Client Area
IT Support10 min read

Patch Management: What It Is and Why Your Business Needs It

What patch management is, how it works and why it shields your SME from attacks and downtime. Practical guide by TN Solutions, ISO 27001. Call 02 9517550.

Patch Management: What It Is and Why Your Business Needs It

In this article

  1. 01What is patch management?
  2. 02Patches, updates, upgrades: getting the terminology straight
  3. 03How a patch management process works
  4. 04Why patch management really matters: the risks of going without
  5. 05Patch management: do it yourself or have it managed?
  6. 06Where to start: three practical moves
  7. 07Systems always up to date, with nothing to worry about: let's talk

What is patch management?

Patch management is the process by which a business identifies, tests, deploys and verifies software updates (patches) across servers, workstations and applications. Its purpose is to close security vulnerabilities before they are exploited, fix bugs and keep systems stable and compliant — on a controlled schedule, rather than leaving it to chance.

In more than 25 years as a System Integrator, we have investigated dozens of security incidents at small and mid-sized businesses across the Milan area, and one finding comes up with embarrassing regularity: in most cases the attacker used nothing sophisticated. They walked in through a known vulnerability for which a patch had been available for months. Nobody had installed it. In this guide we explain what a patch management process actually involves, why "Windows Update is switched on" is not a strategy, and how to organise it in a company without a dedicated IT department.

Patches, updates, upgrades: getting the terminology straight

Before we talk about process, it is worth separating the terms, because in everyday usage they get muddled together.

  • Security patches: targeted fixes that close a specific vulnerability, often tracked under a CVE identifier. This is the most urgent category: from the moment a vulnerability is public, attackers know exactly where to strike.
  • Bug fixes and quality updates: these correct malfunctions, crashes and performance issues. Less urgent, but neglecting them lets instability pile up.
  • Feature updates: these introduce new capabilities and changes that are often visible to users. They need more careful planning because they can disrupt working habits and break compatibility with line-of-business software.
  • Version upgrades: moving to a major new release of an operating system or application. Strictly speaking this is not patch management, but the software lifecycle — end of support, end of life — is one of the things the process must keep in view: a system that is out of support no longer receives patches, and becomes a permanent risk.

The scope, moreover, does not stop at Windows. Serious patch management covers server and client operating systems, hypervisors, the firmware of firewalls, switches and NAS units, third-party applications (browsers, email clients, PDF readers, Java) and business software. Third-party applications are the most common blind spot of all: Windows updates itself, the rest often does not.

How a patch management process works

A structured process does not mean bureaucracy. It means always knowing what is up to date, what is not, and why. There are five stages.

1. Inventory: you cannot patch what you don't know you have

Everything starts with an up-to-date register of devices and software: how many servers, how many workstations, which versions, which applications are installed. It sounds trivial, yet in almost every company we take on we find "forgotten" machines — the PC in the warehouse, the server of a half-decommissioned application, the external contractor's laptop. These are precisely where the trouble starts.

2. Assessment and prioritisation

Not all patches are equal. A critical vulnerability being actively exploited on an internet-facing server needs dealing with in hours, not weeks; a minor update on an internal workstation can wait for the monthly window. Prioritisation weighs the severity of the vulnerability (its CVSS score) against the system's exposure and its criticality to the business. This is where patch management connects with vulnerability assessment work: the scan tells you where you are exposed, and patching closes the gaps in order of risk.

3. Testing before deployment

The most common fear — "the update will break my ERP" — is a legitimate one, and the answer is not to postpone indefinitely but to test. In practice, for an SME, this means deploying patches to a pilot group first (a few representative workstations, one non-critical server) and rolling them out to the rest of the estate after an observation period. For genuinely sensitive systems, compatibility is checked with the application vendor before going ahead.

4. Controlled deployment

Patches are released in stages and within agreed windows: out of hours for servers, at low-impact times for clients, with reboots planned and communicated in advance. Centralised management tools (RMM platforms, WSUS or Intune in Microsoft environments) make it possible to do this across tens or hundreds of machines without physically visiting each one. Before touching a critical server, there is one non-negotiable rule: confirm that the most recent backup is intact. For how to structure that, see our guide to backup and disaster recovery for SMEs.

5. Verification and reporting

The classic mistake is to consider the job done at the moment of deployment. A percentage of installations always fails: machines switched off, disks full, reboots never completed. The verification stage measures actual coverage, retries the failed installations and produces a report: which systems are up to date, which are not, and for what reason. That report is not an auditor's indulgence — it is the evidence of compliance that insurers, customers and regulators increasingly demand.

