// 9TO5MAC — MOBILE & WEB
Apple @ Work: The three prongs of software updates in the AI era
Apple @ Work is exclusively brought to you by Mosyle, the only Apple Unified Platform. Mosyle is the only solution that integrates in a single professional grade platform all the solutions necessary to seamlessly and automatically deploy, manage, and protect Apple devices at work. Over 45,000 organizations trust Mosyle to make millions of Apple devices work ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple.
For my entire IT career, software updates have operated on a predictable schedule. IT administrators have been conditioned to build workflows around quarterly point releases or monthly patching cycles (Patch Tuesday). However, as AI tools become very proficient at automatically discovering software vulnerabilities, threat actors are moving faster than ever before. With that being said, I very much miss 18th-month macOS/OS X releases.
We are rapidly entering an era in which software updates will look less like traditional operating system updates and more like continuous cloud updates. To survive this shift, IT teams must understand the three prongs of modern patch management.
About Apple @ Work: Bradley Chambers has been an Apple IT admin since 2009. Through his experience deploying and managing firewalls, switches, a mobile device management system, enterprise grade WiFi, 1000s of Macs, and 1000s of iPads, Bradley will highlight ways in which Apple IT managers deploy Apple devices, build networks to support them, train users, share stories from the trenches of IT management, and ways Apple could improve its products for IT departments.
The first pillar of this new world has to center completely on user experience and education. End users will have to accept a much more aggressive update approach. For years, users have treated operating system updates as optional annoyances that can be deferred until the last possible minute. In an era where zero-day vulnerabilities can be weaponized in just a few hours, that behavior is a massive liability. We might be entering an era in which zero-day issues occur almost monthly.
IT departments must prepare their workforces for frequent, mandatory interruptions. Much like applications such as Zoom or web browsers, which update constantly in the background, operating systems will require similar frequency of updates. Employees must understand that short-term disruption to their immediate productivity is a necessary trade-off to prevent data breaches for their organization.
The second prong places an immense operational burden directly on IT deployment teams. Historically, an administrator might take 90 days to test a major operating system update against corporate applications before pushing it to production fleets. That timeline is completely dead, and I think 90 days might turn into 9 days or even 9 hours.
Testing windows must shrink from months to weeks, days, or even hours, depending on the severity of the threat found. IT teams will need to lean heavily on device management tools to enforce compliance rules instantly. If a critical patch drops, administrators might need to prepare to automatically lock any device that remains unpatched by the end of the week or the end of the day, forcing the update before the user can resume work.
There might also need to be a distinction for different classes of employees as well. Developers with privileged access might need to see shorter windows than those in roles without it.
The final prong lies squarely on the shoulders of the operating system vendors themselves. Google had a massive advantage when designing ChromeOS because they built a cloud-first platform from the ground up to support silent, background updates with near-instantaneous reboots. I manage 100s of Chromebooks, and it’s incredible how they stay up to date. Apple and Microsoft are carrying decades of legacy desktop architecture originally optimized for physical media instal