Jump to content

Recommended Posts

Posted

Reading the latest DFE guidelines says:

IT support must complete security updates (known as patching) to operating systems, applications and firmware, including configuration changes, within 14 days of the release of the patch where the vulnerability is.

 

Some searching found many bits of old software floating around, some with many CVE's and all that we don't have any reporting on. So we are looking at updating/patching/reporting beyond WSUS/WUFB. We had a demo from Action1 , patch management software that looks great, it has a few other hardware audit and power mgmt features, but for our 500 workstations it's £4.5K, quite a bit for what it does.

 

Has anyone persuaded their schools to purchase Action1 or have any recommendations for alternate solutions?

 

Thanks

Posted
can Lansweeper actually push out updates or is it purely for identifying them and then IT would deploy with the usual tools, WSUS etc?
Posted

I did mention this - that 14 days was very tight for a school to a) find out b) download c) test on a pc d) test on 60 pcs e) roll out to all other pcs, and do do this eith each and every patch day in day out given the level of staffing and comeplete lack of expensive auto patch software that schools usually end up with.

 

Clearly fell on deaf ears.

Posted
can Lansweeper actually push out updates or is it purely for identifying them and then IT would deploy with the usual tools, WSUS etc?

 

Purely identify

 

- - - Updated - - -

 

I did mention this - that 14 days was very tight for a school to a) find out b) download c) test on a pc d) test on 60 pcs e) roll out to all other pcs, and do do this eith each and every patch day in day out given the level of staffing and comeplete lack of expensive auto patch software that schools usually end up with.

 

Clearly fell on deaf ears.

 

we patch anything urgent within 14 days. Everything else can wait until half terms.

Posted

Ah Cyber Essentials requirement there. You need a vulnerability scanner in place. Or subscribe to alerts from Adobe/Microsoft and be on top of patching. Easier with Patch My PC.

 

Possible Vulnerability Scanners are Nessus, Qualsys etc. Zoho/ManageEngine which may be cheaper.

Defender (depending on licensing) can detect vulnerabilities.

Posted
I did mention this - that 14 days was very tight for a school to a) find out b) download c) test on a pc d) test on 60 pcs e) roll out to all other pcs, and do do this eith each and every patch day in day out given the level of staffing and comeplete lack of expensive auto patch software that schools usually end up with.

 

Clearly fell on deaf ears.

 

Not mine.

 

I never patch that quickly except in exceptional circumstances.

 

So, I have tested and nearly finnished rolling out the August Updates in that I'm just waiting for the stragglers to tricke through.

 

I'm not a Microsoft Beta tester, so am happy to let other find and fix the problems first.

 

I will start testing the September updates on 1st October or thereabouts. I am a bit more reckless with Edge updates, and release them one they have been stable for 3 days!

 

I still use WSUS but use a Powershell script that sorts out most client/server sync problems. I will be looking at WSUS alternatives though. I'm not wedded to it exactly.

Posted
Not mine.

 

I never patch that quickly except in exceptional circumstances.

 

So, I have tested and nearly finnished rolling out the August Updates in that I'm just waiting for the stragglers to tricke through.

 

I'm not a Microsoft Beta tester, so am happy to let other find and fix the problems first.

 

I will start testing the September updates on 1st October or thereabouts. I am a bit more reckless with Edge updates, and release them one they have been stable for 3 days!

 

I still use WSUS but use a Powershell script that sorts out most client/server sync problems. I will be looking at WSUS alternatives though. I'm not wedded to it exactly.

I used to take that approach, but now I just patch all the things.

 

There's a risk to my approach, but I think the balance has moved so that the risk from being successfully attacked outweighs the risk of deploying a patch that breaks something.

 

We also have a policy supported by management that we're working towards Cyber Essentials which requires patches within 14 days. I won't get sacked for following that policy.

 

We do have machines that are in a group exempt from that, but we monitor those. The owners know that it's their responsibility to find a time to install patches otherwise we come knocking and will remove network access if patches aren't installed.

Posted
I used to take that approach, but now I just patch all the things.

 

There's a risk to my approach, but I think the balance has moved so that the risk from being successfully attacked outweighs the risk of deploying a patch that breaks something.

 

We also have a policy supported by management that we're working towards Cyber Essentials which requires patches within 14 days. I won't get sacked for following that policy.

 

We do have machines that are in a group exempt from that, but we monitor those. The owners know that it's their responsibility to find a time to install patches otherwise we come knocking and will remove network access if patches aren't installed.

