Patch Management: What We Patch, How Fast, and the Updates Everyone Forgets
All dispatches
Security23 Sept 20266 min read

Patch Management: What We Patch, How Fast, and the Updates Everyone Forgets

Joe Welch
Joe Welch
Head of Engineering · Black Sheep Support
Share this dispatch

Every managed IT provider says they do patching. Here is what ours actually covers, how fast, and the category of updates most businesses never touch.

When we take on a new client and run the first audit, the pattern is nearly always the same. Windows is more or less up to date, because Windows nags. The laptops have a mix of driver versions from whenever they were bought. And the software people use all day, the browser, the PDF reader, the video calling app, the compression tool, has not been updated since it was installed.

That last group is where the risk is, and it is the part of patching that gets forgotten.

What "patched" means for us

Our commitment is simple to state: every critical update is applied within 14 days of release, and usually within 7. That covers four things, not one.

  1. Operating systems. Windows and macOS, on every laptop, desktop and server we manage. Monthly cumulative updates and the out-of-band fixes Microsoft and Apple release when something is being exploited.
  2. Drivers and firmware. Graphics, network, storage and chipset drivers, plus the BIOS and firmware on the machine itself. These are the updates nobody thinks of as security, until a vulnerability in a Wi-Fi driver lets someone on the same network in.
  3. Critical and security updates for the Microsoft products that are not "Windows": Office, Teams, Edge, .NET, SQL Server where it exists.
  4. Third-party software. Google Chrome, Mozilla Firefox, Adobe Acrobat and Reader, Zoom, 7-Zip, Java, VLC, Notepad++ and the rest of the long tail of things installed on a business PC. This is the category that matters most, because it is the one attackers reach first and the one most businesses do not patch at all.

The 14-day figure is not arbitrary. It is the window Cyber Essentials requires: updates that fix vulnerabilities rated critical or high risk must be applied within 14 days of release, on every device in scope. We aim for seven because the gap between a patch being published and the exploit being used against it has been shrinking for years, and because seven leaves room to deal with a machine that has been switched off for a fortnight.

Why third-party software is the gap

A browser is the piece of software on your computer that spends its whole day opening content written by strangers. Chrome and Firefox each fix dozens of security vulnerabilities a year, several of them already being exploited when the fix ships; Google publishes them on the Chrome releases blog and Mozilla in its security advisories. A PDF reader opens files that arrive by email from people you do not know, and Adobe's security bulletins run to a similar cadence.

None of those updates arrive through Windows Update. Chrome updates itself, but only when it is restarted, and a browser left open for three weeks on a desk is three weeks out of date. Firefox, Adobe and the rest depend on the user clicking a prompt they have learned to dismiss. Nobody in the business is responsible for it, so nobody does it.

The NCSC's device security guidance is blunt about this: unpatched software is one of the most common ways attackers get in, and the responsibility has to sit with whoever manages the device, not with the person using it. We agree, which is why third-party patching is in the base price of managed IT support and not an add-on.

How it actually works

The tools are less interesting than the process, but here it is.

Inventory first. Every managed device reports what is installed and at what version. Software we did not know about is the first finding on most audits, and you cannot patch what you have not seen.

Test, then rings. Updates are approved after a short soak on our own machines and a pilot group at each client, then rolled out in rings: a handful of machines, then a department, then everyone. A bad update, and there are a few every year, hits one machine and is stopped, rather than hitting forty and stopping the business.

Reboots, handled like adults. Most security updates need a restart. We schedule them for the end of the day, warn the user, and let them defer a few times, but not forever. A machine that has dodged its reboot for two weeks gets a conversation, then a deadline.

Off-network machines are still in scope. The laptop that lives at someone's kitchen table patches over the internet the same as one in the office. The one that has been in a drawer since Easter gets patched the day it is switched on, before it is allowed near anything else.

Servers and firmware, with care. Servers patch in a maintenance window with a snapshot taken first. Firmware and BIOS updates are done deliberately, on a schedule, because a failed one is a dead machine.

Reporting you can show someone. Each month you see what was released, what was applied, what is outstanding and why. When an insurer, an auditor or a Cyber Essentials assessor asks how you patch, the answer is a report, not a shrug.

What this does not fix

Patching closes the door attackers use most, but it is one control among several. It does not stop someone handing over their password to a convincing email, which is why we run phishing simulation and training. It does not help with software that is out of support and no longer gets patches at all, which is why Windows 10 machines still in use are a problem we raise loudly. And it does nothing for the device nobody told us about, which is why the inventory comes first.

Book a Discovery Call

The question to ask your current provider

If you want one question that tells you whether patching is really being done: ask when Chrome and Adobe Reader were last updated across every machine, and ask to see the report. If the answer is "they update themselves", that is the gap.

If you are not sure where you stand, the free IT Health Check benchmarks your setup in a few minutes and patching is one of the things it looks at.

Start with the free IT Health Check

Based in Brighton or Hove? We are too: see IT support in Brighton.

Back to all dispatchesEnd of Intelligence · BSS Digital Dispatch
Monthly IT briefing

The three things worth knowing this month

One short email a month: what broke, what got patched, and what we would change in a small business this week. No sales pitch, unsubscribe in one click.

We only use your email for the briefing. See our privacy policy.