Blog
On coordination, windows and patches
What we learned building patch coordination inside a bank's infrastructure team. No customer stories we don't have, and no numbers we didn't measure.
- ArticleAugust 6, 20264 min read
Measuring patch compliance without lying to yourself
Open vulnerability count is not a metric — it moves with what the scanner found, not with what you did. Four measures that survive contact with an auditor, and three that do not.
- ArticleAugust 4, 20264 min read
Two valid windows, one night, and a system that went down
The expensive failure in patch coordination is not a window that slips. It is two properly approved windows on systems that depend on each other — and how to catch it before the date is set.
- ArticleJuly 28, 20262 min readHebrew only
הוראה 357 כבר לא בתוקף — מה בא במקומה
הוראת ניהול בנקאי תקין 364 מאחדת ומחליפה את 357, 361 ו‑363. אם המדיניות שלכם עדיין מפנה ל‑357, זה מה שצריך לעדכן ואיפה נמצאים הסעיפים המקבילים.
- ArticleJuly 21, 20264 min read
Reading Directive 364 §61.4 as an operations requirement
What the patch-management clause of Bank of Israel Directive 364 actually requires, which operational decisions it forces, and what has to be written down to have anything to show.
- ArticleJuly 2, 20264 min read
What happens between the scan and the install — eight steps
Patch coordination end to end: grouping by patch, ranking against business impact, proposing a window, owner approval, invitations, reminders, checklist execution and evidence.
- ArticleJune 24, 20264 min read
The patch was ready in March. The window was in July
Four months between an available fix and an installed one is almost never a technical failure. Here are the five places it actually stops, and what moves each of them.