Insights › Essential Eight

Patch Management Made Simple: A Monthly Routine

Dark navy banner reading Patch Management Made Simple under an Essential Eight label, with a SecurityScore.com.au footer

Almost every business owner knows they should keep their software up to date. The problem is rarely a lack of good intentions. It is that updates arrive at awkward moments, a pop-up gets dismissed during a busy morning, and one unpatched laptop quietly becomes the weak point an attacker walks through months later. Patching is one of the cheapest and most effective things you can do, yet it is also one of the easiest to let slide.

The fix is not more willpower. It is a routine: a short, repeatable set of checks you run on the same day each month so nothing depends on anyone remembering. This guide walks through a simple monthly patch routine built for a small business that does not have a dedicated IT team, and explains how quickly the Australian Signals Directorate expects patches to be applied.

What patch management really means

A patch is a small update that a vendor releases to fix a problem in their software. Many patches add features or fix bugs, but the ones that matter most for security close holes that attackers have found. When a vendor publishes a security patch, they often describe the flaw it fixes, which effectively hands criminals a map of what to attack on any system that has not updated yet. That is why speed matters.

Patch management is simply the practice of staying on top of those updates across everything your business runs: operating systems like Windows and macOS, the applications your team uses every day, the firmware on your router, and the plugins and extensions bolted onto your browser and website. Keeping software current is so important that patching applications and patching operating systems are two of the eight controls in the ACSC Essential Eight. If you want the fuller case for why this one habit protects you more than almost anything else, we have covered why software updates matter separately.

Why a routine beats good intentions

Patching fails in small businesses for predictable reasons. Someone turns off automatic updates because a restart interrupted a presentation. A line-of-business application only runs on an old version of Windows, so that machine never gets touched. A laptop that lives in a drawer for a slow season comes back online six months behind. None of these are dramatic failures. They are the ordinary drift that happens when updating is left to chance.

A routine removes the guesswork. When patching happens on a set day, through a short checklist, you stop relying on memory and start relying on a process. You also get something valuable for free: a record. If a client or an insurer ever asks whether you keep your systems updated, you can point to a routine you actually follow rather than a vague assurance that you try to stay current.

How quickly should you patch?

Not every patch carries the same urgency, and the Essential Eight reflects that. The timeframes below are drawn from the ASD maturity model and are a sensible target even if you are not formally assessed against it.

The pattern is easy to remember. The more exposed a system is, and the more attackers already know about a flaw, the faster you act. A monthly routine comfortably covers the two-week and one-month items. The 48-hour items need a separate trigger, which we build into the routine below.

A simple monthly patch routine

Pick a fixed day, such as the second Tuesday of the month, which conveniently falls just after Microsoft and many other vendors release their monthly updates. Block out an hour, and work through the same steps each time.

  1. Know what you own. Keep a simple list of every device, operating system and key application in the business, including phones, the router and any website platform. You cannot patch what you have forgotten exists, and an up-to-date inventory is the foundation of the whole routine. Review it each month and add anything new.
  2. Check that automatic updates are still on. For most small businesses, turning on automatic updates across Windows, macOS, browsers and phones does the heavy lifting. The monthly job is to confirm they are still enabled and that nothing has silently switched off.
  3. Apply anything waiting. Install pending updates on every device, then restart where needed so the patch actually takes effect. A downloaded update that is never restarted into place is not protecting you.
  4. Cover the devices that hide. Chase down the laptop that was off, the spare machine in the cupboard and the phone belonging to the staff member who was on leave. These stragglers are exactly where gaps open up.
  5. Update the things people forget. Patch the firmware on your router and firewall, update website plugins and themes, and refresh browser extensions. These sit outside the usual update prompts and are a favourite target.
  6. Write down what you did. A one-line note of the date and anything you could not patch takes seconds and gives you a running record. It also makes next month faster.

Alongside the monthly cycle, set one standing rule: when you hear about a critical vulnerability in something you run, or a vendor pushes an emergency fix, deal with it straight away rather than waiting for patch day. A free alert service from the ASD or your software vendors will tell you when that moment arrives. This is how you meet the 48-hour expectation without checking every system every day.

Handling software you can no longer update

Every so often the routine will surface something that simply cannot be patched because the vendor has stopped supporting it. Old versions of Windows, a long-abandoned accounting package or a plugin whose developer has vanished all fall into this category. Once software reaches end of life, no more security fixes arrive, so known holes stay open forever. The ACSC is direct about this: unsupported software should be removed.

In practice that means planning the replacement before the support date arrives rather than after. Where you genuinely cannot retire a system yet, isolate it: take it off the internet, limit which machines can reach it, and treat it as a known risk with a deadline attached. Unsupported software left connected and forgotten is one of the most common ways a manageable situation turns into a breach.

How rigorous your patching needs to be depends on your size, your industry and what you are protecting. If you are weighing up how far to take it, our guide to the Essential Eight maturity levels explains the different targets and how to choose the right one for your business.

Find out where you stand

Patching is one piece of a bigger picture, and the fastest way to see how your business is tracking across all of it is to measure where you are today. The free self-assessment at SecurityScore.com.au asks 27 plain-English questions and takes about five to ten minutes. At the end you get a personalised PDF report mapped to the ACSC Essential Eight, ISO 27001 and SOC 2, showing your strengths and the gaps worth closing first.

It costs nothing, there is no obligation, and it turns a vague worry about whether you are doing enough into a clear, prioritised list. Take the assessment and see exactly where patching, and everything else, sits for your business.

Discover more from Security Score

Subscribe now to keep reading and get access to the full archive.

Continue reading