The cycle begins on the day the notes are published, that is the second Tuesday of the month. We review the published security notes and make an initial separation between items relevant to the supported environments and those that do not apply.
We then carry out the impact assessment. Notes are mapped to the client's specific systems, versions and configurations, and for critical items we verify the conditions under which the vulnerability can be exploited.
On this basis we prepare a rollout plan split into immediate actions, items for the next service window, and handling on the planned cycle.
Patches are applied first in non-production environments, then in production during an agreed window, with regression testing scope matched to process criticality.
The cycle closes with a report: what was analysed, what was applied, what was deferred and on what basis. We comment on the same Patch Day publicly in our "Security Tuesday with SNOK" series.