18 months, there has been so many high-profile examples of software and configuration changes causing widespread operational disruption. I've seen it here in the UK and everything from banking, where people cannot get hold of their money, their wages, etc. And equally, the supermarket as well. And even a few fast food restaurants out there that I've seen it happen to too.

[00:17:58] So what practical safeguards, such as stage deployments, testing, rollback capabilities, and real-time monitoring, what should every organisation have in place before that next urgent incident inevitably arrives? Well, the time to act is now. You need to get an autonomous solution for your patching in place.

[00:18:21] You cannot wait for human decisions in order to realise a more highly secure environment. And that's done through autonomy. All of these reports, the reports I mentioned earlier, our own state of patch management report, they all speak to we need to get to a more machine speed type patching environment.

[00:18:47] We need to get to a solution that sees that these patches are available and starts the process for you. You cannot continue to wait for that process to start. You have to have something that starts the process for you. And then go through the steps. Go through your pilot phase. Get your feedback loop going. Get your user communications going. But all of that needs to be done automatically and autonomously. We cannot continue to wait for the speed of a human to keep up with the threats

[00:19:17] that are being introduced by machine speed AI. And I'd love to have a bit of fun with you now. On a personal note, we're talking to you quite early on a Friday morning. And I think we're all bombarded with so much information now. And you, I, and everyone listening around the world will have a slightly different way of starting their day. Some will reach for their phone and tackle their emails straight away. Some will just ease in gently by having a little doom scroll down their social feeds. Others will look at news.

[00:19:46] Others will have AI agents delivering the latest trends and industry news to help them with continuous learning and keeping up to speed with the pace of technological change. As I'm speaking to you early today, I've got to ask, what is your early morning routine? How do you start your day? You would like me to tell you that I listen to your podcast every morning, wouldn't you? I was teeing you up for that. No.

[00:20:11] So, so every, I have this routine every morning, uh, I wake up and I, and I start my coffee brewing and, and I always play a game of risk. And, and yes, that, that game of risk that, that you used to play as a teenager in your basement with your friends. I, I play a game of that online and I feel like the, the strategy and the real time decisions get my brain going faster than, even better than, than the coffee gets me going.

[00:20:38] Um, and, and honestly, I think playing a game of risk is the perfect way to set me up for a day of, of addressing risk with our customers. So that's, that's how I start my days. I absolutely love that. What a unique answer. There was so many different ways you could have gone with that, but I absolutely love it. I'd even know that classic game was available online. So I'll be checking that out. And for everyone listening, they want to check out the, uh, report we referenced today, find out more information about you, the work, et cetera.

[00:21:07] Where would you like me to point everyone? So let's get everybody to go to adaptiva.com. Uh, there you can check out our 2026 data patch management report. Um, I would also encourage you to check out, uh, well, we also can link you to the Gartner report. So the, the Gartner roadmap for accelerating in-point patching. Uh, I, we recommend you check that out. Uh, go and look at the Verizon 2026 data breach investigations report.

[00:21:34] And then, like I said, just this week, uh, IBM released the cost of data breach report 2026. I'm, I'm sure, uh, we can get those links to you and you can put them, uh, put them on your website. Let everybody out, go out and, and read the information for themselves. Well, I think every organization is currently trying to navigate that tension between speed control, governance, and business continuity.

[00:21:59] And when cyber risk is moving so much faster than this traditional decision-making processes, everybody needs to be on their game here. So I would urge everyone listening to go to techtalksnetwork.com. If you go to the podcast, you'll find a blog post associated with this episode with all the links of everything that you mentioned. And let's keep this conversation going. But, uh, thank you so much for joining me today. Really appreciate your time. Pleasure to be here. Thank you.

[00:22:26] I think there's a wonderfully simple lesson from listening to David today. And that is visibility will tell you there's a problem. Someone or increasingly something has to fix it. And security teams have more vulnerability data alerts, dashboards, than ever before. But knowing a patch is required, that doesn't protect the business on its own.

[00:22:48] The hard part is getting from detection to remediation quickly without creating operational chaos along the way. And David made a compelling case today for replacing layers of manual approvals with automation, notifications, representative pilot groups, feedback loops, and rollback controls. And that could help organizations move closer to machine speed patching.

[00:23:13] But most importantly, while retaining the safeguards needed when thousands of endpoints are involved. And I have to give David credit for possibly the most appropriate morning routine I have ever heard in 4,000 interviews. He starts by playing risk while his coffee brews before spending the rest of his day helping customers address risk. Beautiful. Beautiful. So thank you to David for joining me today. And thank you for listening.

[00:23:44] And please, let me know your morning routines. You've got a big one to beat there. I'd love to hear from you. TechTalksNetwork.com. But I'll be back again real soon. Speak with you then. Bye for now. Bye for now.