Not as easy as just update: Survey of System Administrators and Patching Behaviours
Adam D. G. Jenkins, Linsen Liu, Maria K. Wolters, Kami Vaniea
Abstract
Patching software theoretically leads to improvements including security critical changes, but it can also lead to new issues. For System Administrators (sysadmins) new issues can negatively impact operations at their organization. While mitigation options like test environments exist, little is known about their prevalence or how contextual factors like size of organization impact the practice of Patch Management. We surveyed 220 sysadmins engaged in Patch Management to investigate self-reported behaviors. We found that dedicated testing environments are not as prevalent as previously assumed. We also expand on known behaviours that sysadmins perform when facing a troublesome patch, such as employing a range of problem solving behaviours to inform their patching decisions.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers4
- Mapping the Cloud: A Mixed-Methods Study of Cloud Security and Privacy Configuration ChallengesSumair Ijaz Hashmi, Shafay Kashif, Lea Gröber, Katharina Krombholz et al.NDSS 2026 · 3 citations
- No Silver Bullet: Towards Demonstrating Secure Software Development for Small and Medium Enterprises in a Business-to-Business ModelRaha Asadi, Bodil Biering, Vincent van Dijk, Oksana Kulyk et al.CHI 2025 · 2 citations
- Understanding Home Router Configuration Habits & AttitudesJunjian Ye, Xavier de Carné de Carnavalet, Lianying Zhao, Lifa Wu et al.CHI 2025 · 1 citation
- Behind the Curtain: How Shared Hosting Providers Respond to Vulnerability NotificationsGiada Stivala, Rafael Mrowczynski, Maria Hellenthal, Giancarlo PellegrinoS&P 2026
Builds on13
- A Large-Scale Empirical Study of Security PatchesFrank Li, Vern PaxsonCCS 2017 · 273 citations
- How I Learned to be Secure: a Census-Representative Survey of Security Advice Sources and BehaviorElissa M. Redmiles, Sean Kross, Michelle L. MazurekCCS 2016 · 192 citations
- Investigating System Operators' Perspective on Security MisconfigurationsConstanze Dietrich, Katharina Krombholz, Kevin Borgolte, Tobias FiebigCCS 2018 · 116 citations
- "I Have No Idea What I'm Doing" - On the Usability of Deploying HTTPSKatharina Krombholz, Wilfried Mayer, Martin Schmiedecker, Edgar R. WeipplUSENIX Security 2017 · 114 citations
- Understanding Privacy-Related Questions on Stack OverflowMohammad Tahaei, Kami Vaniea, Naomi SaphraCHI 2020 · 93 citations
Related papers
- "Technically speaking I'm at the top of the hierarchy": How System Administrators Think About PowerLydia Weinberger, Carolin Lämmle, Andreas Hammer, Christian Eichenmüller et al.CHI 2026 · 1 citation
- Asking for a Friend: Evaluating Response Biases in Security User StudiesElissa M. Redmiles, Ziyun Zhu, Sean Kross, Dhruv Kuchhal et al.CCS 2018 · 65 citations
- The Unpatchables: Why Municipalities Persist in Running Vulnerable HostsAksel Ethembabaoglu, Rolf van Wegberg, Yury Zhauniarovich, Michel van EetenUSENIX Security 2024 · 4 citations
- Measuring Secure Coding Practice and Culture: A Finger Pointing at the Moon is not the MoonIta Ryan, Utz Roedig, Klaas-Jan StolICSE 2023 · 13 citations
- Why, How and Where of Delays in Software Security Patch Management: An Empirical Investigation in the Healthcare SectorNesara Dissanayake, Mansooreh Zahedi, Asangi Jayatilaka, Muhammad Ali BabarCSCW 2022 · 18 citations
