Vulnerability
OT Patch Management
Apply vendor-validated updates safely within operational and safety constraints.
Defensive guide
Why should I care?
Patching in OT is a planned engineering activity, not a routine push.
How to implement it
- Track vendor advisories per product family
- Test in a lab or on a non-production system first
- Schedule into maintenance windows with rollback planned
- Where patching is not possible, document compensating controls and accept the risk formally
What good looks like
- A defined cadence with engineering ownership
- Documented deviations with compensating controls
Common failure modes
- Automatic patching of control systems
- 'We never patch' with no compensating analysis
How to verify it
- Sample systems against their intended patch baseline