The energy sector is classified as Critical National Infrastructure (CNI). Unlike a standard enterprise environment where a software bug might lead to lost productivity, a vulnerability in an energy client can have physical consequences.
When an energy client is patched, developers are usually addressing one of several common security flaws:
The patch is deployed to a small percentage of clients to monitor for stability issues.