Apple's reported plans to move towards a faster iOS update cycle have sparked plenty of discussion across the cyber security industry. While the change could mean more frequent updates for IT teams to manage, it also highlights a much bigger issue facing organisations today: the speed at which vulnerabilities can be exploited is increasing.
Acumen’s Principal Consultant, Nathan Davies-Webb, recently shared his thoughts with IT Pro, explaining why patch management can no longer be treated as a monthly task.
Traditionally, organisations have balanced the need to patch against concerns about stability and operational disruption. That caution made sense when updates were less frequent, and attackers often took longer to weaponise newly disclosed vulnerabilities. Today, that window is shrinking.
As Nathan explains:
"From a risk perspective, I'd much rather see organisations patch quickly and in a controlled way than wait for monthly cycles and leave vulnerabilities sitting there to be exploited."
Apple's ecosystem is one of the most widely used in the world, making it an obvious target for security researchers and attackers alike. While the company has long invested heavily in security, including features such as Lockdown Mode for users at highest risk, no platform is immune from vulnerabilities.
For security teams, the fundamentals remain the same. Every update should be reviewed, the potential business impact assessed and an appropriate response agreed. In many cases, that response will be to deploy the patch as quickly as possible. Where that isn't practical, organisations should be prepared to introduce compensating controls that reduce risk until patching can take place.
The wider lesson extends beyond iOS.
Modern IT environments should be designed to support rapid patching without disrupting critical services. Building resilience through redundancy, testing failover capabilities and understanding which systems can be taken offline safely all play an important role in reducing cyber risk.
Nathan also believes organisations need to rethink their approach to automation.
"There was a time when concerns around stability and functionality made organisations cautious about patching too quickly, and there will always be exceptions for critical systems. But for most environments, the risk now sits firmly on the other side of the equation. AI is accelerating how quickly vulnerabilities are discovered and weaponised, which means organisations need to be reducing exposure as quickly as they can."
As attackers continue to move faster, organisations need to do the same. Effective patch management is no longer just about keeping systems up to date. It's about reducing the amount of time attackers have to exploit known weaknesses.
You can read the full IT Pro article here.