1. Purpose
This policy sets out how Black Sheep Support keeps client devices up to date. Its purpose is to close known security vulnerabilities quickly and predictably, to keep devices within the Cyber Essentials requirement that critical and high-risk updates are applied within 14 days of release, and to do so without disrupting the working day.
2. Scope
The policy applies to every device enrolled in our managed IT support service and running our management agent. It covers:
- Operating systems: Windows and macOS on laptops, desktops and servers.
- Microsoft products: Office, Teams, Edge, .NET, SQL Server and other Microsoft software.
- Third-party software: Google Chrome, Mozilla Firefox, Adobe Acrobat and Reader, Zoom, 7-Zip, Java, VLC, Notepad++ and other supported applications installed on managed devices.
- Drivers and firmware, where the manufacturer publishes them through a supported channel.
- Antivirus and Microsoft Defender definition updates.
3. Timescales
- Critical and high-risk security updates: applied within 14 days of release, and normally within 7. With installation windows on Monday and Thursday evenings and a reboot window on Friday afternoon, an update released on a Tuesday is typically installed on Thursday and active by Friday evening.
- Updates that are already being exploited (out-of-band or zero-day fixes): approved and deployed outside the normal schedule as soon as they are validated, with an immediate reboot prompt where a restart is required.
- Other updates (feature updates, non-security fixes, optional driver updates): approved and deployed in the normal windows once tested, and may be deferred where they carry a known compatibility risk.
- Definition updates: installed immediately on release.
4. Weekly schedule for workstations
The standard schedule for laptops and desktops is set out in the table below. Servers and specialist equipment follow a maintenance window agreed with each client (normally outside business hours, with a snapshot taken first) rather than the workstation schedule.
| Stage | When | What happens |
|---|---|---|
| 1. Patch detection | 00:00, 09:00 and 16:00, every day | Each managed device checks for missing operating system, Microsoft and third-party updates three times a day and reports the results to us. |
| 2. Pre-download | Immediately after detection | Approved updates are downloaded in the background as soon as they are detected, so installation is not delayed by download time and does not compete with the working day. |
| 3. Installation | 19:00 every Monday and Thursday | Approved updates are installed outside working hours twice a week. Devices that are switched off or offline install at the next window. |
| 4. Reboot | 15:00 every Friday, three-hour warning | Where an installed update needs a restart, the user is prompted at 15:00 with a countdown of 180 minutes. They can save their work and restart sooner, or the device restarts at the end of the window. The message comes from Black Sheep Support and the device saves its state before restarting. |
| Definition updates | Immediately, every day | Antivirus and Microsoft Defender definition updates install as soon as they are released, at any time, and never need a restart. |
5. Approval and testing
- Updates are approved before deployment. Security updates are approved on release unless a known problem is reported; feature updates and driver updates are held for a short test period on our own devices and a pilot group at each client before general release.
- An update found to cause problems is declined for all devices, and removed where it has already been installed and removal is supported.
- Software that is out of support and no longer receives security updates is reported to the client with a recommendation to upgrade or replace it. It cannot be patched and is a risk until it is dealt with.
6. Reboots and the three-hour warning
- Restarts are only forced in the Friday reboot window. At 15:00 the user sees a message from Black Sheep Support explaining that the device will restart to complete important updates, with a 180-minute countdown.
- The user can save their work and restart immediately, or continue working; the device restarts automatically at the end of the countdown. The device saves its state before restarting.
- A device that is switched off or offline during the window restarts at the next Friday window. A device that misses two consecutive reboot windows is reported to the client and followed up, because an installed update is not effective until the restart completes.
- Devices in downtime or in use for a client-notified critical task can be excluded from a specific window on request.
7. Devices that are offline or off site
Laptops used away from the office are patched over the internet on the same schedule. A device that has been switched off for an extended period runs detection when it next comes online and installs outstanding approved updates at the next installation window, or immediately where the backlog includes exploited vulnerabilities. Devices that have not reported in for 30 days are listed in the monthly report.
8. Exceptions
- A client may ask for a device or an application to be excluded from patching, for example a machine controlling specialist equipment whose vendor requires a fixed software version. Exclusions are agreed in writing, recorded, reviewed quarterly, and the associated risk is accepted by the client.
- Excluded devices are isolated from the rest of the network where practical and remain in the inventory and the monthly report.
9. Reporting
Each month the client receives a patch report showing the updates released, the updates installed, the devices that are fully patched, the devices with outstanding updates and why, and any devices that have not reported in. The report is suitable as evidence for Cyber Essentials assessments, cyber insurance renewals and customer due diligence.
10. Client responsibilities
- Leave devices switched on and connected on Monday and Thursday evenings and Friday afternoons where possible, or accept that they will catch up at the next window.
- Save work and restart when prompted, rather than deferring repeatedly.
- Tell us about new devices, devices leaving the business, and any software with vendor restrictions on updates.
- Keep Microsoft 365 and other licences current, as some updates depend on them.
11. Roles
- Black Sheep Support engineering is responsible for approving, deploying and reporting on updates and for maintaining the management agent.
- The client's nominated contact is responsible for agreeing exceptions and maintenance windows for servers, and for receiving the monthly report.
12. Review
This policy is reviewed at least annually and whenever the tooling or the Cyber Essentials requirements change. Version 1.0, effective 23 September 2026.