Most successful attacks on small and medium businesses do not use anything clever. They use a known weakness in software that has had a fix available for weeks or months. Patch management is the work of making sure those fixes are installed everywhere on time and proving it. This guide explains what needs patching, how quickly and a simple process that works for a business of 10 to 500 staff.
The short answer
Know every device and application you have, install security updates on a schedule set by how exposed each system is, test before rolling out widely, check what failed and keep the reports. Internet facing systems come first, because they are what attackers scan for.
What needs patching
- Operating systems on every laptop, desktop and server.
- Microsoft 365 apps, web browsers and their extensions, email clients and PDF readers, which attackers target most.
- Line of business applications, accounting, practice management and design software.
- Firewalls, VPNs, switches and Wi-Fi, whose firmware does not update itself and which face the internet.
- Printers, phone systems and building systems connected to your network.
- Phones and tablets that access company email and files.
How quickly: the Essential Eight timeframes
Patching applications and patching operating systems are two of the eight strategies in ASD’s Essential Eight. At Maturity Level One:
| What | Scan for missing patches | Install patches |
|---|---|---|
| Internet facing services, servers and network devices | At least daily | Within 48 hours if critical or a working exploit exists, otherwise within two weeks |
| Office apps, browsers and extensions, email clients, PDF software and security products | At least weekly | Within two weeks |
| Workstations, internal servers and internal network devices | At least every two weeks | Within one month |
| Anything the vendor no longer supports | Removed or replaced |
Levels Two and Three tighten how often you scan and how quickly you patch. Our Essential Eight checklist lists every requirement.
A patch process that works
- Inventory. Use an automated tool to find every device and application at least every two weeks. You cannot patch what you do not know about.
- Scan. Check for missing updates against an up to date vulnerability database, on the schedule above.
- Test. Send updates to a small pilot group first, usually IT and a few willing staff, and wait a few days before everyone else.
- Deploy. Roll out to everyone outside business hours, with restarts scheduled so work is not lost.
- Check. Look for devices where updates failed, laptops that have been offline and anything that needs a manual fix.
- Report. Keep a monthly report of patch status per device. It is your evidence for insurers, clients and assessors.
- Handle exceptions. Record any system that cannot be patched, why, what protects it in the meantime and when it will be replaced.
Urgent patches
When a critical weakness is being used by attackers, waiting for the normal cycle is the bigger risk. Firewalls, VPNs and remote access systems are the usual examples. A good process has a fast lane: assess the same day, patch or apply the vendor’s workaround within 48 hours and check nothing else was touched.
Unsupported software
Software past its end of support gets no more security fixes. Windows 10 is the current example: support ended in October 2025, and business devices can keep receiving security updates only through extended security updates, which in most cases are paid and end in October 2028. See our article on Windows 10 end of life.
Tools
Businesses of this size usually patch through a remote monitoring and management platform, Microsoft Intune or both. The tool matters less than the process around it: someone has to read the reports, chase the failures and patch the network gear that the tools do not reach. See device management.
Patching is not the whole answer
Patching closes known holes. It does nothing about a stolen password or a weakness nobody has found yet. It works alongside multi-factor authentication, endpoint detection watched 24/7 and protected backups, which is how most ransomware attacks are stopped.
Where Austin Technology fits
Patching of operating systems, Microsoft 365 apps, browsers and common applications, with monthly reports, is included in our managed IT services, and firmware on the firewalls and network gear we manage is kept current. Call us on 1300 787 429.
Patch management questions
What is patch management?
The process of finding, testing, installing and checking software updates across every computer, server, network device and application in the business, so known security holes are closed before attackers use them.
How quickly should patches be installed?
For the Essential Eight at Maturity Level One: critical patches for internet facing services and devices within 48 hours, other patches for them within two weeks, office apps, browsers and PDF software within two weeks, and workstation and internal server operating systems within one month.
Do automatic updates count as patch management?
They are part of it. Patch management adds the parts automatic updates miss: knowing every device and application you have, checking the updates installed, catching the ones that failed and covering firewalls, switches and other gear that does not update itself.
Can a patch break something?
Occasionally. That is why updates go to a small test group first and wait a few days before going to everyone, except urgent security fixes, where the risk of waiting is greater than the risk of the patch.
What about software that is no longer supported?
It gets no more security patches, so it should be replaced. The Essential Eight requires unsupported operating systems, browsers, office apps and internet facing services to be removed or replaced.
How do we prove we are patched?
With reports showing each device, its operating system and application versions, which updates are installed and when. Insurers, clients and Essential Eight assessors all ask for them.


