{"id":4603,"date":"2021-06-15T08:00:41","date_gmt":"2021-06-15T06:00:41","guid":{"rendered":"https:\/\/www.teal-consulting.de\/?p=4603"},"modified":"2021-06-15T15:13:48","modified_gmt":"2021-06-15T13:13:48","slug":"esae-deep-dive-series-part-10-patch-management","status":"publish","type":"post","link":"https:\/\/www.teal-consulting.de\/en\/2021\/06\/15\/esae-deep-dive-series-part-10-patch-management\/","title":{"rendered":"(E)SAE DEEP DIVE SERIES PART 10 \u2013 Patch Management"},"content":{"rendered":"<div class=\"wpb-content-wrapper\" id=\"wpb-content-root\">[vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;30&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text]This month our blog is about patch management. Today&#8217;s software is complex, the source code of Windows includes several million lines of code and vulnerabilities are discovered regularly. At the same time, the attacker scene has become much more professional, including state actors with access to immense resources. This makes it all the more important to close these vulnerabilities as quickly as possible with patches provided by the manufacturer.<\/p>\n<p>An <a href=\"https:\/\/www.fireeye.com\/blog\/threat-research\/2020\/04\/time-between-disclosure-patch-release-and-vulnerability-exploitation.html\" target=\"_blank\" rel=\"noopener\">investigation<\/a> by the security vendor FireEye of 60 vulnerabilities in 2018\/2019 concludes that 58 percent of vulnerabilities were exploited before a patch was released and 27 percent were exploited within a month of a patch being released. At the same time, according to a <a href=\"https:\/\/cdn2.hubspot.net\/hubfs\/4118561\/BCC030%20Vulnerability%20Stats%20Report%20(2020)_WEB.pdf\" target=\"_blank\" rel=\"noopener\">study<\/a> by the security vendor Edgescan, it takes an average of up to 73 days for organizations to close the vulnerability by installing the patch. The message is clear, the patch management process must be accelerated.[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][vc_empty_space height=&#8221;30&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221; padding_top=&#8221;20&#8243; padding_bottom=&#8221;20&#8243;][vc_column_inner][vc_single_image image=&#8221;4543&#8243; img_size=&#8221;800&#215;800&#8243; alignment=&#8221;center&#8221; qode_css_animation=&#8221;&#8221;][\/vc_column_inner][\/vc_row_inner][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221; padding_top=&#8221;20&#8243; padding_bottom=&#8221;20&#8243;][vc_column_inner][vc_empty_space height=&#8221;30&#8243;][vc_column_text]This sounds trivial at first glance, but customer experience shows that many organizations do not have a complete handle on the topic or simply take too long compared to the attackers. There are countless articles on the subject of patch management in the literature and on the web, which is why we will limit ourselves to describing our &#8220;standard process&#8221; in the blog article. We usually start the discussion with the customer with this standard process and adapt the process to the customer&#8217;s specific needs and technical requirements.<\/p>\n<p>The patch management process includes the regular identification of existing patches, as well as the planning and installation of the patches in the company. The prerequisite for identifying patches is that the systems and software used in the company are known.<\/p>\n<p>To shorten the time between becoming aware of a security vulnerability and closing it, it is important to automate this process as much as possible. Common management tools such as <a href=\"https:\/\/docs.microsoft.com\/windows-server\/administration\/windows-server-update-services\/get-started\/windows-server-update-services-wsus\" target=\"_blank\" rel=\"noopener\">Windows Server Update Services<\/a> (WSUS) or<a href=\"https:\/\/www.microsoft.com\/security\/business\/microsoft-endpoint-manager\" target=\"_blank\" rel=\"noopener\">Microsoft Endpoint Manager<\/a> already offer a range of functions for automation:<\/p>\n<ul>\n<li>Provision