All insights

How should a small business patch its software?

5 min readBy Brendon Whiting, Founder · 13 November 2025

Automatically and centrally, with a defined window for how quickly patches go on, applied to applications as well as operating systems, and verified with a report rather than assumed. Relying on individual staff to click update reminders is not a patching strategy, and it is the arrangement most small businesses actually have.

Patching is unglamorous and it is where quiet risk accumulates, because the attacks it prevents are not clever. An attacker does not need a new technique when a known hole with a published fix is sitting unpatched on a machine somewhere. That is the cheapest possible way in, it is entirely automated, and it is why the Essential Eight lists patching applications and patching operating systems as two of its eight controls rather than folding them together.

The distinction between the two matters more than it sounds. Most businesses have some handle on Windows updates, because the operating system nags loudly and reboots eventually. Applications are where the gap lives: the PDF reader, the browser, the compression tool, the accounting client, the design software, the dozen utilities that accumulated over five years. Each updates on its own schedule, or not at all, and none of them nags with any authority. If you patch only the operating system, you have covered the noisiest half of the problem.

A workable approach for a small business has four parts. First, know what you have, since you cannot patch software you do not know is installed; a management tool inventories it, and the inventory is usually the moment someone discovers the machine still running something abandoned in 2019. Second, automate the routine, because anything requiring a human to remember will be missed in a busy month. Third, set a cadence with a number attached: critical patches within a stated window, routine ones on a regular cycle, and write the numbers down so there is something to measure against. Fourth, verify, with a compliance report showing which machines are current and which are not.

That fourth step is the one that converts patching from an intention into evidence. Every Essential Eight assessment, insurer questionnaire and serious tender will ask, in some form, how current your systems are, and the answer that carries weight is an export with dates on it. A verbal assurance that updates are on carries none, and it is frequently wrong: laptops that have been off for a fortnight, a machine excluded from the tool years ago, a server nobody wants to reboot during business hours.

The awkward cases deserve honesty because every business has one. The line-of-business application that the vendor certifies only against an older platform. The machine attached to a piece of equipment that cannot be touched. The server that cannot be rebooted during trading hours. These are real, and the answer is not to pretend or to give up, but to isolate, document and plan: restrict what the machine can reach, record why the exception exists and who approved it, and put an end date against it. An exceptions register is a legitimate part of a mature patching posture; an undocumented exception is just a gap.

Third-party patching is the capability worth asking your provider about by name, because it is what separates real coverage from operating-system-only coverage. Tools such as Intune, along with the patching engines built into most managed service platforms, can push updates for the common third-party applications, the browsers, the readers, the compression and media tools, on the same cadence as Windows itself. If your provider cannot tell you which third-party applications they patch, the honest assumption is that the answer is none of them.

On reboots, which is where patching quietly fails in practice: patches installed but not applied are patches not applied. A machine that has downloaded updates and not restarted for three weeks is still vulnerable, and staff will defer a restart indefinitely if allowed to. A sensible policy sets a maximum deferral with a forced restart outside working hours, which annoys people once and then stops mattering.

For most small businesses this is bought rather than built, because the value is in someone watching the report rather than in the tooling itself. Our plans include managed patching across operating systems and applications, from $79 to $199 per user per month depending on the Essential Eight tier, precisely so the cadence and the evidence exist without anyone in the business having to remember. If you want to know how far behind your machines actually are today, the Cyber Security Scorecard measures it free, or call 1800 456 567.

Make patching something you can prove

We patch operating systems and applications on a managed cadence and give you the compliance report, which is what an assessor asks for.

Frequently asked questions

It depends on severity and on your target maturity level, and the principle is that critical vulnerabilities in internet-facing systems are measured in days rather than months. Work from the current Essential Eight maturity model for the exact windows, set a cadence you can actually meet, and measure against it rather than adopting a number you will quietly miss.

For a small business, generally no for routine operating system and application updates, because the risk of delay now outweighs the risk of a bad patch. Where you do want a staged rollout is anything touching a line-of-business system: patch a pilot group first, confirm the critical application still works, then release to everyone.

That is not a patching problem, it is a replacement decision, and it should be treated as urgent rather than deferred. Unsupported software accumulates known holes that will never be closed, and both the Essential Eight and any insurer's questionnaire treat its presence as a serious finding. Plan the upgrade and document the dates.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.