Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Ivanti: How Microsoft's Patch Tuesday Transformed Security Updates

Ivanti
07/03/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


I think there's a couple of things that those of you who have been in the patch management space for a while might remember. Eric, back in the day, was often referred to as Mr. Patch. If you would have emailed secure at Microsoft.com, Eric would have been the person responding to that. This is back when, I mean, really patches were just hot fixes that were being created on the fly by Microsoft to fix bugs in the operating system at that point. So, Eric, what was patch management like in the beginning? Well, I'm glad I'm retired now since the patch management problem has been solved, but we can go back and talk about the beginning of Patch Tuesdays. I was at the Microsoft Security Response Center, secure at Microsoft.com. To be most responsive to customers, we wanted to release the patches, the security patches, as quickly as possible. So, as soon as a patch was done and the product team blessed it, we would go ahead and issue the security bulletin with the corresponding patch. That could be on a Friday afternoon. It could have been on a Monday morning. We released one patch years ago. It was an Exchange server patch. Moments after releasing it, a bug was identified in the patch. So, we pulled the patch down after we updated the security bulletin to say we were pulling the patch down. We released the patch a second time that same day and updated the security bulletin. A few hours later, the team identified that there was still a bug inside of that patch. So, they pulled that patch down again and released it a third time that same day. Again, this was in this press to get the patches released as soon as possible. It didn't work out so well in that case because we released it three times in a day. We shortly thereafter moved to a weekly patch process. That was Patch Tuesday. It was every Tuesday. That helped customers because you could then plan when security bulletins and patches would be coming out, would be on Tuesday afternoons. The patches had to be completed some number of days prior to that time where it could then be thoroughly vetted and tested and then released on Tuesday. We found that that cut down on the recurrence of reissuing patches and it brought the quality up. At some point after I left MSRC, that weekly process morphed into a monthly process to the Patch Tuesday that we know today.

TL;DR

  • Early Microsoft patches were released immediately upon completion, sometimes on Friday afternoons or Monday mornings with no predictable schedule.
  • A notorious Exchange server patch was released, pulled, and reissued three times in a single day due to bugs discovered after each release.
  • Microsoft transitioned from ad-hoc releases to weekly Patch Tuesday, then eventually to the monthly cycle used today, dramatically improving patch quality.

Summary

This interview features Eric, a former Microsoft Security Response Center engineer known as 'Mr. Patch,' reflecting on the origins of modern patch management. He recounts the chaotic early days when security patches were released immediately upon completion—sometimes multiple times in a single day due to bugs. A particularly memorable Exchange server patch was pulled and reissued three times within hours, highlighting the risks of prioritizing speed over quality. This experience drove Microsoft to adopt a weekly release cadence, which eventually became the monthly Patch Tuesday cycle still used today. The shift allowed for proper vetting and testing, significantly improving patch quality and giving IT administrators predictable schedules for planning updates. Eric's firsthand account provides valuable historical context for understanding why structured patch release processes became essential to enterprise security operations.

Chapters

0:00 - Introduction and Eric's Legacy
0:51 - Early Patch Release Chaos
1:32 - The Exchange Server Incident
2:14 - Birth of Patch Tuesday

Key Quotes

0:23 "Eric, back in the day, was often referred to as Mr. Patch. If you would have emailed secure at Microsoft.com, Eric would have been the person responding to that."
1:42 "We released the patch a second time that same day and updated the security bulletin. A few hours later, the team identified that there was still a bug inside of that patch."
2:39 "We found that that cut down on the recurrence of reissuing patches and it brought the quality up."

FAQ

Why did Microsoft move from immediate patch releases to Patch Tuesday?

The rush to release patches as quickly as possible led to quality problems, including instances where patches had to be pulled and reissued multiple times in a single day. Moving to a scheduled release cycle allowed time for thorough vetting and testing, which significantly reduced the need to reissue patches and improved overall quality.


Categories:
  • » Webinar Library » Ivanti
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Vulnerability Management
  • Best Practices
  • Interview
  • patch management history
  • Microsoft Security Response Center
  • Patch Tuesday origins
  • security bulletin process
  • hot fix releases
  • patch quality assurance
  • enterprise update scheduling
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Ivanti: How Microsoft's Patch Tuesday Transformed Security Updates

              Industry Events (Sponsor Hosted)

              • Oct
                13

                Ensuring Compliance Through Audit Evidence: From CJIS to FERPA

                10/13/202601:00 PM ET
                • Oct
                  13

                  Your Questions Answered: Insights on DatasecAI 2026

                  10/13/202602:00 PM ET
                  • Oct
                    15

                    Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                    10/15/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 10/13/2026
                      01:00 PM
                      10/13/2026
                      Ensuring Compliance Through Audit Evidence: From CJIS to FERPA
                      https://www.truthinit.com/index.php/channel/2159/ensuring-compliance-through-audit-evidence-from-cjis-to-ferpa/
                    • 10/13/2026
                      02:00 PM
                      10/13/2026
                      Your Questions Answered: Insights on DatasecAI 2026
                      https://www.truthinit.com/index.php/channel/2141/your-questions-answered-insights-on-datasecai-2026/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 10/20/2026
                      11:00 AM
                      10/20/2026
                      Harnessing Data Governance for AI with Cyera and Snowflake
                      https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                    • 10/27/2026
                      01:00 PM
                      10/27/2026
                      The HUMAN Experience: Real-Time Insights into Page Intelligence
                      https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Leveraging CISA’s Zero Trust Maturity Model for an AI-Driven Landscape
                      https://www.truthinit.com/index.php/channel/2149/leveraging-cisas-zero-trust-maturity-model-for-an-ai-driven-landscape/
                    • 11/05/2026
                      01:00 PM
                      11/05/2026
                      HUMAN Dialogue: Redefining Authentic Trust in the Agentic Internet
                      https://www.truthinit.com/index.php/channel/2160/human-dialogue-redefining-authentic-trust-in-the-agentic-internet/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version