The Challenges of Patching
Patching is a challenge, but vitally important.
Sometimes I forget that my dad knows a hell of a lot about financial IT. The man is pushing seven decades on this planet, with about four of those decades spent building data centers for various insurance firms and, finally, Avon. (Yes, my Bronx-born-and-raised, Marine father finished his working career at the global beauty products behemoth...and he actually really enjoyed working there, ironically enough.)
Anyway, in passing I mentioned that I'm working on a story looking at running patches after a new vulnerability is discovered or a software upgrade is necessary. Sure enough, he knew the subject well and regaled me with some tales.
After talking with my old man, and several industry CIOs/CTOs, here are a few broad takeaways that I'll look to delve into more deeply in the April issue of Waters:
1. As an IT specialist, you'll receive absolutely no praise or rewards for keeping the firm safe from cyber attacks by keeping up-to-date on patch releases. These patches take a fair amount of manpower ─ usually on weekends or late at night ─ and if you do your job well, no one outside of IT will have known that you've done your job well.
But, if something gets screwed up, or, in the worst-case scenario, a hacker sneaks in and takes information out, heads will roll.
2. There isn't a great science behind patching; it's more about logistics, operational cohesion, and diligent back testing. The key is to make sure that by running a patch on one system, you don't inadvertently throw off another linked system.
3. As with anything in security, you're in a perpetual up-hill battle when trying to defend against vulnerabilities. So many things at a financial institution are interconnected that in many ways, you're working on a hope and a prayer.
4. Patching is time consuming. The weekend is valuable time in IT, and the more time that is dedicating to patching and then testing, takes away from building and testing for more business-oriented projects. Again, it's not fun, you don't get any credit for it, and it can serve as a time-suck. But in today's day and age, it is absolutely, positively critical.
As I said before, I'll be writing more in-depth about this for the April issue, which will be dedicated to cyber security. The magazine will profile a prominent chief information security officer (CISO), and it will have a round-table of CISOs discussing how this position has taken on importance on Wall Street in recent years, and what makes for a good CISO. (Hint: There's no one right background...everyone seems to have their own theories.)
The issue will also take a look at security vendors in the space and layout all the major hacks from the last 10-20 years, and what firms learned from these breaches.
As for my patching story, if you have any insight, I'd love to hear from you. You can reach me at anthony.malakian@incisivemedia.com or give me a call at 646-490-3973.
The Sunny Shores of Florida...Oh, and FIA Boca 2015
Tomorrow I'll be flying down to Florida for this year's FIA Boca (Raton) conference. My slate is fairly-well filled up with meetings, but please don't hesitate to pull me aside for a quick chat if you see me ─ I'm the guy with the shaved head and bushy beard...I kinda stand out.
Only users who have a paid subscription or are part of a corporate subscription are able to print or copy content.
To access these options, along with all other subscription benefits, please contact info@waterstechnology.com or view our subscription options here: https://subscriptions.waterstechnology.com/subscribe
You are currently unable to print this content. Please contact info@waterstechnology.com to find out more.
You are currently unable to copy this content. Please contact info@waterstechnology.com to find out more.
Copyright Infopro Digital Limited. All rights reserved.
As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (point 2.4), printing is limited to a single copy.
If you would like to purchase additional rights please email info@waterstechnology.com
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (clause 2.4), an Authorised User may only make one copy of the materials for their own personal use. You must also comply with the restrictions in clause 2.5.
If you would like to purchase additional rights please email info@waterstechnology.com
More on Emerging Technologies
TT acquires Trafix in 24/7 push, T+1 deadlines in the EU loom, and more
The Waters Cooler: A recap of the major tech and data news from the past week in the capital markets.
Buy-side firms warn semantic layers not a quick fix for AI integration
Semantic layers promise to teach AI what a firm’s data means. Keeping that meaning current is the part that may get overlooked, tech heads warn.
If everyone can be an expert in everything, is anyone an expert in anything?
The Waters Wrap: AI has promised to democratize knowledge and skillsets. Reb wonders whether that’s an entirely good thing.
Bloomberg launches CLO data solution, Alibaba Cloud expands, and more
The Waters Cooler: A recap of the major tech and data news from the past week in the capital markets.
GPU compute derivatives are put to the test
Interest rates and onions of the past haunt what could be a booming new index market.
The GPU compute index race begins
Major exchanges are partnering with a new crop of benchmark providers to create a tradable asset class around GPU compute.
Agents are invading. Will it stick?
The Waters Wrap: Agentic features are becoming commonplace in the workflow tools of capital markets. Nyela wonders if the trend is sustainable.
TS Imagine launches new agentic platform
TSIQ can act based on client queries, using built-in agent “personas” that can be modified by users on a case-by-case basis.