Why, How and Where of Delays in Software Security Patch Management: An Empirical Investigation in the Healthcare Sector
Nesara Dissanayake, Mansooreh Zahedi, Asangi Jayatilaka, M. Ali Babar

TL;DR
This empirical study investigates the causes of delays in security patch management within healthcare organizations, identifying key reasons and suggesting strategies to improve timeliness and reduce security risks.
Contribution
It provides the first detailed empirical analysis of delay causes in healthcare patch management and offers practical mitigation strategies based on longitudinal data.
Findings
Coordination delays are the main cause of patching delays.
Most delays occur during the patch deployment phase.
Practitioners employ specific strategies to mitigate delays.
Abstract
Numerous security attacks that resulted in devastating consequences can be traced back to a delay in applying a security patch. Despite the criticality of timely patch application, not much is known about why and how delays occur when applying security patches in practice, and how the delays can be mitigated. Based on longitudinal data collected from 132 delayed patching tasks over a period of four years and observations of patch meetings involving eight teams from two organisations in the healthcare domain, and using quantitative and qualitative data analysis approaches, we identify a set of reasons relating to technology, people and organisation as key explanations that cause delays in patching. Our findings also reveal that the most prominent cause of delays is attributable to coordination delays in the patch management process and a majority of delays occur during the patch…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Software Engineering Techniques and Practices · Software System Performance and Reliability
