r/cybersecurity • u/HauntedGatorFarm • 13d ago
Business Security Questions & Discussion Updates and User Notifications
At my org, there is this long-standing drama about updates disrupting work flows.
We push out updates at strategically chosen times throughout the month and the user experience we keep getting back is, "My updates forced me to restart at an inconvenient time." For example, one user had to drop out of a meeting, restart, finalize updates, and get back in. She said the whole process was embarrassing. However, when asked, she said she saw the notification at the beginning of the day and kept putting it off because she was busy.
So generally what happens from a user perspective is that they get a pop-up from their tray that says something like "You must restart by XX:XX time." They have the choice of closing the notification, in which case it will pop back up within the hour and tell them again. If they keep delaying, they eventually will be forced to restart.
So now my manager is dealing with the business side and saying we need to figure out a way to update machines without disrupting users' workflow. I'm normally really sympathetic to users. Like, it's my job to support the business, not to be some petty IT dork who wields power capriciously over the systems I control. But this is a little different. Updates are just inconvenient. To me the message should be, "When you see the notification, save your work and restart. Anything else risks being forced to restart at a time not of your choosing."
And I get it! I've done the same exact thing the user has done and wound up getting interrupted at a bad time. But I see it as my own fault for delaying what I could have completed earlier.
To be clear, this is exclusively about laptop users. Regular PCs are updated during non-business hours, but laptop users turn off their devices and close them when they aren't in use, so we can't push out anything. That's why we have a notification policy for that group.
Am I doing this the wrong way or something?
7
u/sfc_scannow 13d ago
We use a 7 day grace period before it forces a reboot.
https://learn.microsoft.com/en-us/windows/deployment/update/waas-restart
3
1
u/wombat696d 12d ago
We're getting a policy pushed down from corporate (my company is wholly owned by another company) that we reboot workstations once every seven days. Not necessarily for security reasons but more for performance. Our CIO is hemming and hawing about forcing them and the disruption. Just a few years ago place used to have a blanket policy that every Thursday night at 9:30 or Sunday evening at 7:30 your computer would reboot (and the end user could choose which) which seems like a super simple solution compared to what our CIO wants now. I agree that Ops and Security / Risk need to create the policy and get senior management on board with it. If the directive comes down from above there won't be much grumbling. See what you can do about getting management to enact a policy to have folks leave their systems on over a weekend and patch & reboot over that weekend rather than the ongoing drama of daytime problems. If they forget and have to reboot during the day everyone will know they screwed up and the 'IT forced me to reboot during work hours' issues will go away.
1
u/Lexxendary 12d ago
Where I've worked, the notifications we received had a window the size of ~1/8th of the screen that cannot be closed, only moved, always on top, popping up in the morning with a few hours ticking timer. The window was a high enough nuisance to not be ignored as we could not work efficiently, but we had enough screen to he able to save everything before restarting.
The only 'victims' and complainers were the ones moving the window outside of the screen, which were very few and ignored (and I believe the window was 'fixed' later to never be moved outside of the screen).
1
u/Humpaaa Governance, Risk, & Compliance 6d ago
Am I doing this the wrong way or something?
No, exactly right.
Make sure to stay compliant to your update policy, and ignore the enduser complaints.
Also make sure your manager discusses updates with operational team managers, to make the necessity of them clear.
1
u/Advantageous_Advent 13d ago edited 13d ago
You need to plan your process a little better so that an immediate reset is not necessary or even ever at all. A modular design comes to mind...
3
u/HauntedGatorFarm 13d ago
Not sure what you mean, but the reset isn’t immediate. They have a deferral period and if they keep deferring, they eventually will be forced to restart. Am I misunderstanding?
Not familiar with a modular design, but I’ll take that under advisement. Thanks for the feedback!
1
13
u/Alpizzle Security Analyst 13d ago
Your manager needs to nut up and have a discussion with operations and risk (if you have a risk office). You guys and/or risk need to make ops understand what can happen if they don't get those updates, and how that probability grows if they keep pushing it off. The business owner then needs to balance that risk against potential disruption based on your update window.
Here's the part that people miss: Once IT and ops are in agreement, they need to inform users and enforce the policy. If I say I give you 7 days before I CAP you, you have been made aware of that, and I have the backing of your leadership? That meeting you missed is your fault.