News, Trends, and Insights for IT & Managed Services Providers
News, Trends, and Insights for IT & Managed Services Providers
closeup photo of turned-on blue and white laptop computer

And early Big Idea, and it’s security related. In a recent discussion at the Infrastructure, Operations & Cloud Strategies Conference, Craig Lawson, a Research Vice President at Gartner, suggested that organizations may not need to rush into implementing every security patch that becomes available. He emphasized that most companies struggle to keep up with patching efforts and may be misled into believing that accelerating patches is the solution to their security vulnerabilities. Lawson pointed out that only 8 to 9 percent of vulnerabilities are actively exploited by cybercriminals, who often target less critical flaws rather than the most severe issues. He noted that the overwhelming number of patches issued can lead to complications, as developers may release new patches for software components that are interdependent. This complexity can result in organizations facing more problems without a corresponding decrease in successful cyberattacks. Lawson advocates for a tailored approach that emphasizes collaboration across teams to prioritize patches based on actual security needs.

Why do we care?

The patching treadmill is unsustainable—especially for resource-constrained environments.

Lawson points out a real-world issue: excessive patching can break dependencies, cause downtime, and distract from higher-priority threats. For MSPs juggling multiple stacks across client environments, the real risk is instability from uncoordinated patch application, not just unpatched flaws.

Misused, this advice becomes an excuse for inaction. Lazy or under-resourced orgs may take “don’t patch everything” to mean “don’t patch much.” That’s not Lawson’s point. The takeaway is to patch smarter, not slower or less.

Choose your upgrade:

Get the full benefits of Business of Tech Plus

Insider Access

$12/month

Perfect for MSPs and ITSPs that want full interviews, early access, and ad-free listening

  • Programmatic Ad-free private podcast feedSame show, little interruptions
  • Channel Chatter previews1–2 topics with light insights
  • Early access to interview episodesHear it days before public release
  • Monthly Insider BriefTighter analysis you can share internally
  • Extra audio segmentsCut interviews, behind-the-scenes commentary, quick competitive notes
  • Become an Insider for $12/month

    Leadership Access

    $149/month

    Perfect for MSPs and Vendors that run a team and need the extended tactics, executive summaries, and weekly alignment brief

  • All Insider Access benefits plus . . .
  • Invite your teamIncludes access for 5 team members with option to add more
  • Vendor Strategy BriefsThe entire library, plus new analysis every month
  • Channel ChatterAll topics, full insights, complete vendor discussion + sentiment list
  • Quarterly State of the Channel Briefing
  • Monthly AMA submission priorityAsk Dave direct questions, and skip the line
  • Get the Leadership Edge for $149/month

    Vendor Partner

    $500/month

    Perfect for channel companies or vendors looking to deepen their engagement with the show.

  • All Leadership Access benefits plus . . .
  • Get highlighted as a show sponsor You'll get placement in the show notes, throughout the website, and on our dedicated sponsors page.
  • Enjoy regular shout outs You'll be featured in a rotating format during the show
  • Become a show sponsor for $500/month

    Search all stories