Cyber Security

IT department confirms they’ll get round to updating that critical security patch sometime before Christmas, probably

The IT department at Hargreaves Financial Solutions has reassured staff that the critical security vulnerability identified in their customer database system three months ago will be addressed before the end of the year, provided nothing comes up and assuming the fix doesn’t interfere with Karen’s Excel macros.

The patch, which addresses what the software vendor has described as a “catastrophically exploitable flaw” allowing unauthorised access to the entire network, has been sitting in the department’s ticketing system since July with a status of “under review”. It currently sits behind 247 other tasks, including investigating why the third floor printer makes a concerning noise on Tuesdays and updating Steve from Accounts’ desktop background, which he says has been stuck on the Windows XP hillside since 2019.

Graham Mitchell, Head of IT Infrastructure, confirmed that the update was definitely on the radar. “We’re very aware of the security implications,” he said, during a meeting scheduled to discuss the matter but which largely focused on whether the new coffee machine required its own VLAN. “The thing is, we need to run it past Operations first, then Finance, then test it in the staging environment, which has been down since June. We’re looking at a potential window in November. Second half of November.”

When pressed on reports that the vulnerability was already being actively exploited by hackers, Mitchell noted that the company had seen no evidence of a breach, apart from some unusual login activity from IP addresses in Belarus, though that could easily be Dave from Sales who mentioned he was going on holiday somewhere near there, or possibly Croatia.

The delay has been attributed to concerns that applying the patch might cause minor disruptions to business operations, such as requiring people to restart their computers or, in a worst-case scenario, spend up to four minutes logging back into various systems. Such an eventuality, Mitchell explained, would need to be carefully scheduled around the monthly sales call, the quarterly review, the weekly catch-up, and the period between 12pm and 2pm when people are generally at lunch or thinking about lunch.

Rebecca Winters, Chief Technology Officer, defended the department’s cautious approach. “Security is absolutely our top priority,” she said, speaking from a conference room where she was coordinating the urgent replacement of the CEO’s iPhone charger. “But we can’t just go around installing updates willy-nilly without considering the broader impact on business continuity. What if someone is in the middle of something important when we restart the servers. We have a responsibility to our users.”

The IT department has scheduled a meeting for late October to discuss scheduling another meeting to finalise a timeline for the update, unless that clashes with someone’s annual leave, in which case it will probably be pushed to January.

Leave a comment

Your email address will not be published. Required fields are marked *