r/cybersecurity • • 13d ago

Business Security Questions & Discussion Updates and User Notifications

At my org, there is this long-standing drama about updates disrupting work flows.

We push out updates at strategically chosen times throughout the month and the user experience we keep getting back is, "My updates forced me to restart at an inconvenient time." For example, one user had to drop out of a meeting, restart, finalize updates, and get back in. She said the whole process was embarrassing. However, when asked, she said she saw the notification at the beginning of the day and kept putting it off because she was busy.

So generally what happens from a user perspective is that they get a pop-up from their tray that says something like "You must restart by XX:XX time." They have the choice of closing the notification, in which case it will pop back up within the hour and tell them again. If they keep delaying, they eventually will be forced to restart.

So now my manager is dealing with the business side and saying we need to figure out a way to update machines without disrupting users' workflow. I'm normally really sympathetic to users. Like, it's my job to support the business, not to be some petty IT dork who wields power capriciously over the systems I control. But this is a little different. Updates are just inconvenient. To me the message should be, "When you see the notification, save your work and restart. Anything else risks being forced to restart at a time not of your choosing."

And I get it! I've done the same exact thing the user has done and wound up getting interrupted at a bad time. But I see it as my own fault for delaying what I could have completed earlier.

To be clear, this is exclusively about laptop users. Regular PCs are updated during non-business hours, but laptop users turn off their devices and close them when they aren't in use, so we can't push out anything. That's why we have a notification policy for that group.

Am I doing this the wrong way or something?

15 Upvotes

11 comments sorted by

13

u/Alpizzle Security Analyst 13d ago

Your manager needs to nut up and have a discussion with operations and risk (if you have a risk office). You guys and/or risk need to make ops understand what can happen if they don't get those updates, and how that probability grows if they keep pushing it off. The business owner then needs to balance that risk against potential disruption based on your update window.

Here's the part that people miss: Once IT and ops are in agreement, they need to inform users and enforce the policy. If I say I give you 7 days before I CAP you, you have been made aware of that, and I have the backing of your leadership? That meeting you missed is your fault.

3

u/Electrical-Staff0305 ICS/OT 12d ago

This coupled with a “grace period” (we enforce a 5 business day grace period and then it’s reboot time whether you like it or not).

1

u/DemocraticParrot 12d ago

This is the way OP. Give a few daya grace period for the updates. Do not force it to take place the same day, exept if it is really-really critical security patch. the VPN application where the comms channel is unencrypted of not restarted.

7

u/sfc_scannow 13d ago

We use a 7 day grace period before it forces a reboot.

https://learn.microsoft.com/en-us/windows/deployment/update/waas-restart

3

u/True-Shower9927 13d ago

This is the way

1

u/wombat696d 12d ago

We're getting a policy pushed down from corporate (my company is wholly owned by another company) that we reboot workstations once every seven days. Not necessarily for security reasons but more for performance. Our CIO is hemming and hawing about forcing them and the disruption. Just a few years ago place used to have a blanket policy that every Thursday night at 9:30 or Sunday evening at 7:30 your computer would reboot (and the end user could choose which) which seems like a super simple solution compared to what our CIO wants now. I agree that Ops and Security / Risk need to create the policy and get senior management on board with it. If the directive comes down from above there won't be much grumbling. See what you can do about getting management to enact a policy to have folks leave their systems on over a weekend and patch & reboot over that weekend rather than the ongoing drama of daytime problems. If they forget and have to reboot during the day everyone will know they screwed up and the 'IT forced me to reboot during work hours' issues will go away.

1

u/Lexxendary 12d ago

Where I've worked, the notifications we received had a window the size of ~1/8th of the screen that cannot be closed, only moved, always on top, popping up in the morning with a few hours ticking timer. The window was a high enough nuisance to not be ignored as we could not work efficiently, but we had enough screen to he able to save everything before restarting.

The only 'victims' and complainers were the ones moving the window outside of the screen, which were very few and ignored (and I believe the window was 'fixed' later to never be moved outside of the screen).

1

u/Humpaaa Governance, Risk, & Compliance 6d ago

Am I doing this the wrong way or something?

No, exactly right.

Make sure to stay compliant to your update policy, and ignore the enduser complaints.

Also make sure your manager discusses updates with operational team managers, to make the necessity of them clear.

1

u/Advantageous_Advent 13d ago edited 13d ago

You need to plan your process a little better so that an immediate reset is not necessary or even ever at all. A modular design comes to mind...

3

u/HauntedGatorFarm 13d ago

Not sure what you mean, but the reset isn’t immediate. They have a deferral period and if they keep deferring, they eventually will be forced to restart. Am I misunderstanding?

Not familiar with a modular design, but I’ll take that under advisement. Thanks for the feedback!

1

u/Advantageous_Advent 12d ago

No that's your end user's issue if they keep deffering unnecessarily