Library
What to read before you book the window
Guides, definitions and checklists for the half nobody's tool covers — the coordination between the scan and the patch.
37 items
- ArticleAugust 6, 20264 min read
Measuring patch compliance without lying to yourself
Open vulnerability count is not a metric — it moves with what the scanner found, not with what you did. Four measures that survive contact with an auditor, and three that do not.
- ReleaseAugust 6, 2026
Permissions, SSO, alerting and an integrations registry
The release that makes the system fit a large organisation: levelled roles and permissions, OIDC single sign-on, an alert rule engine, and an integrations registry with encrypted secrets.
- ArticleAugust 4, 20264 min read
Two valid windows, one night, and a system that went down
The expensive failure in patch coordination is not a window that slips. It is two properly approved windows on systems that depend on each other — and how to catch it before the date is set.
- DatasheetAugust 3, 2026
Regulaxy — platform datasheet
One page: what the product does, what it explicitly does not do, what it integrates with, and what deploying it on an air-gapped network requires.
- GuideJuly 30, 20266 min read
Directive 364 readiness — a guide for infrastructure teams
Clauses 61.4, 97 and 98 mapped to operational practice: what each requires, which evidence it expects to see, and what an audit actually asks for.
- ReleaseJuly 30, 2026
Tables, export and dashboards
Every table moved onto one engine with filtering, multi-level sort and saved views; a styled Excel export landed beside CSV; and dashboards became user-built.
- ArticleJuly 28, 20262 min readHebrew only
הוראה 357 כבר לא בתוקף — מה בא במקומה
הוראת ניהול בנקאי תקין 364 מאחדת ומחליפה את 357, 361 ו‑363. אם המדיניות שלכם עדיין מפנה ל‑357, זה מה שצריך לעדכן ואיפה נמצאים הסעיפים המקבילים.
- ArticleJuly 21, 20264 min read
Reading Directive 364 §61.4 as an operations requirement
What the patch-management clause of Bank of Israel Directive 364 actually requires, which operational decisions it forces, and what has to be written down to have anything to show.
- TermJuly 15, 2026
Air gap
A network with no internet connectivity. Everything that enters passes through a controlled transfer, so anything that calls out simply will not work.
- TermJuly 15, 2026
Audit trail
A chronological record of the actions performed during a change, retained to support investigation and problem resolution during and after it.
- TermJuly 15, 2026
Business Impact Analysis
A mapping of what happens to the business when a system is unavailable: who is affected, how fast, and at what cost. The basis for non-technical ranking.
- TermJuly 15, 2026
Blast radius
Everything affected when one system goes down — including the systems that depend on it and did not know they did. What sets a window's real risk.
- TermJuly 15, 2026
Change Advisory Board
The forum that approves production changes. For patching, the body that decides whether a class of window may go ahead and who carries it.
- TermJuly 15, 2026
Change freeze
A defined period in which production changes are not permitted — quarter end, year end, a business event — except for approved emergency changes.
- TermJuly 15, 2026
Window collision
Two windows overlapping in time on systems that depend on each other. Each was properly approved, and neither approver knew about the other.
- TermJuly 15, 2026
Cumulative update
An update containing every fix that preceded it. Installing the latest one also closes everything that was missed before it.
- TermJuly 15, 2026
CVE
A public unique identifier for one security vulnerability, in the form CVE-YYYY-NNNN. The shared language that lets tools talk about the same flaw.
- TermJuly 15, 2026
CVSS
An open standard scoring the technical severity of a vulnerability from 0 to 10. It measures the flaw — not the risk to the system it happens to sit on.
- TermJuly 15, 2026
Directive 364
The Bank of Israel directive covering IT risk, information security and cyber defence. It consolidates and replaces Directives 357, 361 and 363.
- TermJuly 15, 2026
Emergency change
A change that cannot wait for the normal process. §97 of Directive 364 requires defined procedures for assessing and approving it, and a named approver.
- TermJuly 15, 2026
End of life / end of support
The date from which a product no longer receives security updates. After it, a new vulnerability will not be closed by a patch — it needs another decision.
- TermJuly 15, 2026
EPSS
A model estimating the probability that a vulnerability will be exploited in the near term. It complements a severity score rather than replacing it.
- TermJuly 15, 2026
KEV
A catalog of vulnerabilities with evidence of exploitation in the wild. A stronger operational signal than severity, because it describes what is happening.
- TermJuly 15, 2026
Maintenance window
A defined period during which a system may be taken down or changed, agreed with its owner and known to everyone the outage affects.
- TermJuly 15, 2026
Patch cadence
How often a system gets a planned maintenance window. Usually derived from how exposed the host is and how critical the system on it is.
- TermJuly 15, 2026
Patch coordination
The work between finding a vulnerability and installing the fix: grouping, ranking, proposing a window, getting approval, and recording what happened.
- TermJuly 15, 2026
Patch group
The set of vulnerabilities one patch closes, together with every host it applies to. The unit a maintenance window can actually be booked for.
- TermJuly 15, 2026
Patch Tuesday
The second Tuesday of each month, when Microsoft publishes its monthly security rollup. The rhythm most Windows estates plan their year around.
- TermJuly 15, 2026
Remediation SLA
The maximum time defined between finding a vulnerability and fixing it, by severity and asset criticality. A target you can be measured against.
- TermJuly 15, 2026
Rollback plan
What to do when the update fails: how to get back to the previous state, how long that takes, and who decides it is time to stop and revert.
- TermJuly 15, 2026
RTO and RPO
How long a system may be down, and how much data may be lost. The two objectives that decide how long a maintenance window you can afford.
- TermJuly 15, 2026
System owner
The person authorised to approve an outage of a system and accountable for the consequences. No window without them, and no evidence without a record.
- TermJuly 15, 2026
Network tier
Where a host sits in the network topology, from the external edge to internal management. It sets exposure, and therefore patch cadence.
- TermJuly 15, 2026
WSUS target group
The group a host belongs to on the internal Windows update server, which decides which approved updates it receives and in which wave.
- ArticleJuly 2, 20264 min read
What happens between the scan and the install — eight steps
Patch coordination end to end: grouping by patch, ranking against business impact, proposing a window, owner approval, invitations, reminders, checklist execution and evidence.
- ReleaseJune 30, 2026
Scheduling, calendar and inventory — the base
The release that closes the full sequence: a five-step scheduling wizard, a window calendar, a server inventory reconciled from several sources, and templates.
- ArticleJune 24, 20264 min read
The patch was ready in March. The window was in July
Four months between an available fix and an installed one is almost never a technical failure. Here are the five places it actually stops, and what moves each of them.