Most cyber security tools work reactively. Something suspicious happens, the system spots it, and…
Implementing Patch Management in Cyber Essentials
Patch management involves taking a systematic, methodical approach to regularly updating your devices, applications and network with security patches that keep them defended against evolving cyber threats. These patches will almost always be supplied by the vendors of your hardware and software, with the main responsibility for organisations being to accept and apply them regularly.
Without applying patch management across your organisation, the security posture across your business will gradually become more (excuse the pun) ‘patchy.’ This can create security gaps that can be exploited by cyber threats, making this one of the key pillars of Cyber Essentials.
The Scope and Goals of the Patch Management Key Control
This control applies to: Desktop computers, laptops, tablets, mobile phones, firewalls, routers, as well as web, email, and application servers.
Its objective: To ensure that devices and software are not vulnerable to known security issues for which fixes are available.
Compared to the other key controls, this one is the simplest to implement in practice, as the vendors for your hardware and software will offer these patches for you; the key thing is to regularly check for them and apply them across your organisation.
An example of applying this key control, is regularly surveying your inventory of software and hardware for updates and rolling these updates out across your organisation. These updates could be applied across the board from an administrative dashboard, applied automatically as a default configuration on each device (like daily automatic updating of antivirus software discussed in our last post), otherwise, you can prompt users to apply the updates and verify they have done so.
These are the key requirements for the patch management key control:
- All software must be licensed and supported. For example, with Windows 10 no longer being supported in 2025, organisation would need to update this Operating System across their devices to one that is still receiving regular updates and dedicated support.
- All unsupported and no-longer updated software must be removed from devices
- Software updates/patches need to be applied within 14 days of an update being released wherever this patch fixes a vulnerability that a vendor describes as ‘critical’ or ‘high risk’.

Your Practical Guide To Applying The Patch Management Key Control
Create an Inventory
If you have been following this guide and steadily putting it into practice as you’ve went along, you will probably already have an inventory of your software and devices documented. If not, take care to map these out in your organisation in order to track what can be updated. With an inventory, managing patches will be much easier.
Regularly Check for Patches
In regular time intervals, conduct regular checks across your devices and software for possible updates from each of your vendors. There are some ways to help you to do this, you can subscribe to receive vendor notifications or use a dedicated patch management tool which can greatly streamline updates across your organisation.
Automate Patching Where Possible
Check to ensure that you have automatic updates configured across your software and devices wherever it is possible. For many of these, you can enforce organisation-wide updates from administrative dashboards in your software solutions, which help to ensure patches are being applied across the board. By automating updates, you can save time and enhance consistency.
Apply Patches Promptly
As soon as patches are tested and verified, apply them promptly to all relevant devices and software. This step is critical to safeguard your systems from potential threats.
Monitor Patch Status
Implement a system to monitor the patch status of your devices and software. Regularly check for missing or failed patches and take corrective action as needed.
Educate Employees
Getting your people aware and onboard with the importance of patch management and best practices can empower regular updates across your organisation. You can incorporate employee patch management awareness into your IT policy and processes to culturally promote patch management.
Get your FREE cyber risk traffic light report
Our Cyber Risk Traffic Light Report is designed to help businesses audit their cyber security posture, enabling them to find risk areas and security gaps and to address them with actionable insights. Get started with your cybersecurity journey by getting your own Cyber Risk Traffic Light Report today.