of patch metadata<\/li>\n<li>Automatic inventory of systems<\/li>\n<li>Detection of uninstalled patches based on metadata<\/li>\n<li>Automatic installation of patches at defined times<\/li>\n<li>Reports on installed or uninstalled patches on all systems<\/li>\n<\/ul>\n[\/vc_column_text][vc_empty_space height=&#8221;60&#8243;][vc_column_text]\n<h3>Overview Patch Management-Process<\/h3>\n[\/vc_column_text][vc_empty_space height=&#8221;30&#8243;][vc_single_image image=&#8221;4552&#8243; img_size=&#8221;full&#8221; qode_css_animation=&#8221;&#8221; el_class=&#8221;kreis&#8221;][vc_empty_space height=&#8221;30&#8243;][vc_column_text]\n<h5>Identify patches<\/h5>\n<p>Patches released by vendors need to be identified and evaluated on a regular basis. In the case of very urgent updates, such as this year&#8217;s remotely exploitable <a href=\"https:\/\/msrc-blog.microsoft.com\/2021\/03\/16\/guidance-for-responders-investigating-and-remediating-on-premises-exchange-server-vulnerabilities\/\" target=\"_blank\" rel=\"noopener\">vulnerabilities for Microsoft Exchange<\/a>, a monthly update cycle is not sufficient. In this case, an emergency patch process must be provided to install the patches as quickly as possible and, if necessary, manually on the affected systems. The remaining patches are installed as part of the normal patch process at regular intervals (in most cases every 4 weeks).<\/p>\n<p>For the identification of the patches, management tools are very helpful, which provide and regularly update the metadata of the patches for Microsoft and ideally for widespread software manufacturers. Based on this metadata, these management tools can scan all managed systems and determine which patches are installed or not installed. In this way, extensive automation of many process steps can also be achieved.<\/p>\n<p>For systems that are not automatically managed with management tools, such as servers in a DMZ or in Tier 0 in an ESAE environment, it must be determined what the procedure is there. In these cases, it often makes sense to deploy a separate WSUS environment.<\/p>\n<p>The BSI also regularly issues <a href=\"https:\/\/www.bsi.bund.de\/DE\/Themen\/Unternehmen-und-Organisationen\/Cyber-Sicherheitslage\/Technische-Sicherheitshinweise-und-Warnungen\/Cyber-Sicherheitswarnungen\/cyber-sicherheitswarnungen_node.html\" target=\"_blank\" rel=\"noopener\">cyber security alerts<\/a> about new and threatening attack vectors.<\/p>\n<h5>Planning<\/h5>\n<p>In most cases, patches are rolled out on a monthly basis. In this case, it makes sense to bundle all patches and install them at the same time in a maintenance window. Patches as part of the emergency patch process are installed separately.<\/p>\n<p>If ITIL-compliant change management is implemented, the installation of patches is approved by the Change Advisory Board (CAB). As the installation of patches is a regularly recurring activity, a standard Change is usually defined for this purpose, which is automatically approved.<\/p>\n<h5>Patch testing<\/h5>\n<p>For testing patches it is very helpful to have a test environment. This should ideally be as close as possible to the production environment. In the test environment, the essential infrastructure services such as Active Directory, Exchange or SharePoint should be installed, of course in a smaller version but still in a similar configuration. For Active Directory, this means at least two domain controllers or, in the case of SQL Server, in a cluster configuration if this is also the case in production (in test, two nodes are then usually sufficient).<br \/>\nIn testing, the respective infrastructure service or application should be checked for functionality after the installation of patches. Here, automated tests help to reduce the effort and the critical time until the patches are installed. Monitoring tools such as <a href=\"https:\/\/docs.microsoft.com\/system-center\/scom\/key-concepts?view=sc-om-2019\" target=\"_blank\" rel=\"noopener\">System Center Operations Manager<\/a> can be very helpful here because they regularly check whether a service is actually available.