Why patch management really matters: the risks of going without

Known vulnerabilities are attackers' favourite way in

The attacks that hit SMEs rarely exploit unknown vulnerabilities (so-called zero-days, which are expensive and reserved for high-profile targets). They exploit public, well-documented vulnerabilities with ready-made exploits freely available. From the day a vendor publishes a patch, a race begins: attackers reverse-engineer the fix to understand the flaw, then automate scans of the internet hunting for unpatched systems. Incidents like WannaCry — which paralysed organisations worldwide in 2017 by exploiting a flaw whose patch had been available for two months — made the point painfully concrete. Modern ransomware follows the same playbook: unpatched VPN appliances and mail servers are among the most frequent entry points, as we explain in our guide on how to protect your business from ransomware.

Stability and business continuity

Patching is not only about security. Systems left behind accumulate bugs, incompatibilities and performance degradation that translate into outages, sluggishness and recurring support tickets. A consistent, up-to-date estate is simpler to support, breaks down less often and costs less in corrective work. That is why patch management is a standing component of our managed IT support for businesses: preventing a problem always costs less than chasing one.

Compliance: NIS2, GDPR and cyber insurance

Vulnerability handling is now an obligation, not an optional good practice. The NIS2 directive explicitly lists it among the risk-management measures required of in-scope organisations — and that scope pulls in many SMEs along the supply chain, as we discuss in our piece on NIS2 and what changes for SMEs. The GDPR requires technical measures appropriate to protecting personal data, and a system running a year behind on patches will struggle to pass that test after a data breach. Cyber insurance policies, too, now ask for evidence of a patching process: without it, the premium goes up or the claim is not paid out.

Patch management: do it yourself or have it managed?

The right question is not whether to do patch management, but who owns it. Windows' automatic updates cover part of the problem, but they do not handle third-party software, do not test, do not verify outcomes and do not produce reports. Above all: if nobody is watching, nobody notices the machines that have fallen behind.

Aspect DIY (auto-update) Managed patch management
Coverage OS and vendor products only OS, third parties, firmware, hypervisors
Pre-deployment testing None Pilot group and compatibility checks
Planned windows Unpredictable reboots Agreed, out of hours for servers
Outcome verification Absent Coverage measured, failures remediated
Compliance reporting None Documentation for audits and insurers

For a business with 10 to 100 seats, building all of this in-house rarely makes economic sense. The model that works is the managed service: a centralised platform monitors the estate, engineers approve and deploy patches according to agreed policies, and the business receives a periodic report. Patching, incidentally, is a defence that works as part of a team: it reduces the number of doors an attacker can open, while endpoint detection and response tools catch whatever gets through regardless.

Where to start: three practical moves

  1. Take inventory and measure the lag. How many machines do you have, and how long since they last received patches? If you cannot answer by the end of the day, that is the first sign you need a process.
  2. Secure the exposed perimeter first. Firewalls, VPNs, mail servers and anything reachable from the internet get patched first: these are the systems attackers scan every single day.
  3. Set a cadence and name an owner. A monthly window for routine patching, an emergency procedure for critical vulnerabilities, and one person — in-house or a partner — accountable for the result.

Systems always up to date, with nothing to worry about: let's talk

TN Solutions has been managing patch management for servers, workstations and network equipment at SMEs for over 25 years, with ISO 9001 and ISO 27001 certified processes: inventory, testing, planned deployment and compliance reporting, all included in our managed IT support contracts. If you would like to know how up to date your estate really is, that is the place to start: get in touch or call 02 9517550 for a no-obligation check-up.

Frequently asked questions

What is the difference between patch management and vulnerability management?

Vulnerability management is the broader process: it identifies and assesses vulnerabilities (through scans and assessments) and decides how to treat them. Patch management is the most important operational arm of that process: it applies the fixes. Not every vulnerability is solved by a patch — sometimes it takes configuration changes or network segmentation — but without patching, the rest counts for little.

How often should patches be installed?

It depends on criticality. Critical security patches on exposed systems should be applied within days, if not hours. For routine patching, a monthly cadence is the accepted standard (Microsoft releases its updates on the second Tuesday of the month — "Patch Tuesday"). What matters is that the cadence is defined, kept to and verified.

Can updates break business applications?

It can happen, which is exactly why the process includes pilot-group testing, verified backups before any work on servers, and staged rollouts. The risk of a badly handled update, however, should be weighed against the alternative: the consequences of an exploited vulnerability — a full production standstill, a ransom demand, data loss — are of a different order of magnitude altogether.

Does patch management also cover firewalls, NAS units and printers?

Yes, and they are often the most neglected devices of all. The firmware in firewalls, switches, access points, NAS units and network printers contains vulnerabilities like any other software — made worse by the fact that this equipment stays in production for years without anyone touching it. A firewall running old firmware does not protect much.

How much does a managed patch management service cost?

For an SME the cost is typically a monthly fee per device, included in an IT support contract or a managed security service, and it depends on the number of machines and the service levels required. It is a fraction of the cost of a single day of lost production — in our experience, that comparison settles itself.

Technology partners

Want to discuss it with our team?

We analyse your infrastructure for free and propose the most suitable solution.

Discover moreRequest a quote