If y’all think you’re pissed off and tired, try approaching it from the systems/architect side. It’s been “happy $day, vendor just dumped a mountain of updates, have fun picking out which you need. p.s. update all the images with those patches immediately” for years. (Which is even fucking worse if you have any sort of regulatory scrutiny.)
Which of those patches is Oracle going to say voids support or breaks production? 
Did the vendor document any of it adequately? 


Well at least they told you if a reboot’s required, right? 
It’s fine, I’m sure we can schedule it quickly and easily. 
And it’s all down to a fundamental lack of craft and giving a shit. Not skill - craft. Notice how all of these problems are not “oh yeah if you jiggle the bits precisely this way when precisely these conditions happen you can sometimes fail through a handler” or “… crap, I put the order wrong 10 years ago” and instead keep coming up as “basic logic bug”?
Lack of craft. This is what happens when you have an entire generation of people who think they are god’s gift to coding, and have no need to look at history or listen to older programmers.
These are not the result of unexplained, novel, or unknown behaviors. It’s quite simply people who decided they didn’t need to study or think because they knew better and everything they were doing was new and novel. (It is not, and in fact, is why most reasonable operating systems don’t co-mingle.) It’s why ../ is the meme that will never die, despite everyone knowing better in 1995. You know, back when /etc/passwd actually contained passwords and you could telnet in.
And when this has the oh so predictable results? The people responsible don’t give a shit. Companies certainly don’t - why should or would they? They’re never going to suffer any real consequences. The people who wrote it don’t give a shit. “I made an oopsie, it’s fine, just patch it.” It doesn’t cost them more than maybe 30 minutes writing a patch. It’s trivial! Maybe if it’s colossally embarrassing, they have to go work for somebody else.
It’s the normalization of failure; the standardization of unsafe operation; setting the baseline as this_is_fine.jpeg except the monitor displaying it is actively on fire. It is not the question people think it is.
“How do we deal with being unable to keep up with patching?” is entirely the wrong question and wrong framing.
The actual question that is being asked is basically “what self-flagellation can we perform indefinitely as penance for using shit that isn’t fit for purpose?”
Yes, that should sound exactly as unappealing and borderline insulting as it does.
The question we should be asking as an entire industry - not just security practitioners, fucking everyone - is: “how do we hold these assholes that have made reliability a mystery, security a joke, and any attempt to protect systems a true Sisyphean feat responsible for it?” Especially the executives that insist they take security very very seriously.
Run this by an executive: what if instead of hiring a new batch of security professionals and incident responders and crisis communication consultants every year because the vendor keeps screwing up, you stop doing business with a vendor that is directly responsible for seven digits of HR cost and climbing? What if when the same vendor keeps doing the same thing and making the same meaningless apologies and making the same mistakes year after year after year and costing you millions, you just stop doing business with them? Hell, maybe you even sue for a refund on breach of contract or misleading you as to their capabilities or whatever!
Imagine if everyone after reading the ‘root cause’ from ClownStrike said “you guys could not more obviously be 
, you clearly lied about your own internal processes, so get the fuck out.” ‘But, but then all those people lose their jobs when George yanks the plug so he can cash out!!’ Yeah, and? How many millions of dollars did it cost you trying to recover from that? Everyone who said “it’s okay, we all make mistakes” both failed to comprehend the RCA and is also eager to reward the dog that’s biting them. It’s fine, I’m sure giving Fido another pound of bacon while he rips open my artery will teach him to stop doing that.
A mistake is when you have a - instead of a -> somewhere in 2M LOC, the unit test couldn’t possibly catch it, and if you hit things just right any user can panic() the box. ‘I don’t need bounds checking’ is a complete lack of craft and caring. ‘It’s no big, everyone can just patch it’ is a complete lack of craft and caring. ‘We had another ../ but it’s fine, here’s a patch’ - you get the idea. It’s not people being better at finding bugs, it’s not better tooling. It’s worse and worse crap being shoveled out the door, or just the same crap from 10 years ago without having learned anything, or just saying “what’re they gonna do, buy from the other guy?! LOL!”
We are not the little Dutch boy with his finger in the dike. We’re not Superman stopping a bus from hitting that adorable puppy. At this point, we’re a guy who hasn’t slept in 6 months or had any sustenance but Monster(R) energy drinks wearing absolutely nothing but a pair of swim floaties insisting we can hold back a literal tsunami of sewage. (Please feel free to draw this image.) Especially as, hey look, they found a way to make even more and worse sewage! How grand. Which is why this is, god, the eighth? Ninth? Time I’ve had the ‘well how can we cope with vendors being shit?’ go-round. (It ain’t just security.) And you can guess how those all went by browsing your way to Palo’s or F5’s or Cisco’s or Red Hat’s or IBM’s or (your vendor here)'s security advisory page. Or product defect page. Or hot knowledge base topics. Or APARs. Or ‘hey Surveillance Machine, search for (your vendor here) sucks.’ Or just look at their share price.
So yeah. I hold that the question isn’t what to replace a broken process with. It absolutely should not be any of our job or responsibility to cover for the same repeated fuck ups, same vendors, same Bat-channel, same Bat-fucking-time. The question is how to break what is basically a cycle of abuse.
And I can tell you that I’ve thrown vendors out on their ass when it became clear they weren’t going to get it together. And so far the total result of that’s been two acquired by Oracle, and one Symantec merger-demerger. So if anyone’s got the right answer, it doesn’t appear to be me. But if people don’t start figuring out what I got wrong and getting it right, burnout with a side of nervous breakdown’s going to be the second most widespread thing in the industry, right behind self-destructive existential nihilism.
Yeah. This stuff puts me in a bit of a mood. (Can’t imagine why. Hey, check out this picture of Anna Kournikova I sent you on Discord.)
(edit: curse you, Discourse formatting.)