<\/p>\n<h5>Rolling out patches<\/h5>\n<p>To minimize risks, patches should not be rolled out to all systems simultaneously. For this purpose, different rollout groups are defined on which the patches are successively installed at different times. There is sufficient buffer between the installation times of the individual rollout groups to be able to react if problems occur.<\/p>\n<p>The systems are categorized and assigned to the various rollout groups. Systems implementing a particular service should be assigned to different rollout groups. For example, Domain Controller 1 to Rollout Group 1 and Domain Controller 2 to Rollout Group 2.[\/vc_column_text][vc_empty_space height=&#8221;30&#8243;][vc_single_image image=&#8221;4560&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; qode_css_animation=&#8221;&#8221; el_class=&#8221;group&#8221;][vc_empty_space height=&#8221;30&#8243;][vc_column_text]To automate more complex dependencies, a runbook automation tool such as <a href=\"https:\/\/docs.microsoft.com\/system-center\/orchestrator\/learn-about-orchestrator?view=sc-orch-2019\" target=\"_blank\" rel=\"noopener\">System Center Orchestrator<\/a> can be used.<\/p>\n<p>Tests are performed between the deployment of the different rollout groups. These tests are performed by the respective server or application managers according to the requirements of the application.[\/vc_column_text][vc_empty_space height=&#8221;30&#8243;][vc_single_image image=&#8221;4570&#8243; img_size=&#8221;full&#8221; qode_css_animation=&#8221;&#8221; el_class=&#8221;group&#8221;][vc_empty_space height=&#8221;30&#8243;][vc_column_text]In a fully automated patch rollout process, there should be a way to prevent the installation of a patch for a specific system.<\/p>\n<h5>Verify<\/h5>\n<p>After installation, a check is made to ensure that the patches have actually been installed. In the case of common management tools, the check is performed automatically. The status is usually displayed in web-based reports. SQL Server Reporting Services offers the possibility to generate reports at specific times and send them to e-mail distribution lists. In addition, they contain an environment for developing reports that are adapted to the company&#8217;s requirements and prepare essential information for management.[\/vc_column_text][vc_empty_space height=&#8221;30&#8243;][vc_column_text]\n<h5 style=\"text-align: center;\">Patch Compliance Overall<\/h5>\n[\/vc_column_text][vc_empty_space height=&#8221;30&#8243;][vc_single_image image=&#8221;4611&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; qode_css_animation=&#8221;&#8221; el_class=&#8221;group1&#8243;][vc_empty_space height=&#8221;30&#8243;][vc_column_text]In addition, it can be very useful to use a vulnerability scanner such as <a href=\"https:\/\/www.tenable.com\/products\/nessus\" target=\"_blank\" rel=\"noopener\">Nessus<\/a>. This scans the systems in the network and checks whether the vulnerability is exploitable.<\/p>\n<h3>Procedure<\/h3>\n<p>Here we will outline a standard approach for implementing a patch management process.<\/p>\n<h5>Implementation project<\/h5>\n<p>It starts with an implementation project, the scope of which depends on the customer&#8217;s goals, the number of systems and applications, and the maturity of the existing process. A typical project structure may include the following activities:[\/vc_column_text][vc_empty_space height=&#8221;30&#8243;][vc_single_image image=&#8221;4583&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; qode_css_animation=&#8221;&#8221; el_class=&#8221;group&#8221;][vc_empty_space height=&#8221;30&#8243;][vc_column_text]\n<h5>Patch-Cycle<\/h5>\n<p>The following describes the activities that occur in a patch cycle. In most companies, this is carried out on a monthly basis. In Microsoft-heavy companies, it has become customary to align the patch cycle with Microsoft&#8217;s &#8220;Patch Tuesday&#8221;. Microsoft always releases its patches on the second Tuesday of the month. In the meantime, a number of other manufacturers have adopted this approach.