 

I'd probably take the same line if I had management buy-in.

Posted (edited)

You need a proper vulnerability manager. Rapid7, Crowdstrike,tenable for example. It will look at everything you have and tell you what needs fixing. Operating system, applications, bios, printers, switches etc.

 

LanSweeper and other tools will show some data. But will massively fall short.

 

There is no point doing it unless you do it properly.

Edited by FN-GM
  • Thanks 1
Posted (edited)

Awww the good old DofE guidance written by people in cosy offices using the blue sky method not realising the struggles and costs of IT within schools.

 

So they want us actively patching server clusters within 14 days during school term with zero time for rectification should something go wrong, definitely a smart decision that [emoji849]

 

Gave up reading that tripe ages ago and work to common sense best practice trends as best we can within reasonable timeframes.

Edited by Tefters
  • Thanks 3
Posted

We have had a change freeze during the public exam period for anything other than priority remedial work for many years now for anything that can’t be completely isolated.

 

This is a really interesting thread that has rather unsettled some of my previous opinions, although unless there is a change in the allocation of funding to rural state schools, any solution that is a cost option with on costs would be a non starter for us for the time being.

Posted
You need a proper vulnerability manager. Rapid7, Crowdstrike,tenable for example.

 

I recently had a quote including Crowdstrike and it was over half of my annual budget (that was with a huge edu discount too). No doubt it's where we should be but the cost is prohibitive so we do the best with the tools we can afford.

  • Thanks 1
Posted

 

There is no point doing it unless you do it properly.

 

That's my point though - we are trying our best. The defenition of "doing properly" it is simply unrealistic for many schools to meet.

 

And jeees - we're ahead of a lot of companies I see - even the LA who are still picking out odd windows 2003 servers in random cuboards across the borough.

  • Thanks 3
Posted

While Action1 sounds like a solid solution, I completely understand the budgetary constraints you're facing, especially in schools where every penny counts. In our case, we found that Patch My PC strikes a good balance between cost and functionality. It's quite cost-effective compared to some of the higher-end solutions like Action1 or Rapid7, but still covers patch management and some basic vulnerability detection.

Additionally, if you’re looking for something more robust but still mindful of cost, tools like ManageEngine and Zoho can offer patching along with other features such as inventory management and reporting. We've also had good success combining WSUS with some well-placed PowerShell scripts, which helps in syncing and patch deployment without relying on expensive third-party tools.

Ultimately, it’s all about finding the balance between compliance (e.g., Cyber Essentials) and practicality, given the staffing and resources available.

  • Thanks 2
Posted
Not mine.

 

I never patch that quickly except in exceptional circumstances.

 

So, I have tested and nearly finnished rolling out the August Updates in that I'm just waiting for the stragglers to tricke through.

 

I'm not a Microsoft Beta tester, so am happy to let other find and fix the problems first.

 

I will start testing the September updates on 1st October or thereabouts. I am a bit more reckless with Edge updates, and release them one they have been stable for 3 days!

 

I still use WSUS but use a Powershell script that sorts out most client/server sync problems. I will be looking at WSUS alternatives though. I'm not wedded to it exactly.

 

Out of interest, what do you actually do when testing Windows updates each month? Are you just testing whether stuff boots, or are you going deeper than that?

 

I just let our servers and workstations install their updates automatically, since I can't imagine me being able to recreate or identify all potential issues ahead of time. They have either 3 or 7 days deferral set, with a 3 day deadline to complete on top of that and 2 days grace for restarts thereafter (servers doing their restarts automatically overnight). In reality that means most things aren't running the latest patch until at least a week after patch Tuesday (patches generally getting picked up in the UK on Weds morning due to time difference with the US, the 3 day deferral taking us to the weekend, and then usage patterns, installation time and restarting needing a few days of the following week).

 

IIRC one of the Server 2022 monthlies was pulled and delayed for a week or so earlier this year, but it was pulled before the 3-day deferral had elapsed. For workstations, a patch would basically need to have been released for the best part of a week before they begin installing, which seems like it gives MS a reasonable chance to pull anything problematic.

