Microsoft's August Patch Tuesday: 421 Bugs and a North Korean Attack
All dispatches
Security12 Aug 20268 min read

Microsoft's August Patch Tuesday: 421 Bugs and a North Korean Attack

Joe Welch
Joe Welch
Head of Engineering · Black Sheep Support
Share this dispatch

Microsoft's regular "Patch Tuesday" releases are a consistent fixture in the IT calendar. Recently, one such update addressed a substantial volume of vulnerabilities across their product range. What was particularly concerning was the confirmation that one of these flaws had already been exploited by state-backed cyber attackers before the patch was even available. This specific incident underscores a broader, critical point for any business using Microsoft products: the necessity of prompt, effective patch management. It is not merely an administrative task for your IT department; it is a fundamental pillar of your operational security and business continuity.

What Patch Tuesday actually means

"Patch Tuesday" refers to the second Tuesday of each month when Microsoft releases a comprehensive suite of security updates and bug fixes for its software. Essentially, it is their scheduled effort to address vulnerabilities discovered in their operating systems, applications like Office, server products, and various cloud services. A vulnerability is a weakness or flaw in software code that, if exploited, could allow an attacker to gain unauthorised access, disrupt operations, or steal data. Patching is the process of applying the corrective code, or "patch," to mitigate these risks. These updates are crucial because they close the doors that malicious actors might otherwise walk through. Ignoring them leaves known weaknesses exposed, which is, frankly, an invitation for trouble.

Why it matters for UK SMEs

For UK SMEs, the implications of neglecting patch management extend far beyond a technical glitch. Unpatched systems are a primary vector for cyber attacks, leading directly to data breaches, operational downtime, and significant financial and reputational damage. The incident involving state-backed attackers exploiting a zero-day vulnerability (a flaw known to attackers before a patch is available) serves as a stark reminder. If your business relies on Microsoft products, which most UK SMEs do, you are a potential target.

Beyond the immediate operational risks, there are clear regulatory obligations. The Information Commissioner's Office (ICO) expects organisations to implement appropriate technical and organisational measures to protect personal data under GDPR. Failing to patch known vulnerabilities could be interpreted as a failure to meet this standard, potentially leading to substantial fines and public scrutiny. Furthermore, the National Cyber Security Centre (NCSC) consistently highlights patching as a foundational security control. Achieving certifications like Cyber Essentials, often a prerequisite for government contracts or supply chain inclusion, absolutely requires a robust patching regime. Delays in applying critical updates are not just an IT problem; they are a direct threat to your business continuity, compliance, and market standing.

How to manage patching effectively, a practical walkthrough

Implementing effective patch management is a structured process, not a sporadic reaction. It requires a clear strategy, consistent execution, and ongoing verification.

3.1 Inventory and Assessment

First, you need a precise inventory of all your IT assets running Microsoft software. This includes workstations, laptops, servers (physical and virtual), and cloud services. Understand what is running, where it is, and who is responsible for it. Identify critical systems that might require more cautious patching, perhaps through a pilot group first. Regularly assess the criticality of your data and systems to prioritise patching efforts. This foundational step ensures you know what needs protection and where your efforts should be concentrated. Without a clear picture of your IT estate, you cannot guarantee comprehensive coverage.

3.2 Establish a Patching Schedule

While critical vulnerabilities demand immediate attention, a regular schedule ensures routine updates are applied consistently. This might involve monthly updates for workstations, perhaps outside of core business hours, and more carefully planned maintenance windows for servers. Automated deployment tools are invaluable here, but they require careful configuration and monitoring. A predictable schedule minimises disruption and establishes a routine, making the process less prone to oversight. Consider staggered deployments to reduce the impact of any unforeseen issues.

3.3 Prioritise Critical Updates

Not all patches are equal. Microsoft categorises updates by severity: Critical, Important, Moderate, and Low. Critical and Important updates, especially those addressing actively exploited vulnerabilities (zero-days), must be prioritised. Your strategy should allow for rapid deployment of these urgent patches, potentially bypassing standard schedules if the risk warrants it. This prioritisation ensures that the most dangerous threats are addressed first, mitigating the highest immediate risks to your organisation. Staying informed about emerging threats, often via NCSC advisories or your IT provider, is key here.

