HACKED24, Autonomous Enterprise IT

Nobody owns the update chain, and that is where the money goes

Updates now arrive daily across 9 layers, from firmware to SAP. The cost sits in the dependencies nobody owns, and AI agents can run that chain under clear rules.

David Lorenz
Oct 8, 20267 min read
Stack of 9 thin frosted glass hexagon plates, one lit in indigo to cyan, on a light grey backdrop

Key points

  • Updates now arrive daily across 9 layers, from notebook firmware to SAP, each with its own vendor, tool and team.
  • The damage rarely comes from a single update. It comes from the dependencies between layers that nobody owns.
  • Existing tools such as Intune, Jamf or Tanium are good inside their layer, and an AI agent layer on top coordinates them across the whole chain.
  • Measure the cost of 2 update cycles first, then let agents run one scope with clear rules.

Patch Tuesday is history. A mid-sized company today gets updates every day: Windows and macOS, iPhones and Android devices, notebook firmware, Microsoft 365 Apps, browsers, the security agent on every endpoint, the POS software in the stores, plugins nobody remembers installing, SaaS vendors changing their APIs, and SAP with its own release rhythm. Each one comes from a different vendor, on a different schedule, owned by a different team.

Most IT organisations still run update management as a list of separate jobs. That is where the time and the money go. For the board this is a cost and risk question, and AI agents change the answer.

Every layer has an owner, nobody owns the chain

Single updates rarely cause the damage. The damage comes from dependencies nobody has mapped. These are typical patterns in a mixed environment:

  • A Windows cumulative update changes a print driver, and the receipt printers in the stores stop working. The POS software was never part of the test.
  • A notebook vendor pushes a BIOS update through its own tool, and BitLocker asks for the recovery key on Monday morning.
  • A SaaS vendor retires an API version with a notice in a developer blog. The interface into SAP fails quietly, and Finance notices at month-end.
  • A browser update disables an old extension that a business application depends on. Nobody knew the extension existed.
  • An Office add-in for the CRM is not compatible with the new Microsoft 365 Apps build, and Sales cannot log calls.

The extreme case is a vendor update that hits everything at once. In July 2024 a faulty CrowdStrike update affected an estimated 8.5 million Windows devices, according to Microsoft. Every team involved had its own layer under control. Nobody owned the chain.

The cost sits in 4 places, and none of them is a budget line

Update management is spread across the service desk, the client team, the server team, application owners, SAP basis, external providers and the on-call rota. That is why its cost is underestimated.

  • People. Reading release notes, testing, planning change windows, watching rollouts and chasing devices that did not update. Every month, for every layer, often on evenings and weekends.
  • Downtime. A failed update at the POS costs revenue by the hour. A broken SAP interface can cost a month-end close.
  • Risk window. The days between a security patch being released and it being installed everywhere. Attackers measure that window in hours.
  • Audit. NIS2, DORA and cyber insurers ask for evidence: what was patched, when, and what is still open and why. Collected by hand, that evidence costs time again.

One more cost never gets counted: the updates that are postponed because nobody has time. Windows 10 reached end of support on 14 October 2025. Mainstream maintenance for SAP ECC on EHP6 and later ends at the end of 2027. Postponing is also a decision, usually the most expensive one.

Your tools are good at their layer and stop there

There is no shortage of tools. Most companies already pay for several of them, and each one does its own job well:

Layer Typical tools Where they stop
Windows clients and servers Microsoft Intune with Windows Autopatch, Configuration Manager Microsoft updates only. Whether business applications still work is your problem.
macOS, iOS, iPadOS Jamf, Kandji, Intune Enforce the OS version, know nothing about the apps on top
Android and rugged devices Intune, Workspace ONE, Android Enterprise Device level only, scanner and warehouse apps are separate
Third-party applications Patch My PC, ManageEngine, Automox, NinjaOne Cover the catalogue of common apps. Line-of-business, POS and in-house software fall out.
Notebook firmware and drivers Dell Command Update, HP Image Assistant, Lenovo Update Retriever One vendor each, own schedule, own console
Large and mixed estates Tanium, Ivanti Strong visibility and deployment at scale, still per device and not per business process
SAP SAP Solution Manager, SAP Cloud ALM, Maintenance Planner SAP only, the interfaces to the rest are outside
SaaS and APIs Mostly none: changelogs, status pages, deprecation e-mails Nobody watches systematically
Plugins and add-ins Browser policies, Office add-in central deployment Inventory is usually incomplete