Posted
[emoji[emoji6[emoji640][emoji638]][emoji640][emoji6[emoji640][emoji638]]][emoji6[emoji640][emoji637]][emoji[emoji6[emoji640][emoji638]][emoji640][emoji6[emoji640][emoji638]]][emoji637][emoji[emoji6[emoji640][emoji638]][emoji640][emoji640]][emoji637]]

So they want us actively patching server clusters within [emoji637][emoji640] days during school term with zero time for rectification should something go wrong, definitely a smart decision that [emoji[emoji[emoji6[emoji640][emoji638]][emoji640][emoji640]][emoji640][emoji[emoji6[emoji640][emoji638]][emoji640][emoji6[emoji640][emoji637]]]]

 

 

 

If you’re clustered surely you can do it during the day without any downtime?

Posted (edited)
Out of interest, what do you actually do when testing Windows updates each month? Are you just testing whether stuff boots, or are you going deeper than that?

 

IIRC one of the Server 2022 monthlies was pulled and delayed for a week or so earlier this year, but it was pulled before the 3-day deferral had elapsed. For workstations, a patch would basically need to have been released for the best part of a week before they begin installing, which seems like it gives MS a reasonable chance to pull anything problematic.

 

Firstly, I check any reports of updates causing problems, or unintended consequences along the lines of "I updated A and now B doesn't work".

 

Then I roll out things with no reported problems with anything apparently relevant to us and won't need a reboot to my test group - users that will exercise the software, but who wouldn't be phased if we had to swap their device out at short notice in the event of a problem.

 

I work through a group of devices that would cause the least incovenience if they were affected but are used a lot. No point in testing on devices that are not used much.

 

Then one laptop trolley, and staff laptops.

 

Then everything else that needs to be high availability.

 

Whiile that is going on, I'll start on the updates I might have concern about - normally because others might have experienced printing issues, and specifically test the things that others have complained about. Same order.

 

Ususally the Win 10 (LTSC) cumulative updates last, but they may be first depending on what's in them.

 

I do try to put the updates through singly to the oldest or slowest devices to misimise any percieved disruption.

 

I currently don't have any updates outstanding that I've avoided as they have all been superceeded. It does happen sometimes though.

 

Before I joined the school, there was no WSUS setup and nobody did updates for anything ever!

 

I know what I do is a home made roll your own of dubious quality, and I would like to get it properly formalised and more automated.

 

MS don't always pull problematic updates.

Edited by sigma
  • Thanks 1
Posted

Interesting discussion. For some of us Cyber Essentials is a funding requirement. 95% of software gets patch within 14 days which is do able. where I am.

 

Nessus does miss vulnerabilities or has false positives.

 

The areas where updates don’t happen are where there is a mission critical application with dependencies where a lot of testing is required.

 

It seems to come back to lack of a decent budget in Schools and maybe FE.

 

Which affects the whole sector with the amount of networking that takes place.

  • Thanks 1
Posted (edited)
If you’re clustered surely you can do it during the day without any downtime?
Correct I can, on paper it should work flawlessly, is it worth the risk for when something goes wrong and I lose a host or have to reboot both due to a patch failure or bug and therefore have 100% downtime, NO.

 

I speak from experience, don't patch critical resources during key working hours.

 

School doesn't pay me for out of hours work therefore non key working hours when I am paid is half-term.

 

I refer back to my previous common sense statement and the Moto "just because you can doesn't mean you should".

 

Even in zero point of failure setups by ISP's and other companies an update has wiped out a router which in turn caused HA not to activate therefore the zero point of failure was useless because it relied on software which was corrupt or failed for XYZ reason causing mega issues.

Edited by Tefters
Posted
We're currently trialling PDQ Connect which has just added vulnerability patching and reporting in BETA (we're testing it with them) - and very good it is too.

 

Have also got PDQ Connect, love it. Although only using it for app deployment, device management and the Remote Desktop tool. We use PatchMyPC for patching.

  • Thanks 1
Posted
While Action1 sounds like a solid solution, I completely understand the budgetary constraints you're facing, especially in schools where every penny counts. In our case, we found that Patch My PC strikes a good balance between cost and functionality. It's quite cost-effective compared to some of the higher-end solutions like Action1 or Rapid7, but still covers patch management and some basic vulnerability detection.

 

 

I got a quote for Manage Engine and their Update/Vulnerability solution was £9000\year....

 

So, looking at Patch my PC, their site says you can deploy 3rd party software through WSUS which I guess is good, but more importantly will it:

  • Replace WSUS
  • Find and recommendation remediation on vulnerabilities in all our software, drivers etc?

Thanks for the info before I go for demos etc.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...