<\/p>\n<p>First, the patches published by the manufacturers are identified. The patches are combined in a release (and, if necessary, in an emergency release). The patch release is installed on prepared waves for test systems. These systems are usually located in a separate test environment. In larger organizations, test environments are often multi-tiered. If one does not exist, dedicated test systems are used within the production environment. If a test environment exists, but it reflects the production environment only to a very limited extent, it is a good idea to include some production systems in the test wave.[\/vc_column_text][vc_empty_space height=&#8221;30&#8243;][vc_single_image image=&#8221;4590&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; qode_css_animation=&#8221;&#8221; el_class=&#8221;group&#8221;][vc_empty_space height=&#8221;30&#8243;][vc_column_text]The patches are rolled out in several waves. The systems are usually statically assigned to the individual waves. This means that this is configured once and no changes need to be made to this configuration during the regular patch cycle. In many patch management tools, the necessary steps can also be automated. The installation of the patches must be checked. For this purpose, the common patch management tools offer web-based reports.[\/vc_column_text][vc_empty_space height=&#8221;30&#8243;][vc_single_image image=&#8221;4592&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; qode_css_animation=&#8221;&#8221; el_class=&#8221;group&#8221;][vc_empty_space height=&#8221;30&#8243;][vc_column_text]The process presented here illustrates how the installation of the patches in the company can be carried out in a short time. Of course, this must be adapted to the requirements and framework conditions during an implementation.<\/p>\n<h3>Summary<\/h3>\n<p>In detail, there are certainly many more aspects that need to be considered, but we hope to have given you an idea of how a fast patch management process can look like. Feel free to leave us feedback.[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_empty_space height=&#8221;50&#8243;][vc_separator type=&#8221;small&#8221; position=&#8221;center&#8221; color=&#8221;#eeeeee&#8221; thickness=&#8221;2&#8243; width=&#8221;1100&#8243;][vc_empty_space height=&#8221;50&#8243;][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;center&#8221; background_image_as_pattern=&#8221;without_pattern&#8221; z_index=&#8221;&#8221;][vc_column width=&#8221;1\/2&#8243; offset=&#8221;vc_hidden-sm vc_hidden-xs&#8221;][vc_column_text][\/vc_column_text][\/vc_column][vc_column width=&#8221;1\/2&#8243; offset=&#8221;vc_hidden-sm vc_hidden-xs&#8221;][vc_column_text][\/vc_column_text][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;grid&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;center&#8221; background_image_as_pattern=&#8221;without_pattern&#8221; z_index=&#8221;&#8221;][vc_column width=&#8221;1\/2&#8243; offset=&#8221;vc_hidden-lg vc_hidden-md&#8221;][vc_column_text][\/vc_column_text][\/vc_column][vc_column width=&#8221;1\/2&#8243; offset=&#8221;vc_hidden-lg vc_hidden-md&#8221;][vc_column_text][\/vc_column_text][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;center&#8221; background_image_as_pattern=&#8221;without_pattern&#8221; z_index=&#8221;&#8221;][vc_column width=&#8221;1\/2&#8243;][vc_empty_space height=&#8221;30&#8243;][vc_column_text]\n<blockquote class=\"instagram-media\" style=\"background: #FFF; border: 0; border-radius: 3px; margin: 1px; max-width: 540px; min-width: 326px; padding: 0;\" data-instgrm-permalink=\"https:\/\/www.instagram.com\/p\/CNF_8xCjiyu\/?utm_source=ig_embed&amp;utm_campaign=loading\" data-instgrm-version=\"13\">\n<div style=\"padding: 16px;\">\n<p>&nbsp;<\/p>\n<div style=\"flex-direction: row; align-items: center;\">\n<div style=\"background-color: #f4f4f4; border-radius: 50%; flex-grow: 