3.4 Implement a Testing Protocol

Before widespread deployment, especially for server updates, test patches on a small, non-critical group of systems. This helps identify potential compatibility issues or regressions that could disrupt operations. While this adds a step, it prevents widespread outages across your entire infrastructure. For smaller SMEs, this might mean a single test machine or a non-production server. Even a limited test can save significant downtime and recovery costs should an update cause an unexpected problem with line-of-business applications.

3.5 Automated Deployment and Verification

Automate as much of the patching process as possible using tools like Microsoft Endpoint Manager (formerly SCCM and Intune) or dedicated patch management solutions. Automation reduces human error and ensures consistency. Crucially, don't just assume updates have applied. Implement systems to verify successful installation across all devices. This is where many businesses falter. On a recent client tenant audit for a 60-user engineering firm based in Birmingham, we found that nearly 30% of their workstations, despite being configured for automated updates, had not successfully applied critical security patches for several months due to various issues, including insufficient disk space and user-initiated deferrals. This is a common pattern, and it’s why verification is non-negotiable.

3.6 Monitoring and Reporting

Continuous monitoring of your environment is essential. Tools should report on patch compliance, identifying any systems that are out of date or have failed to apply updates. Regular reporting allows for proactive intervention and demonstrates due diligence for compliance purposes. This also provides an audit trail, which can be invaluable for regulatory bodies like the ICO or for demonstrating adherence to standards like Cyber Essentials. Without monitoring, you are operating blind, unaware of the actual security posture of your systems.

3.7 User Education

For workstation patching, user cooperation is often necessary for restarts. Educate your staff on the importance of updates and why they should allow scheduled restarts, rather than deferring them indefinitely. A simple "restart required" notification with a brief explanation of the security benefits can make a significant difference. Clear internal communication about patching schedules and expectations helps foster a culture of security awareness, reducing instances of users inadvertently hindering the patching process.

Common mistakes we see

We frequently encounter several recurring errors in how UK SMEs approach patching.

  1. Delayed Application: The most prevalent mistake is simply not applying patches promptly. Many businesses assume a few days' delay won't matter, but attackers often move faster, exploiting vulnerabilities within hours or days of a patch release.
  2. Lack of Verification: Relying solely on automated updates without verifying their successful application is a significant oversight. Systems can fail to restart, encounter conflicts, or users might defer updates indefinitely, leaving critical gaps in your defence.
  3. Ignoring Non-Windows Products: Focus often remains on Windows and Office, but other Microsoft products like Exchange Server, SQL Server, and Azure components also require diligent patching. These are equally attractive targets for attackers and often overlooked.
  4. No Testing Protocol: Skipping even basic testing, particularly for server environments, can lead to unforeseen compatibility issues or system instability after an update, causing more disruption than the vulnerability itself.
  5. Insufficient Bandwidth or Storage: For smaller organisations, network congestion during large downloads or insufficient local storage on older machines can prevent updates from completing, often unnoticed until a problem arises.

Key Takeaways

  • Patching is immediate and non-negotiable. Known vulnerabilities are actively exploited, making prompt action critical.
  • Verify, don't just assume. Automated updates need verification to ensure successful application across all systems.
  • Comprehensive coverage. Remember to patch all Microsoft products, not just Windows and Office, including servers and cloud components.
  • Regulatory implications are real. Unpatched systems risk GDPR non-compliance, ICO fines, and failure to meet NCSC guidelines.
  • Proactive over reactive. A structured, scheduled patch management strategy prevents reactive crisis management and maintains business continuity.

When to call in help

For many UK SMEs, the internal resources or expertise required to manage a comprehensive, verified, and timely patching regime simply aren't available. Between running your core business, managing staff, and navigating daily operational challenges, dedicating consistent attention to intricate IT security tasks can be overwhelming. If your current patching process is reactive, inconsistent, or you lack the tools and confidence to ensure all systems are secure and compliant, it is time to consider professional assistance. Delegating this critical function to specialists ensures your systems are always protected without diverting your valuable internal resources.

To take the next step

Book a Discovery Call

Back to all dispatchesEnd of Intelligence · BSS Digital Dispatch
Monthly IT briefing

The three things worth knowing this month

One short email a month: what broke, what got patched, and what we would change in a small business this week. No sales pitch, unsubscribe in one click.

We only use your email for the briefing. See our privacy policy.