The Challenges of Patching
Patching is a challenge, but vitally important.
Sometimes I forget that my dad knows a hell of a lot about financial IT. The man is pushing seven decades on this planet, with about four of those decades spent building data centers for various insurance firms and, finally, Avon. (Yes, my Bronx-born-and-raised, Marine father finished his working career at the global beauty products behemoth...and he actually really enjoyed working there, ironically enough.)
Anyway, in passing I mentioned that I'm working on a story looking at running patches after a new vulnerability is discovered or a software upgrade is necessary. Sure enough, he knew the subject well and regaled me with some tales.
After talking with my old man, and several industry CIOs/CTOs, here are a few broad takeaways that I'll look to delve into more deeply in the April issue of Waters:
1. As an IT specialist, you'll receive absolutely no praise or rewards for keeping the firm safe from cyber attacks by keeping up-to-date on patch releases. These patches take a fair amount of manpower ─ usually on weekends or late at night ─ and if you do your job well, no one outside of IT will have known that you've done your job well.
But, if something gets screwed up, or, in the worst-case scenario, a hacker sneaks in and takes information out, heads will roll.
2. There isn't a great science behind patching; it's more about logistics, operational cohesion, and diligent back testing. The key is to make sure that by running a patch on one system, you don't inadvertently throw off another linked system.
3. As with anything in security, you're in a perpetual up-hill battle when trying to defend against vulnerabilities. So many things at a financial institution are interconnected that in many ways, you're working on a hope and a prayer.
4. Patching is time consuming. The weekend is valuable time in IT, and the more time that is dedicating to patching and then testing, takes away from building and testing for more business-oriented projects. Again, it's not fun, you don't get any credit for it, and it can serve as a time-suck. But in today's day and age, it is absolutely, positively critical.
As I said before, I'll be writing more in-depth about this for the April issue, which will be dedicated to cyber security. The magazine will profile a prominent chief information security officer (CISO), and it will have a round-table of CISOs discussing how this position has taken on importance on Wall Street in recent years, and what makes for a good CISO. (Hint: There's no one right background...everyone seems to have their own theories.)
The issue will also take a look at security vendors in the space and layout all the major hacks from the last 10-20 years, and what firms learned from these breaches.
As for my patching story, if you have any insight, I'd love to hear from you. You can reach me at anthony.malakian@incisivemedia.com or give me a call at 646-490-3973.
The Sunny Shores of Florida...Oh, and FIA Boca 2015
Tomorrow I'll be flying down to Florida for this year's FIA Boca (Raton) conference. My slate is fairly-well filled up with meetings, but please don't hesitate to pull me aside for a quick chat if you see me ─ I'm the guy with the shaved head and bushy beard...I kinda stand out.
Only users who have a paid subscription or are part of a corporate subscription are able to print or copy content.
To access these options, along with all other subscription benefits, please contact info@waterstechnology.com or view our subscription options here: http://subscriptions.waterstechnology.com/subscribe
You are currently unable to print this content. Please contact info@waterstechnology.com to find out more.
You are currently unable to copy this content. Please contact info@waterstechnology.com to find out more.
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. Printing this content is for the sole use of the Authorised User (named subscriber), as outlined in our terms and conditions - https://www.infopro-insight.com/terms-conditions/insight-subscriptions/
If you would like to purchase additional rights please email info@waterstechnology.com
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. Copying this content is for the sole use of the Authorised User (named subscriber), as outlined in our terms and conditions - https://www.infopro-insight.com/terms-conditions/insight-subscriptions/
If you would like to purchase additional rights please email info@waterstechnology.com
More on Emerging Technologies
S&P debuts Spark Assist genAI copilot, draws up ‘Blueprints’ of combined datasets
S&P’s Kensho subsidiary has rolled out new emerging tech products leveraging AI to explore and combine the vendor’s wealth of datasets to solve common use cases.
Nasdaq reshuffles tech divisions post-Adenza
Adenza is now fully integrated into the exchange operator’s ecosystem, bringing opportunities for new business and a fresh perspective on how fintech fits into its strategy.
Liquidnet sees electronic future for gray bond trading
TP Icap’s gray market bond trading unit has more than doubled transactions in the first quarter of 2024.
Verafin launches genAI copilot for fincrime investigators
Features include document summarization and improved research tools.
Waters Wrap: Open source and storm clouds on the horizon
Regulators and politicians in America and Europe are increasingly concerned about AI—and, by extension, open-source development. Anthony says there are real reasons for concern.
Waters Wavelength Podcast: Broadridge’s Joseph Lo on GPTs
Joseph Lo, head of enterprise platforms at Broadridge, joins the podcast to discuss AI tools.
Man Group CTO eyes ‘significant impact’ for genAI across the fund
Man Group’s Gary Collier discussed the potential merits of and use cases for generative AI across the business at an event in London hosted by Bloomberg.
BNY Mellon deploys Nvidia DGX SuperPOD, identifies hundreds of AI use cases
BNY Mellon says it is the first bank to deploy Nvidia’s AI datacenter infrastructure, as it joins an increasing number of Wall Street firms that are embracing AI technologies.
Most read
- Chris Edmonds takes the reins at ICE Fixed Income and Data Services
- Deutsche Börse democratizes data with Marketplace offering
- Waters Wavelength Podcast: Broadridge’s Joseph Lo on GPTs