Several of these vendors add AI features, and the AI stays inside their product. Intune does not know that the SAP interface depends on a SaaS API. Jamf does not care whether the POS printer driver survived the last Windows update.

An AI agent layer sits above the tools you already have and operates them through their APIs. It keeps 1 inventory across all layers, including which system depends on which. It reads every vendor source, also the ones that arrive by e-mail or sit in a developer blog. It tests business processes instead of devices: a sale on the till, an order into SAP, an invoice out of the CRM. And it produces 1 audit trail for the whole estate instead of 9 exports from 9 consoles. The tools stay. Replacing them would be expensive and pointless.

Agents run the cycle, people set the rules

Take a normal week. Microsoft ships its monthly update, Apple a security fix for iOS, the POS vendor a new build, and a SaaS vendor announces that an API version will be switched off in 90 days.

  1. Triage. The agents read all 4 announcements, match them against inventory and dependency map, and rate them: security-critical, touches a business process, can wait.
  2. Plan. The POS build goes first to 2 pilot stores. The Windows update waits until the POS test is green. The API change becomes a ticket for the integration owner, with the deadline.
  3. Test. In the pilot rings the agents run the defined process tests and read logs, crash reports and service status. Go or no-go follows criteria the business has set.
  4. Rollout. Ring by ring, through Intune, Jamf, the POS vendor’s tool or SAP transport management. If a ring shows problems, the rollout stops and is rolled back where possible.
  5. Cleanup and report. Devices that did not update are fixed automatically. What cannot be fixed goes to a person with the diagnosis attached. Change records and audit evidence are written along the way.

Some decisions stay with people. Management sets how fast security patches must land and which systems may lag. SAP production, store systems on a Saturday and anything regulated are updated only after an explicit sign-off. When a vendor update conflicts with a business process, a person decides whether to wait, work around or escalate. Without these rules, automation only breaks things faster.

Measure update management before you automate it

How much time and money agents save depends on the estate, so we do not promise percentages before we have seen the numbers. Most companies cannot answer the questions below today, and that alone shows where the money goes.

Question for the board What it reveals
How many person-hours does 1 update cycle cost, across all teams and providers? The real labour cost, spread over many budgets
How many change windows run outside business hours per month? Overtime, on-call load and staff turnover risk
How many days until a critical security patch is on 95% of devices? The open risk window
How many incidents last year were caused by an update? Cost of downtime and failed rollouts
Which updates are postponed right now, and since when? Technical debt that becomes a project later
Who owns the dependencies between POS, SAP, SaaS and the clients? Whether anyone owns the chain at all

What to do now

  1. Board: ask the 6 questions above in the next IT review and name 1 owner for the update chain.
  2. CIO: pick 1 scope with high volume and visible pain, usually end user devices plus the 2 or 3 business processes that hurt most when they break.
  3. IT Operations: map layers and dependencies for that scope and measure 2 update cycles as a baseline.
  4. CIO and business owners: agree the rules: rings, process tests, sign-off points, rollback.
  5. IT Operations: let agents run the next cycles with read access first, compare with the baseline, then extend to servers, SaaS interfaces and SAP.

This is how we run update management at HACKED24: agents do the routine around the clock across all layers, and 1 senior partner answers for the result. Most engagements start with an Executive IT & AI Review that puts numbers on the current update process and shows where agents pay off and where they do not. Book a call or see our engagement models.

David Lorenz

Founder and Managing Partner of HACKED24. More than 20 years in enterprise IT architecture, security and operations.

Want to see what this means for your IT?

Every enquiry is answered personally, usually on the same business day.