When You Need to Update but Can’t Afford Disruption

Jun 26, 2019 | Cyber Security, IT News

We talk about the importance of updating your software all the time — whether it’s applying the dreaded Windows Update patches from Microsoft every “Patch Tuesday” or completely removing depreciated applications. It’s no secret that these updates can cause problems for some people, but unfortunately it doesn’t change the fact that these updates are imperative. How do you manage the sometimes difficult task of keeping your company running during and after applying critical updates — updates that are designed precisely for keeping things running in the first place?

Cybersecurity Begins With Risk Assessment

Which key systems need to be updated and upgraded — and when — are ongoing questions for managers and admins, and it can often require an experienced IT company to help you make those determinations. But you also need to know where your biggest vulnerabilities are and how those vulnerabilities could impact your business. Some systems need to be updated immediately, but not all. To complicate matters further, depending on the age of the system you’re updating, an update could potentially damage it. Your decision-making process must be inherently risk-driven — that is, you must weigh the potential cost of action versus the cost of inaction for each individual system that normally keeps your business afloat.

Some Things Just Can’t Be Patched

When You Need to Update but Can’t Afford DisruptionIt’s true. There are some legacy systems that businesses rely on that are so old, you simply can’t patch them safely or in any meaningful way. If nothing else though, there are important steps you can take to protect legacy infrastructure.

1. Secure Your Endpoints

The difference between endpoint security and say, antivirus software, is that endpoints bear some or all responsibility for their own security. For example, equipment such as programmable logic controllers, or PLCs, remote terminal units, or RTUs, and intelligent electronic devices, or IEDs, should be made secure by allowing only communication to reach them for which they are designed for. Filtering out any and all unnecessary traffic from the communication channel leading up to the endpoint prevents it from being exposed to an exploit or attack.

2. Secure Your Network

If you’re using a legacy device, chances are the network communication protocol it uses isn’t secure. Even if it already has a form of security, it’s likely quite old and can be easily broken by now. A good way of preventing what’s known as a “man-in-the-middle” attack, which exploits weaker versions of SSL and SSH used in the past, is by routing all communication through a VPN.

3. Remain Vigilant and Monitor Both

Once you’ve secured endpoints and their network, you must watch them both carefully. We have ways of doing that for you. New vulnerabilities and exploits are discovered daily, and your network is always going to be under constant threat whenever something newer comes along.

V2 Systems will work with you to help you determine where your most vulnerable areas are, what should be updated and what the potential risks are for updating — or NOT updating. By working together, we can minimize any impact to your business.

Since 1995, Manassas Park, VA-based V2 Systems has employed local systems administrators, network engineers, security consultants, help desk technicians and partnering companies to meet a wide range of clients’ IT needs, from research, to implementation, to maintenance. Concentrate on your VISION…We’ll handle the TECHNOLOGY!

More From V2 Systems

CMMC Update: What Government Contractors Need to Know as of August 2026

The Department of War announced the immediate suspension of CMMC Phase II requirements on July 13, 2026, pausing upcoming third-party assessment mandates. However, Phase I self-assessments, NIST SP 800-171 Rev. 2, DFARS 252.204-7012, and core cybersecurity obligations remain active. This blog explains what government contractors need to know as of August 2026 and how to stay prepared during the review period.

Summer Cyber Risks: Why Attacks Spike When Teams Are Short-Staffed

Summer vacations, lighter staffing, remote work, and busy schedules can create cybersecurity gaps for small businesses and government contractors. This blog explains why attackers take advantage of short-staffed teams and what organizations can do to reduce risk during the summer months.

Why Security Awareness Training Fails and How to Fix It

Security awareness training often fails because it is too generic, too infrequent, or too disconnected from how employees actually work. This blog explains why annual training alone is not enough and how small businesses and government contractors can build a more practical, ongoing approach to cybersecurity awareness.

Cybersecurity Fatigue Is Real: How to Keep Employees Engaged Without Burnout

Employees play a critical role in cybersecurity, but constant warnings, training reminders, password prompts, and security alerts can lead to fatigue. This blog explains how small businesses and government contractors can keep employees engaged with cybersecurity without overwhelming them.

How Government Contractors Can Stay Secure During Disruptions and Staffing Gaps

Disruptions are unavoidable, but security gaps do not have to be. For government contractors, staffing shortages, PTO, turnover, shutdowns, and contract transitions can create real cybersecurity and compliance risk. This blog explains how GovCons can maintain security, protect sensitive data, and keep operations moving when key people are unavailable.

Free
Small Business Cybersecurity Checklist

cybersecurity checklist graphic