0; height: 40px; margin-right: 14px; width: 40px;\"><\/div>\n<div style=\"flex-direction: column; flex-grow: 1; justify-content: center;\">\n<div style=\"background-color: #f4f4f4; border-radius: 4px; flex-grow: 0; height: 14px; margin-bottom: 6px; width: 100px;\"><\/div>\n<div style=\"background-color: #f4f4f4; border-radius: 4px; flex-grow: 0; height: 14px; width: 60px;\"><\/div>\n<\/div>\n<\/div>\n<div style=\"padding: 19% 0;\"><\/div>\n<div style=\"height: 50px; margin: 0 auto 12px; width: 50px;\"><\/div>\n<div style=\"padding-top: 8px;\">\n<div style=\"color: #3897f0; font-family: Arial,sans-serif; font-size: 14px; font-style: normal; font-weight: 550; line-height: 18px;\">Sieh dir diesen Beitrag auf Instagram an<\/div>\n<\/div>\n<div style=\"padding: 12.5% 0;\"><\/div>\n<div style=\"flex-direction: row; margin-bottom: 14px; align-items: center;\">\n<div>\n<div style=\"background-color: #f4f4f4; border-radius: 50%; height: 12.5px; width: 12.5px;\"><\/div>\n<div style=\"background-color: #f4f4f4; height: 12.5px; width: 12.5px; flex-grow: 0; margin-right: 14px; margin-left: 2px;\"><\/div>\n<div style=\"background-color: #f4f4f4; border-radius: 50%; height: 12.5px; width: 12.5px;\"><\/div>\n<\/div>\n<div style=\"margin-left: 8px;\">\n<div style=\"background-color: #f4f4f4; border-radius: 50%; flex-grow: 0; height: 20px; width: 20px;\"><\/div>\n<div style=\"width: 0; height: 0; border-top: 2px solid transparent; border-left: 6px solid #f4f4f4; border-bottom: 2px solid transparent;\"><\/div>\n<\/div>\n<div style=\"margin-left: auto;\">\n<div style=\"width: 0px; border-top: 8px solid #F4F4F4; border-right: 8px solid transparent;\"><\/div>\n<div style=\"background-color: #f4f4f4; flex-grow: 0; height: 12px; width: 16px;\"><\/div>\n<div style=\"width: 0; height: 0; border-top: 8px solid #F4F4F4; border-left: 8px solid transparent;\"><\/div>\n<\/div>\n<\/div>\n<div style=\"flex-direction: column; flex-grow: 1; justify-content: center; margin-bottom: 24px;\">\n<div style=\"background-color: #f4f4f4; border-radius: 4px; flex-grow: 0; height: 14px; margin-bottom: 6px; width: 224px;\"><\/div>\n<div style=\"background-color: #f4f4f4; border-radius: 4px; flex-grow: 0; height: 14px; width: 144px;\"><\/div>\n<\/div>\n<p>&nbsp;<\/p>\n<p style=\"color: #c9c8cd; font-family: Arial,sans-serif; font-size: 14px; line-height: 17px; margin-bottom: 0; margin-top: 8px; overflow: hidden; padding: 8px 0 7px; text-align: center;\"><a style=\"color: #c9c8cd; font-family: Arial,sans-serif; font-size: 14px; font-style: normal; font-weight: normal; line-height: 17px; text-decoration: none;\" href=\"https:\/\/www.instagram.com\/p\/CNF_8xCjiyu\/?utm_source=ig_embed&amp;utm_campaign=loading\" target=\"_blank\" rel=\"noopener\">Ein Beitrag geteilt von TEAL Technology Consulting (@tealconsulting)<\/a><\/p>\n<\/div>\n<\/blockquote>\n[\/vc_column_text][\/vc_column][vc_column width=&#8221;1\/2&#8243;][vc_empty_space height=&#8221;30&#8243;][vc_column_text]\n<blockquote class=\"instagram-media\" style=\"background: #FFF; border: 0; border-radius: 3px; margin: 1px; max-width: 540px; min-width: 326px; padding: 0;\" data-instgrm-permalink=\"https:\/\/www.instagram.com\/p\/CMUM_xrjqno\/?utm_source=ig_embed&amp;utm_campaign=loading\" data-instgrm-version=\"13\">\n<div style=\"padding: 16px;\">\n<p>&nbsp;<\/p>\n<div style=\"flex-direction: row; align-items: center;\">\n<div style=\"background-color: #f4f4f4; border-radius: 50%; flex-grow: 0; height: 40px; margin-right: 14px; width: 40px;\"><\/div>\n<div style=\"flex-direction: column; flex-grow: 1; justify-content: center;\">\n<div style=\"background-color: #f4f4f4; border-radius: 4px; flex-grow: 0; height: 14px; margin-bottom: 6px; width: 100px;\"><\/div>\n<div style=\"background-color: #f4f4f4; border-radius: 4px; flex-grow: 0; height: 14px; width: 60px;\"><\/div>\n<\/div>\n<\/div>\n<div style=\"padding: 19% 0;\"><\/div>\n<div style=\"height: 50px; margin: 0 auto 12px; width: 50px;\"><\/div>\n<div style=\"padding-top: 8px;\">\n<div style=\"color: #3897f0; font-family: