
Of all the security advice a business receives, “keep your software updated” sounds the most boring, and prevents the most incidents. When a vendor releases a security patch, they’re also publishing a map of the hole it fixes. Within days, sometimes hours, attackers build automated tools that scan the internet for systems that haven’t applied it. Unpatched software isn’t a hypothetical risk; it’s a queue you’re standing in.
Two of the Essential Eight are about patching
The ACSC considers patching so important that it takes up two of the eight controls in the Essential Eight: patch operating systems and patch applications. The recommended pace: critical or internet-facing systems patched within 48 hours of a security release, everything else promptly on a regular cycle.
What “applications” really includes
- Browsers and their extensions, the most attacked software on any machine.
- Office suites, PDF readers, video-conferencing tools.
- Your website: the CMS, its plugins and themes. Outdated plugins are the leading cause of small-business website compromise.
- Firmware on routers, firewalls and NAS devices, the forgotten layer that guards everything else.
The end-of-life trap
Some software can’t be patched because the vendor no longer supports it: old Windows versions, abandoned plugins, ancient PHP. Every end-of-life product in your business is a permanent hole. Inventory what you run, flag anything past its support date, and plan the upgrade before an attacker plans it for you.
Make it automatic, then verify
Turn on automatic updates everywhere they exist. Then, once a month, spend ten minutes verifying they actually applied: an update that silently failed six months ago is indistinguishable from no update policy at all. Businesses with an IT provider should ask for a monthly patch-status report across all devices.
Related reading: patching makes up two of the ACSC Essential Eight controls. It pairs naturally with application control, and fits into the complete guide to cyber security for small business in Australia.