Skip to main content

Vulnerability

OT Patch Management

Apply vendor-validated updates safely within operational and safety constraints.

Defensive guide

Why should I care?

Patching in OT is a planned engineering activity, not a routine push.

How to implement it

  • Track vendor advisories per product family
  • Test in a lab or on a non-production system first
  • Schedule into maintenance windows with rollback planned
  • Where patching is not possible, document compensating controls and accept the risk formally

What good looks like

  • A defined cadence with engineering ownership
  • Documented deviations with compensating controls

Common failure modes

  • Automatic patching of control systems
  • 'We never patch' with no compensating analysis

How to verify it

  • Sample systems against their intended patch baseline