How should a small business patch its software?
Automatically and centrally, with a defined window for how quickly patches go on, applied to applications as well as operating systems, and verified with a report rather than assumed. Relying on individual staff to click update reminders is not a patching strategy, and it is the arrangement most small businesses actually have.
Patching is unglamorous and it is where quiet risk accumulates, because the attacks it prevents are not clever. An attacker does not need a new technique when a known hole with a published fix is sitting unpatched on a machine somewhere. That is the cheapest possible way in, it is entirely automated, and it is why the Essential Eight lists patching applications and patching operating systems as two of its eight controls rather than folding them together.
The distinction between the two matters more than it sounds. Most businesses have some handle on Windows updates, because the operating system nags loudly and reboots eventually. Applications are where the gap lives: the PDF reader, the browser, the compression tool, the accounting client, the design software, the dozen utilities that accumulated over five years. Each updates on its own schedule, or not at all, and none of them nags with any authority. If you patch only the operating system, you have covered the noisiest half of the problem.
A workable approach for a small business has four parts. First, know what you have, since you cannot patch software you do not know is installed; a management tool inventories it, and the inventory is usually the moment someone discovers the machine still running something abandoned in 2019. Second, automate the routine, because anything requiring a human to remember will be missed in a busy month. Third, set a cadence with a number attached: critical patches within a stated window, routine ones on a regular cycle, and write the numbers down so there is something to measure against. Fourth, verify, with a compliance report showing which machines are current and which are not.
That fourth step is the one that converts patching from an intention into evidence. Every Essential Eight assessment, insurer questionnaire and serious tender will ask, in some form, how current your systems are, and the answer that carries weight is an export with dates on it. A verbal assurance that updates are on carries none, and it is frequently wrong: laptops that have been off for a fortnight, a machine excluded from the tool years ago, a server nobody wants to reboot during business hours.
The awkward cases deserve honesty because every business has one. The line-of-business application that the vendor certifies only against an older platform. The machine attached to a piece of equipment that cannot be touched. The server that cannot be rebooted during trading hours. These are real, and the answer is not to pretend or to give up, but to isolate, document and plan: restrict what the machine can reach, record why the exception exists and who approved it, and put an end date against it. An exceptions register is a legitimate part of a mature patching posture; an undocumented exception is just a gap.
Third-party patching is the capability worth asking your provider about by name, because it is what separates real coverage from operating-system-only coverage. Tools such as Intune, along with the patching engines built into most managed service platforms, can push updates for the common third-party applications, the browsers, the readers, the compression and media tools, on the same cadence as Windows itself. If your provider cannot tell you which third-party applications they patch, the honest assumption is that the answer is none of them.
On reboots, which is where patching quietly fails in practice: patches installed but not applied are patches not applied. A machine that has downloaded updates and not restarted for three weeks is still vulnerable, and staff will defer a restart indefinitely if allowed to. A sensible policy sets a maximum deferral with a forced restart outside working hours, which annoys people once and then stops mattering.
For most small businesses this is bought rather than built, because the value is in someone watching the report rather than in the tooling itself. Our plans include managed patching across operating systems and applications, from $79 to $199 per user per month depending on the Essential Eight tier, precisely so the cadence and the evidence exist without anyone in the business having to remember. If you want to know how far behind your machines actually are today, the Cyber Security Scorecard measures it free, or call 1800 456 567.
Make patching something you can prove
We patch operating systems and applications on a managed cadence and give you the compliance report, which is what an assessor asks for.
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business