Security & RansomwarePublished January 11, 2022

Log4j Vulnerability: What Small Businesses Should Know

A critical vulnerability in a widely used logging library has put a huge range of software at risk.

A critical vulnerability in Log4j, a logging library used inside an enormous number of business applications and cloud services, was disclosed last month and continues to be actively exploited. Most small businesses don't use Log4j directly, but you very likely rely on software built by other companies that does.

The practical step for most small businesses is making sure any software you use — whether self-hosted or cloud-based — is kept fully up to date, since vendors have been racing to patch affected products. Reach out to any software vendor you're concerned about and ask directly whether they've been affected and patched.

This incident is a good example of why patch management matters even for software you didn't write yourselves — vulnerabilities in the components underneath your everyday tools can affect you just as much as a vulnerability in the tools themselves.

Prefer to have this handled for you?

Our team can take care of this and everything else on your IT plate — no obligation to find out how.