Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs

Measuring Patch Deployment Success with Analytics

Ivanti
04/06/2026
0
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


TL;DR

  • Reporting accounts for 40% of patch management feature requests, driving Ivanti to develop nine out-of-the-box reports covering device status, patch deployment, operational metrics, and CVE-based vulnerability tracking.
  • The platform introduces four critical reporting perspectives: device-based views, patch-specific tracking, operational diagnostics for troubleshooting, and CVE-based reporting that spans multiple platforms and applications.
  • Dashboard designer enables custom analytics through drag-and-drop operations on preprocessed datasets, supporting visualizations from bar charts to time-series analysis without requiring SQL expertise.
  • Exposure-based compliance reporting calculates risk windows from patch release to installation dates rather than operational deployment windows, providing metrics that have successfully passed FDIC audits.
  • Maintenance reports demonstrate ROI by tracking patches deployed, vulnerabilities resolved, and known exploits remediated over time, enabling justification for process improvements like weekly updates or zero-day response programs.

The Reporting Challenge in Patch Management

Patch management has traditionally been dominated by reporting requirements, with approximately 40% of all feature requests focused on analytics and reporting capabilities. Organizations face constant demands for audit trails, compliance documentation, and remediation status updates from multiple stakeholders. The challenge extends beyond simple deployment tracking to include device-based views, patch-specific status reports, operational troubleshooting data, and increasingly, exposure-based reporting that aligns with security team requirements. This session addresses these challenges by demonstrating Ivanti Neurons' comprehensive reporting framework that provides nine out-of-the-box reports covering device status, patch deployment, operational metrics, and vulnerability-based analytics.

Four Critical Reporting Perspectives

Ivanti has identified four essential pivot points that drive reporting needs across organizations. First, device-based reporting provides visibility into what's missing or installed on specific endpoints, including installation dates and associated vulnerabilities. Second, patch-based reporting enables tracking of specific updates across the environment, critical for monitoring zero-day responses or monthly OS updates. Third, operational reporting delivers deep deployment diagnostics including failure codes and error details, essential for cross-team collaboration when patching complex business applications. Fourth, and most strategically significant, is CVE-based reporting that allows security teams to track vulnerabilities across multiple platforms and applications from a single query, eliminating the need to manually correlate patches across different systems.

Dashboard Designer Flexibility

Beyond canned reports, Ivanti Neurons offers a dashboard designer that enables custom analytics without requiring SQL knowledge or complex data manipulation. The platform provides preprocessed, joined datasets covering device patch scans and deployment history, allowing users to create visualizations through simple drag-and-drop operations. Users can build bar charts showing top devices with missing patches, pie charts breaking down exploit types, time-series views of deployment trends, and detailed tables of failed deployments within specific timeframes. The system supports natural language time filtering, allowing queries like 'last 12 hours' without manual date calculations, and offers flexible aggregation options including counts, sums, and maximums across multiple dimensions.

Exposure-Based Compliance and ROI Tracking

The platform introduces a maintenance report that shifts focus from operational metrics to business value demonstration. Rather than measuring compliance from deployment start to finish dates, the system calculates exposure windows from patch release dates to installation dates, providing true risk exposure metrics. This approach has proven successful in FDIC audits with banking customers and enables IT teams to demonstrate the impact of operational changes like weekly browser updates or zero-day response programs. Organizations can track how many patches were deployed, vulnerabilities resolved, and known exploited vulnerabilities remediated over 90-day, 180-day, or annual periods, providing concrete evidence for justifying process improvements and resource investments.

Chapters

0:00 - Introduction and Session Overview
2:52 - The Importance of Analytics in Patch Management
5:00 - Four Types of Reporting Questions
9:00 - Nine Out-of-Box Reports Overview
12:04 - Creating Reports Demo
17:00 - Dashboard Designer Introduction
18:36 - Building Visual Charts
21:36 - Challenge: Exploit Type Analysis
24:08 - Deployment History Visualization
28:48 - Advanced Filtering and Tables
31:32 - Q&A and Roadmap Discussion

Key Quotes

4:04 "I've been in this space for a little over 20 years now, and traditionally reporting has accounted for roughly 40% of all feature requests that my product group gets in their products."
7:04 "This shift from operational to exposure-based mentality. We need to be able to identify the risks to our environment, how long we've been exposed to it, and be able to show when things were remediated."
8:16 "Just let me ask for that specific CVE. If that CVE happens to be both in the Apple OS and the Windows OS and also the browser, it's a shared component across all of those, that one CVE should be able to show me all of those different patches across all the different devices that's affected."
9:48 "Every update is calculated against your SLA from its release date to install date. Not from your operational, this is the day I started patching, this is the day I ended patching."
10:48 "We started doing this three months ago, and since then, we've been able to push more patches faster, resolving more vulnerabilities and specifically more known exploits in a faster time frame by doing that."
18:16 "This is also one thing we're really proud of our feature here, is we tie those data sets for you already. We did all the preprocessing. We joined the tables together so you can have one view into one data set."

Categories:
  • » Webinar Library » Ivanti
  • » Data Protection » Backup & Recovery
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Data Protection
  • Compliance & Governance
  • Security Operations
  • Technical Deep Dive
  • Demo
  • Best Practices
  • Patch Management Reporting
  • Compliance Analytics
  • Vulnerability Tracking
  • Dashboard Design
  • Exposure-Based Metrics
  • Deployment Operations
  • CVE Correlation
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Measuring Patch Deployment Success with Analytics

              Upcoming Webinar Calendar

              • 04/08/2026
                11:00 AM
                04/08/2026
                Managing Configuration at Scale Across Group Policy and Intune
                https://www.truthinit.com/index.php/channel/1865/managing-configuration-at-scale-across-group-policy-and-intune/
              • 04/15/2026
                01:00 PM
                04/15/2026
                Service Account Security in the Age of AI: From Legacy Accounts to Agentic Identities
                https://www.truthinit.com/index.php/channel/1866/service-account-security-in-the-age-of-ai-from-legacy-accounts-to-agentic-identities/
              • 04/30/2026
                10:00 AM
                04/30/2026
                Insights from the 2026 Keepit Annual Data Report on SaaS Data Protection
                https://www.truthinit.com/index.php/channel/1868/insights-from-the-2026-keepit-annual-data-report-on-saas-data-protection/
              • 04/30/2026
                01:00 PM
                04/30/2026
                The New Economics of VMware Exit
                https://www.truthinit.com/index.php/channel/1880/the-new-economics-of-vmware-exit/

              Upcoming Events

              • Apr
                08

                Managing Configuration at Scale Across Group Policy and Intune

                04/08/202611:00 AM ET
                • Apr
                  15

                  Service Account Security in the Age of AI: From Legacy Accounts to Agentic Identities

                  04/15/202601:00 PM ET
                  • Apr
                    30

                    Insights from the 2026 Keepit Annual Data Report on SaaS Data Protection

                    04/30/202610:00 AM ET
                    • Apr
                      30

                      The New Economics of VMware Exit

                      04/30/202601:00 PM ET
                      More events
                      Truth in IT
                      • Sponsor
                      • About Us
                      • Terms of Service
                      • Privacy Policy
                      • Contact Us
                      • Preference Management
                      Desktop version
                      Standard version