Patching Industrial Systems: A Risk-Based Approach to Uptime

Patching OT is not the same as patching laptops. Learn how to prioritize, test and schedule updates while protecting uptime, safety and vendor support.

3 min readBy Ironfield Cyber Team

In an office, applying security updates is mostly routine. Machines restart overnight, and a problem is an inconvenience. In an industrial environment, the same action can interrupt a process, void a vendor support agreement, or cause an unexpected change in how equipment behaves. That is why many OT environments run software that is years behind on updates, and why simply telling operations to "patch everything" does not work.

At the same time, ignoring updates leaves known weaknesses open. CISA regularly publishes advisories about vulnerabilities in industrial control products, and attackers can use them. A practical approach lies between the extremes: a risk-based program that decides what to patch, when, and what to do when patching is not possible.

Why OT patching is different

  • Availability comes first. Many processes run continuously, and downtime has operational and safety consequences.
  • Vendor certification. Control system vendors often test and approve specific patch levels. Applying an unapproved update may affect support.
  • Long lifecycles. Equipment may stay in service for decades, long after the vendor stops issuing updates.
  • Limited maintenance windows. Updates may only be possible during scheduled outages.
  • Testing constraints. Production systems are rarely duplicated for testing.

Step 1: Know what you have

Patching depends on an accurate inventory of devices, operating systems and software versions. Without it, you cannot tell which advisories matter. Start with the most critical systems and work outward.

Step 2: Monitor for relevant vulnerabilities

Subscribe to advisories from your equipment vendors and from CISA for industrial control systems. Assign someone to review them regularly and match them to your inventory. Many advisories will not apply to your configuration, and noting that is a legitimate result.

Step 3: Assess risk, not just severity scores

A vulnerability's published severity is a starting point. Adjust it based on your situation by asking:

  1. Is the affected system reachable from the internet or from less trusted networks?
  2. Does exploitation require network access, local access, or an authenticated user?
  3. What is the consequence if it were exploited, in safety, environmental and operational terms?
  4. Is there evidence the vulnerability is being used in attacks?
  5. What other controls, such as segmentation or access restrictions, already reduce exposure?

A moderate vulnerability on an internet-exposed system can deserve faster action than a severe one on a well-isolated device.

Step 4: Choose a response

Patching is one option among several.

  • Patch. Apply the update, ideally after vendor approval and testing.
  • Mitigate. Reduce exposure with firewall rules, disabling unused services, restricting access or segmenting the device.
  • Monitor. Increase monitoring for signs of exploitation while waiting for a window.
  • Accept the risk. For low-risk situations, document the decision and revisit it.
  • Replace. When equipment is unsupported and cannot be protected, plan for replacement.

Step 5: Test and schedule

  • Confirm vendor compatibility before applying updates.
  • Use a test system or spare hardware when possible.
  • Take a backup of configurations and programs first.
  • Plan updates for maintenance windows with operations present.
  • Prepare a rollback plan.
  • Record what was changed and when.

Step 6: Handle the IT side of OT

Windows servers, historian workstations and engineering laptops are common OT components, and they often can be patched on a defined schedule once vendor compatibility is confirmed. Distinguish between these and the controllers themselves.

Common mistakes

  • Applying office patching policies to control systems without coordination.
  • Never patching because "if it works, don't touch it."
  • Ignoring compensating controls when patches cannot be applied.
  • Failing to update the inventory afterward.

Build a sustainable rhythm

A simple cycle works for many organizations: monthly review of advisories, quarterly planning of updates for the next maintenance windows, and annual review of unsupported equipment for replacement budgeting.

How Ironfield Cyber can help

Ironfield Cyber works with operations teams to build practical patch and mitigation processes that respect uptime and safety. We can help match advisories to your inventory, prioritize actions and plan protective controls for equipment that cannot be updated.