Why Software Patching Is Your Cheapest Security Control
Patching is the least interesting thing in security and one of the most effective. The vulnerabilities used against small businesses are, overwhelmingly, ones that were fixed by the vendor months or years before the attack. The patch existed. Nobody applied it.
How the attack economics actually work
When a vendor publishes a security update, they also publish what it fixes. Within days, that description gets turned into working exploit code, and that code gets folded into automated scanners that sweep the entire internet looking for systems that haven't updated.
So the disclosure that protects you also starts a clock. Before the patch, exploiting the flaw required real skill. A week after, it requires downloading a tool. This is why "we'll get to updates next quarter" is a genuinely dangerous position — you are not racing the attackers, you are racing their automation.
Nothing about this targets you specifically. The scanners don't know or care who you are. They find an unpatched system and try the exploit.
The part everyone gets wrong: third-party software
Most businesses have Windows Update running and consider patching handled. Windows is usually the best-patched thing on the network. The problems live elsewhere.
Commonly unpatched, commonly exploited:
- Browsers and their extensions — usually fine if left to auto-update, but extensions are a real blind spot.
- Adobe Reader, Java, and PDF tools — long-standing favorites for malicious document attacks.
- Conferencing and collaboration clients — Zoom, Teams, Slack desktop apps.
- Firmware on firewalls, routers, and VPN appliances — internet-facing by definition, and among the most aggressively exploited targets there are. These almost never auto-update.
- Network printers and scanners — full computers with credentials stored on them, patched approximately never.
- Line-of-business applications — the industry-specific software the business runs on, often left at whatever version was installed.
If you fix one thing after reading this, make it the firewall and VPN firmware. Edge devices are the single most common initial access point for ransomware at businesses your size, because they're reachable from anywhere on earth and nobody thinks of them as software.
Building a process that actually runs
Good patching isn't heroic effort, it's a boring routine that survives busy weeks.
- Know what you have. You cannot patch an asset you don't know exists. An inventory of every server, workstation, and network device — with its owner and its software — is the foundation. Most gaps we find trace back to a machine nobody remembered.
- Set a fixed cadence. Microsoft ships updates on the second Tuesday of each month. Anchor to that: test midweek, deploy to everyone by the following week. A predictable schedule beats an ambitious one.
- Keep a small pilot group. A handful of non-critical machines that get updates first. Occasionally an update does break something, and you want to find that on four machines rather than forty.
- Define an emergency path. Some vulnerabilities are actively exploited and can't wait for the cycle. Decide in advance who can authorize an out-of-band patch and how fast — the answer should be hours, not "next maintenance window."
- Report on what actually applied. "We have automatic updates on" is a belief. A monthly report showing which machines are current and which failed is a fact. Failed updates are silent by default, and machines can sit broken for months.
When you genuinely can't patch
Sometimes there's a real constraint: a critical application only certified against an old version, or a machine controlling equipment that can't be rebooted during business hours. These are legitimate, and the wrong response is to pretend the risk isn't there.
Instead, compensate. Isolate the system on its own network segment so a compromise can't spread. Remove its internet access if it doesn't need it. Restrict which accounts can reach it. Monitor it more closely than anything else. And put a real date on replacing it — "we can't patch it" tends to quietly become permanent otherwise.
The same thinking applies to end-of-life systems. When a vendor stops shipping security updates, the vulnerabilities keep being discovered; they just stop being fixed. An unsupported system doesn't hold steady, it degrades.
What this looks like when it's working
- Every device is in an inventory with a named owner.
- Critical security patches land within 7–14 days as a matter of routine.
- Actively-exploited vulnerabilities get handled within 24–48 hours.
- Someone reviews a compliance report monthly and chases the exceptions.
- Firmware on edge devices is on the same schedule as everything else.
- Unsupported software has a documented replacement date.
None of that requires a large team. It requires that the job belongs to somebody specifically, which is usually the actual missing ingredient.
Common questions
Won't automatic updates break things?
Occasionally, yes — which is what the pilot group is for. But weigh it honestly: the risk of a rare update issue you can roll back, against the risk of an exploit against a months-old vulnerability. The second is far more likely and far more expensive.
How do we patch laptops that are rarely in the office?
Use cloud-based management rather than anything that depends on the corporate network. Intune, included in Microsoft 365 Business Premium, patches and reports on devices wherever they are. This has become the normal case rather than the exception — see securing remote workers.
Where does patching sit against everything else?
Just behind MFA and alongside tested backups. Those three carry most of the load. Our small business security baseline lays out the full order.
Not sure what's actually up to date?
Vulcan365 manages patching for businesses across Birmingham and Central Alabama — including the firmware and third-party software that usually gets missed. We'll show you exactly what's behind and how far.
Get a patch assessment