Apple @ Work Navigating the evolving landscape of software patching with Zach Wasserman from Fleet

In the latest installment of the Apple @ Work podcast, host Bradley Chambers sits down with Zach Wasserman, the co-founder and CTO of Fleet, to dissect the increasingly complex world of software patch management within the Apple ecosystem. As enterprises continue to adopt macOS, iOS, and iPadOS at an unprecedented rate, the strategies required to keep these devices secure against an ever-shifting threat landscape have undergone a radical transformation. This conversation arrives at a critical juncture for IT administrators who are moving away from traditional, reactive maintenance toward proactive, declarative security models.
The Shift Toward Enterprise-Grade Apple Management
The narrative of Apple in the workplace has transitioned from a niche preference to a dominant corporate standard. Historically, IT departments viewed Macs as "unmanageable" compared to their Windows counterparts. However, the maturation of Mobile Device Management (MDM) frameworks and the introduction of Apple Business Manager (ABM) have leveled the playing field. Today, the challenge is no longer about whether Apple devices can be managed, but how efficiently they can be secured.
Zach Wasserman, whose company Fleet specializes in open-source device management and security based on the osquery framework, highlights a significant trend: the convergence of security and IT operations. Patching is no longer just a "janitorial" task for IT; it is a foundational pillar of cybersecurity. As vulnerabilities are discovered more frequently, the window of time between the disclosure of a bug and its exploitation by malicious actors has shrunk from weeks to hours.

Understanding the Patching Paradox
Software patching presents a unique paradox for modern organizations. On one hand, updates are essential for closing security loopholes and improving performance. On the other hand, aggressive patching schedules can disrupt user productivity and, in some cases, introduce new bugs that break mission-critical enterprise software.
Data from recent cybersecurity reports suggests that nearly 60% of data breaches involve vulnerabilities for which a patch was available but not applied. This "patch gap" is the primary target for ransomware and state-sponsored attacks. During the podcast, Wasserman notes that the complexity of patching is exacerbated by the sheer volume of software running on modern machines. It is not just the operating system (OS) that requires attention; third-party applications like web browsers, communication tools, and development environments often harbor more risk than the OS itself.
The Evolution of Apple’s Management Frameworks
To understand the current state of patching, one must look at the chronology of Apple’s management evolution. For years, Apple relied on a "command-and-response" model via MDM. In this scenario, a server would send a command to a device (e.g., "Install this update"), and the device would attempt to execute it. If the device was offline or the user intervened, the command might fail, requiring the server to poll the device repeatedly for status updates.
This changed with the introduction of Declarative Device Management (DDM). DDM represents a paradigm shift where the device becomes autonomous. Instead of waiting for a server to tell it what to do at every step, the device is given a set of "declarations" or rules. For example, an IT admin can declare that all devices must be running macOS 14.5 by a certain date. The device then takes responsibility for notifying the user and ensuring the update happens, reporting back to the server only when the state changes.

Wasserman emphasizes that DDM is a game-changer for patching. It reduces the load on management servers and provides a more reliable way to ensure compliance across thousands of remote devices.
The Role of Visibility and Osquery
A recurring theme in the discussion is the importance of visibility. You cannot patch what you cannot see. Fleet leverages osquery, an open-source tool originally developed by Facebook, which treats an operating system like a high-performance relational database. This allows IT and security teams to query their entire fleet of devices using basic SQL commands.
For instance, an admin can instantly see which devices have a specific version of a vulnerable library or which machines have disabled their firewalls. Wasserman argues that this level of granular visibility is essential for modern patching. Traditional MDM solutions often provide a "delayed" view of device health; osquery provides real-time data that allows for immediate remediation.
Supporting Data: The Cost of Inaction
The urgency of software patching is backed by sobering industry statistics:

- Average Cost of a Breach: According to IBM’s 2023 Cost of a Data Breach Report, the average global cost of a data breach reached $4.45 million, a 15% increase over three years.
- Vulnerability Growth: The National Vulnerability Database (NVD) reported over 25,000 new Common Vulnerabilities and Exposures (CVEs) in 2023 alone, many of which targeted macOS and mobile platforms.
- Time to Patch: The "Mean Time to Patch" (MTTP) for critical vulnerabilities in many organizations still exceeds 60 days, while exploit code is often available within 48 hours of a disclosure.
These figures underscore why experts like Wasserman are pushing for automated, transparent patching workflows.
Navigating the Human Element
One of the most difficult aspects of patching is the human factor. Employees often view software updates as an annoyance that interrupts their workflow. Apple has attempted to mitigate this with "Rapid Security Responses" (RSR), which allow the company to deliver small, critical security fixes without requiring a full OS update or a lengthy reboot.
Wasserman and Chambers discuss the "carrot vs. stick" approach to patch compliance. While some organizations use "nudge" tools to politely remind users to update, others implement strict "forced" updates that lock the device until the patch is applied. The consensus is that transparency—telling the user why the update is necessary and giving them a reasonable window to complete it—leads to higher satisfaction and better security outcomes.
Official Responses and Industry Standards
While Apple does not typically comment on specific third-party management tools, their engineering decisions at events like the Worldwide Developers Conference (WWDC) signal their support for the methods discussed by Fleet and Mosyle. By expanding the DDM protocol to include software update management, Apple is explicitly telling the industry that the future of the Mac in the enterprise is decentralized and policy-driven.

Regulatory bodies are also weighing in. The Cybersecurity and Infrastructure Security Agency (CISA) in the United States has issued several binding operational directives requiring federal agencies to patch known exploited vulnerabilities within specific timeframes. These standards are increasingly being adopted by private sector companies as a baseline for "due diligence" in cybersecurity insurance applications.
Broader Implications for the Future of Work
As the episode concludes, the conversation turns to the broader implications of these trends. The rise of remote and hybrid work has permanently dissolved the traditional "office perimeter." In this new world, the device itself is the perimeter.
If a device is unpatched, it becomes a weak point that can compromise the entire corporate network, regardless of where the employee is sitting. Consequently, software patching has moved from the basement of the IT department to the boardroom. Executives now recognize that patch compliance is a key metric of organizational health.
The partnership between platforms like Mosyle (which provides a unified Apple management and security layer) and tools like Fleet (which provides deep visibility and open-source flexibility) illustrates the ecosystem required to manage modern workforces. By automating the mundane aspects of patching, IT professionals are freed up to focus on strategic initiatives that drive business value.

Analysis of the Path Forward
The analysis provided by Zach Wasserman suggests that we are entering an era of "Invisible Security." The goal for the next five years is to make the patching process so seamless and automated that neither the IT admin nor the end-user has to think about it.
Key takeaways for organizations include:
- Adopt Declarative Models: Move away from legacy MDM commands in favor of DDM to ensure higher reliability in update delivery.
- Prioritize Third-Party Apps: Don’t just focus on the OS; ensure that browsers and developer tools are included in the automated patching cycle.
- Invest in Visibility: Use tools like osquery to get a real-time pulse on the security posture of the fleet.
- Balance Security and UX: Use transparent communication and RSRs to minimize user friction while maintaining a high security bar.
As Apple continues to innovate with its hardware and software, the tools used to manage them must evolve in lockstep. The insights from Fleet and the Apple @ Work series provide a roadmap for navigating this transition, ensuring that as the landscape of software patching evolves, enterprises are not just keeping up, but staying ahead of the curve.







