Living guide · IT Support & Managed Services

Patch Management: What Gets Patched, How Fast, and the Updates Everyone Forgets

Windows nags, so Windows gets patched. The browser, the PDF reader and the video app that people use all day do not nag, and they are what attackers reach first. Here is what a managed patching service actually covers, the timescales that matter, and the one question to ask any provider.

Last reviewed 23 September 2026 Published 23 September 2026 8 min read
Book a Discovery Call
This guide is for you if
  • You assume patching is handled because Windows updates itself.
  • An insurer, auditor or Cyber Essentials assessor has asked how quickly you apply updates.
  • You want to know what a managed IT provider should be doing, so you can check yours.

The short answer

Everything critical should be patched within 14 days of release, and a good provider does it in about 7: operating systems, drivers and firmware, Microsoft products, and the third-party software such as Chrome, Firefox and Adobe Reader that most businesses never patch at all. Fourteen days is the Cyber Essentials requirement; the third-party category is where most businesses fail it.

In this guide
  1. 1. What gets patched
  2. 2. Why 14 days
  3. 3. Third-party gap
  4. 4. How it works
  5. 5. What it does not fix
  6. 6. Check your provider
  7. 7. FAQs
01

What patched actually means: four categories, not one

When we take on a new client and run the first audit, the pattern is nearly always the same. Windows is more or less up to date, because Windows nags. The laptops have a mix of driver versions from whenever they were bought. And the software people use all day has not been updated since it was installed.

A managed patching service covers four things:

  1. Operating systems. Windows and macOS on every laptop, desktop and server. The monthly cumulative updates and the out-of-band fixes Microsoft and Apple release when something is already being exploited.
  2. Drivers and firmware. Graphics, network, storage and chipset drivers, plus the BIOS and firmware on the machine itself. Nobody thinks of these as security updates until a vulnerability in a Wi-Fi driver lets someone on the same network in.
  3. Microsoft products that are not Windows. Office, Teams, Edge, .NET and SQL Server where it exists.
  4. Third-party software. Google Chrome, Mozilla Firefox, Adobe Acrobat and Reader, Zoom, 7-Zip, Java, VLC, Notepad++ and the long tail of things installed on a business PC. This is the category that matters most, because it is the one attackers reach first and the one most businesses do not patch at all.

Our own commitment is simple to state: every critical update applied within 14 days of release, and usually within 7, across all four.

02

Why 14 days, and why we aim for 7

The 14-day figure is not arbitrary. It is the window Cyber Essentials requires: updates that fix vulnerabilities rated critical or high risk must be applied within 14 days of release, on every device in scope, including third-party software and firmware. Miss it on one category and the assessment fails.

We aim for seven for two reasons. The gap between a patch being published and the exploit being used against it has been shrinking for years, and is often days rather than weeks for the browsers. And seven leaves room to deal with the machine that has been switched off for a fortnight, the server with a maintenance window, and the update that has to be pulled because it broke something.

03

Why third-party software is where businesses fail

A browser is the piece of software on your computer that spends its whole day opening content written by strangers. Chrome and Firefox each fix dozens of security vulnerabilities a year, several of them already being exploited when the fix ships; Google publishes them on the Chrome releases blog and Mozilla in its security advisories. A PDF reader opens files that arrive by email from people you do not know, and Adobe's security bulletins run at a similar pace.

None of those updates arrive through Windows Update. Chrome updates itself, but only when it is restarted, and a browser left open for three weeks on a desk is three weeks out of date. Firefox, Adobe and the rest depend on the user clicking a prompt they have learned to dismiss. Nobody in the business is responsible for it, so nobody does it.

The NCSC's device security guidance is blunt: unpatched software is one of the most common ways attackers get in, and responsibility has to sit with whoever manages the device, not with the person using it. That is why third-party patching is in the base price of our managed IT support, not an add-on.

Not sure which of these applies to your business? Ask an engineer.

Book a Discovery Call
04

How managed patching actually works

The tools are less interesting than the process.