Arial,sans-serif; font-size: 14px; font-style: normal; font-weight: 550; line-height: 18px;\">Sieh dir diesen Beitrag auf Instagram an<\/div>\n<\/div>\n<div style=\"padding: 12.5% 0;\"><\/div>\n<div style=\"flex-direction: row; margin-bottom: 14px; align-items: center;\">\n<div>\n<div style=\"background-color: #f4f4f4; border-radius: 50%; height: 12.5px; width: 12.5px;\"><\/div>\n<div style=\"background-color: #f4f4f4; height: 12.5px; width: 12.5px; flex-grow: 0; margin-right: 14px; margin-left: 2px;\"><\/div>\n<div style=\"background-color: #f4f4f4; border-radius: 50%; height: 12.5px; width: 12.5px;\"><\/div>\n<\/div>\n<div style=\"margin-left: 8px;\">\n<div style=\"background-color: #f4f4f4; border-radius: 50%; flex-grow: 0; height: 20px; width: 20px;\"><\/div>\n<div style=\"width: 0; height: 0; border-top: 2px solid transparent; border-left: 6px solid #f4f4f4; border-bottom: 2px solid transparent;\"><\/div>\n<\/div>\n<div style=\"margin-left: auto;\">\n<div style=\"width: 0px; border-top: 8px solid #F4F4F4; border-right: 8px solid transparent;\"><\/div>\n<div style=\"background-color: #f4f4f4; flex-grow: 0; height: 12px; width: 16px;\"><\/div>\n<div style=\"width: 0; height: 0; border-top: 8px solid #F4F4F4; border-left: 8px solid transparent;\"><\/div>\n<\/div>\n<\/div>\n<div style=\"flex-direction: column; flex-grow: 1; justify-content: center; margin-bottom: 24px;\">\n<div style=\"background-color: #f4f4f4; border-radius: 4px; flex-grow: 0; height: 14px; margin-bottom: 6px; width: 224px;\"><\/div>\n<div style=\"background-color: #f4f4f4; border-radius: 4px; flex-grow: 0; height: 14px; width: 144px;\"><\/div>\n<\/div>\n<p>&nbsp;<\/p>\n<p style=\"color: #c9c8cd; font-family: Arial,sans-serif; font-size: 14px; line-height: 17px; margin-bottom: 0; margin-top: 8px; overflow: hidden; padding: 8px 0 7px; text-align: center;\"><a style=\"color: #c9c8cd; font-family: Arial,sans-serif; font-size: 14px; font-style: normal; font-weight: normal; line-height: 17px; text-decoration: none;\" href=\"https:\/\/www.instagram.com\/p\/CMUM_xrjqno\/?utm_source=ig_embed&amp;utm_campaign=loading\" target=\"_blank\" rel=\"noopener\">Ein Beitrag geteilt von TEAL Technology Consulting (@tealconsulting)<\/a><\/p>\n<\/div>\n<\/blockquote>\n[\/vc_column_text][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;30&#8243;][vc_column_text]\n<h2>LATEST POSTS<\/h2>\n[\/vc_column_text][vc_empty_space height=&#8221;30&#8243;]\n<div class='latest_post_holder boxes three_columns one_row' >\n    <ul>\n    \n        <li class=\"clearfix\">\n            <div class=\"boxes_image\">\n                                <a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/04\/01\/logging-in-instead-of-breaking-in\/\"><img decoding=\"async\" width=\"539\" height=\"303\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/03\/blog_headerbild_teal_krux-mit-der-KI_AI-539x303.jpg\" class=\"attachment-latest_post_boxes size-latest_post_boxes wp-post-image lazyload\" alt=\"\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/03\/blog_headerbild_teal_krux-mit-der-KI_AI-539x303.jpg 539w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/03\/blog_headerbild_teal_krux-mit-der-KI_AI-300x169.jpg 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/03\/blog_headerbild_teal_krux-mit-der-KI_AI-1024x575.jpg 1024w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/03\/blog_headerbild_teal_krux-mit-der-KI_AI-768x432.jpg 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/03\/blog_headerbild_teal_krux-mit-der-KI_AI-1536x863.jpg 1536w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/03\/blog_headerbild_teal_krux-mit-der-KI_AI-700x393.jpg 700w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/03\/blog_headerbild_teal_krux-mit-der-KI_AI.jpg 1920w\" data-sizes=\"(max-width: 539px) 100vw, 539px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 539px; --smush-placeholder-aspect-ratio: 539\/303;\"><\/a>\n            <\/div>\n            <div class=\"latest_post\"  >\n                <div class=\"latest_post_text\">\n                    <div class=\"latest_post_inner\">\n                        <div class=\"latest_post_text_inner\">\n                            <h3 itemprop=\"name\" class=\"latest_post_title entry_title\"><a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/04\/01\/logging-in-instead-of-breaking-in\/\">\u201cLogging In instead of Breaking In\u201d: Why your identities are the biggest security risk<\/a><\/h3>\n                            <p class=\"excerpt\">Attackers no longer \u201csimply\u201d break in, they LOG in. If you\u2019re still relying on traditional defenses in 2026, we believe you\u2019ve probably already lost the battle for your data....<\/p>\n                            <span class=\"post_infos\">\n                                                                    <span class=\"date_hour_holder\">\n                                        <span itemprop=\"dateCreated\" class=\"date entry_date updated\">01 April, 2026 <meta itemprop=\"interactionCount\" content=\"UserComments: 0\"\/><\/span>\n                                    <\/span>\n                                                                                                \n                                \n                                                            <\/span>\n                        <\/div>\n                    <\/div>\n                <\/div>\n            <\/div>\n        <\/li>\n    \n        <li class=\"clearfix\">\n            <div class=\"boxes_image\">\n                                <a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/04\/29\/bsi-update-grundschutz\/\"><img decoding=\"async\" width=\"539\" height=\"303\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/09\/teal_blog_on-prem-safe_header-539x303.jpg\" class=\"attachment-latest_post_boxes size-latest_post_boxes wp-post-image lazyload\" alt=\"\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/09\/teal_blog_on-prem-safe_header-539x303.jpg 539w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/09\/teal_blog_on-prem-safe_header-300x169.jpg 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/09\/teal_blog_on-prem-safe_header-1024x575.jpg 1024w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/09\/teal_blog_on-prem-safe_header-768x432.jpg 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/09\/teal_blog_on-prem-safe_header-1536x863.jpg 1536w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/09\/teal_blog_on-prem-safe_header-700x393.jpg 700w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/09\/teal_blog_on-prem-safe_header.jpg 1920w\" data-sizes=\"(max-width: 539px) 100vw, 539px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 539px; --smush-placeholder-aspect-ratio: 539\/303;\"><\/a>\n            <\/div>\n            <div class=\"latest_post\"  >\n                <div class=\"latest_post_text\">\n                    <div class=\"latest_post_inner\">\n                        <div class=\"latest_post_text_inner\">\n                            <h3 itemprop=\"name\" class=\"latest_post_title entry_title\"><a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/04\/29\/bsi-update-grundschutz\/\">BSI Update: Grundschutz++ Will become mandatory in 2028 &#8211; why you should take action now<\/a><\/h3>\n                            <p class=\"excerpt\">The wait is over: The BSI has published the first guidelines for Grundschutz++. What at first glance looks like additional bureaucratic red tape is, in fact, the new \u201cstate of the art\u201d for NIS2. ...<\/p>\n                            <span class=\"post_infos\">\n                                                                    <span class=\"date_hour_holder\">\n                                        <span itemprop=\"dateCreated\" class=\"date entry_date updated\">29 April, 2026 <meta itemprop=\"interactionCount\" content=\"UserComments: 0\"\/><\/span>\n                                    <\/span>\n                                                                                                \n                                \n                                                            <\/span>\n                        <\/div>\n                    <\/div>\n                <\/div>\n            <\/div>\n        <\/li>\n    \n        <li class=\"clearfix\">\n            <div class=\"boxes_image\">\n                                <a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/01\/29\/bye-bye-rc4\/\"><img decoding=\"async\" width=\"539\" height=\"303\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/01\/Blog-Headerbild_RC4-539x303.png\" class=\"attachment-latest_post_boxes size-latest_post_boxes wp-post-image lazyload\" alt=\"\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/01\/Blog-Headerbild_RC4-539x303.png 539w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/01\/Blog-Headerbild_RC4-300x169.png 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/01\/Blog-Headerbild_RC4-1024x575.png 1024w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/01\/Blog-Headerbild_RC4-768x432.png 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/01\/Blog-Headerbild_RC4-1536x863.png 1536w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/01\/Blog-Headerbild_RC4-700x393.png 700w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/01\/Blog-Headerbild_RC4.png 1920w\" data-sizes=\"(max-width: 539px) 100vw, 539px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 539px; --smush-placeholder-aspect-ratio: 539\/303;\"><\/a>\n            <\/div>\n            <div class=\"latest_post\"  >\n                <div class=\"latest_post_text\">\n                    <div class=\"latest_post_inner\">\n                        <div class=\"latest_post_text_inner\">\n                            <h3 itemprop=\"name\" class=\"latest_post_title entry_title\"><a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/01\/29\/bye-bye-rc4\/\">Bye-bye RC4: Your guide to the Kerberos transition in April 2026<\/a><\/h3>\n                            <p class=\"excerpt\">The clock is ticking for one of the longest-lasting (and most insecure) ciphers in our networks. Microsoft is getting serious and pushing for the shutdown of RC4 encryption in the Kerberos protocol....<\/p>\n                            <span class=\"post_infos\">\n                                                                    <span class=\"date_hour_holder\">\n                                        <span itemprop=\"dateCreated\" class=\"date entry_date updated\">29 January, 2026 <meta itemprop=\"interactionCount\" content=\"UserComments: 0\"\/><\/span>\n                                    <\/span>\n                                                                                                \n                                \n                                                            <\/span>\n                        <\/div>\n                    <\/div>\n                <\/div>\n            <\/div>\n        <\/li>\n        <\/ul>\n<\/div>[\/vc_column][\/vc_row]\n<\/div>","protected":false},"excerpt":{"rendered":"<p>This month our blog is about patch management. Today&#8217;s software is complex, the source code of Windows includes several million lines of code, and vulnerabilities are discovered regularly<\/p>\n","protected":false},"author":14,"featured_media":4548,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[10],"tags":[],"class_list":["post-4603","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/posts\/4603","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/comments?post=4603"}],"version-history":[{"count":7,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/posts\/4603\/revisions"}],"predecessor-version":[{"id":4639,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/posts\/4603\/revisions\/4639"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/media\/4548"}],"wp:attachment":[{"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/media?parent=4603"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/categories?post=4603"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/tags?post=4603"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}