  • Inventory first. Every managed device reports what is installed and at what version. Software nobody knew about is the first finding on most audits, and you cannot patch what you have not seen.
  • Detect, download, install, on a schedule. Every device checks for updates at 00:00, 09:00 and 16:00 each day and downloads approved ones straight away, so nothing waits on a download. Installs run at 19:00 on Monday and Thursday, outside working hours. Antivirus definitions install immediately, any time.
  • Test, then rings. Updates are approved after a short soak on our own machines and a pilot group at each client, then rolled out in rings: a handful of machines, then a department, then everyone. A bad update, and there are a few every year, hits one machine and is stopped rather than hitting forty and stopping the business.
  • Reboots, handled like adults. Most security updates need a restart. Ours happen on Friday at 15:00: the user gets a message from us with a three-hour countdown, can save their work and restart sooner, and the device restarts itself at the end of the window if they do not. A machine that misses two Friday windows gets a conversation, then a deadline.
  • Off-network machines stay in scope. The laptop at someone's kitchen table patches over the internet the same as one in the office. The one that has been in a drawer since Easter is patched the day it is switched on, before it is allowed near anything else.
  • Servers and firmware, with care. Servers patch in a maintenance window with a snapshot taken first. Firmware and BIOS updates are done deliberately and on a schedule, because a failed one is a dead machine.
  • Reporting you can show someone. Each month: what was released, what was applied, what is outstanding and why. When an insurer, an auditor or a Cyber Essentials assessor asks how you patch, the answer is a report, not a shrug.

For our clients the schedule is fixed and published: detection at 00:00, 09:00 and 16:00 every day, installs at 19:00 on Monday and Thursday, restarts on Friday at 15:00 with a three-hour warning, and antivirus definitions immediately. An update released on a Tuesday is normally installed on Thursday evening and active by Friday evening. The full patch management policy sets out scope, timescales, exceptions and reporting.

05

What patching does not fix

Patching closes the door attackers use most, but it is one control among several. It does not stop someone handing over their password to a convincing email, which is what phishing simulation and training is for. It does nothing for software that is out of support and no longer gets patches at all, which is why Windows 10 machines still in use are a problem we raise loudly. And it does nothing for the device nobody told us about, which is why the inventory comes first.

06

The one question to ask your provider

Ask when Chrome and Adobe Reader were last updated across every machine, and ask to see the report.

If the answer is "they update themselves", that is the gap. If the answer is a report with dates and a list of outstanding machines, patching is being done.

Not sure where you stand? The free IT Health Check benchmarks your setup in a few minutes, and patching is one of the things it looks at.

07

Frequently asked questions

How quickly should security updates be applied?

Within 14 days of release for anything rated critical or high risk, which is the Cyber Essentials requirement. We aim for 7. Updates already being exploited when released should go faster still.

Does Windows Update cover everything?

No. Windows Update covers Windows and, if configured, other Microsoft products. It does nothing for Chrome, Firefox, Adobe, Zoom, Java and the rest of the third-party software on a PC, nor for drivers and firmware in most cases. Those need a separate tool and someone responsible for it.

Will patching break things?

Occasionally an update breaks something, which is why updates are tested and rolled out in rings rather than to everyone at once. A bad update reaches a handful of machines and is stopped. That is a far smaller risk than leaving known vulnerabilities open.

When do updates install and when do devices restart?

Devices check for updates three times a day (00:00, 09:00 and 16:00) and download them straight away. Installs run at 19:00 on Monday and Thursday. Restarts happen on Friday at 15:00, with a three-hour countdown so people can save their work; the device restarts itself at 18:00 if they have not. Antivirus definitions install immediately, every day.

What about laptops that are rarely in the office?

They patch over the internet wherever they are. A machine that has been switched off for weeks is patched the moment it comes online, before it can reach company systems.

Do you patch servers and firewalls?

Yes. Servers in a maintenance window with a snapshot first; firewalls, switches and access points on a schedule, because network equipment is a common way in and is often years out of date.

Is patching included in managed IT support?

Yes, all four categories, including third-party software, are in the base price. If a provider quotes patching as an add-on, or only covers Windows, the base price is not the real price.

Find out what is not being patched

We will audit every managed device, show you what is installed, what is out of date and what is out of support, and give you the report whether or not you move to us.

  • A list of every device and what is on it.
  • Which updates are outstanding, by category, and how old they are.
  • Software that is out of support and needs replacing.
  • What it would cost to have it handled.
Book a patching audit

Sources

Prices and product facts on this page were checked against the following Microsoft pages on the dates shown.

  1. 1.NCSC: Cyber Essentials overview · accessed 23 September 2026
  2. 2.NCSC: Keeping devices and software up to date · accessed 23 September 2026
  3. 3.NCSC: Vulnerability management guidance · accessed 23 September 2026
  4. 4.Microsoft Security Update Guide · accessed 23 September 2026
  5. 5.Google Chrome releases · accessed 23 September 2026
  6. 6.Mozilla security advisories · accessed 23 September 2026
  7. 7.Adobe security bulletins · accessed 23 September 2026

What has changed on this page

  • 23 September 2026Page published.

More guides

Related reading