Call NowFree Quote
Cybersecurity

Patch Management for Perth Businesses - Why Keeping Software Updated Matters

The Australian Signals Directorate's annual cyber threat report consistently identifies unpatched software as one of the top three ways attackers get into Australian business systems. Not sophisticated zero-day exploits - just ordinary, known vulnerabilities that have had patches available for weeks or months, but were never applied. Patch management is unglamorous, but it prevents more breaches than almost any other security control.

What Is Patch Management?

Patch management is the process of identifying, testing, and applying software updates (patches) to your systems in a timely and consistent manner. It covers:

  • Operating system patches - Windows, macOS, Windows Server monthly security updates
  • Application patches - Microsoft 365, Adobe, browsers (Chrome, Edge, Firefox), and other installed software
  • Firmware updates - firewall firmware (FortiGate, Sophos), network switch and access point firmware, printer firmware
  • Third-party software - accounting software, line-of-business applications, and any other installed tools

Each unpatched vulnerability is a known, documented entry point that attackers actively scan for and exploit. When a vendor releases a security patch, they are simultaneously publishing a roadmap for attackers: "here is the flaw, here is where it is, here is how it works." The race is between you patching your systems and attackers finding unpatched systems to exploit.

How Fast Do Attackers Move?

Faster than most Perth businesses patch. Research consistently shows that attackers begin exploiting newly disclosed vulnerabilities within days of disclosure - sometimes within hours for high-profile vulnerabilities. The window between a patch being released and exploitation beginning is measured in days, not weeks.

The 2023 MOVEit vulnerability - which affected hundreds of organisations worldwide, including Australian government agencies - was actively exploited within 24 hours of disclosure. Organisations that patched promptly were protected. Those that delayed were breached.

For critical vulnerabilities (CVSS score 9.0+), the ASD recommends patching within 48 hours. For high-severity vulnerabilities (CVSS 7.0–8.9), within two weeks. These timelines require an automated, systematic approach - manual patching cannot keep pace.

What Managed Patch Management Looks Like

A properly managed patching process for a Perth business includes:

Automated patch deployment

A Remote Monitoring and Management (RMM) platform - the software used by managed IT providers - deploys approved patches automatically to all managed devices. Patches are tested in a small group first, then rolled out broadly. Critical security patches bypass the staging delay and deploy immediately.

Scheduled maintenance windows

Many patches require a restart. Scheduled maintenance windows (typically late night or weekend) allow patches to be applied and systems restarted without interrupting business hours. Staff arrive in the morning to fully patched, restarted systems.

Firmware management

Network hardware is frequently overlooked. Firewall firmware, switch firmware, and access point firmware all require regular updates. A FortiGate firewall running firmware that is 12 months out of date has known, exploitable vulnerabilities - even if the subscription is current and the threat feeds are updating.

Patch reporting

Monthly patch reports show which devices are compliant (fully patched), which have outstanding patches, and why - so nothing is silently left behind. Devices that consistently miss patches (because they are offline, or because patches are failing) are flagged for investigation.

Third-party application patching

Windows Update handles Microsoft software but misses everything else. A proper RMM platform patches third-party applications - Adobe Reader, Chrome, Java, 7-Zip, Zoom, and hundreds of other common applications - automatically alongside OS patches.

Common Patch Management Failures

Relying on users to apply updates

Prompting users to update and restart is not patch management - it is hoping for patch management. Users defer restarts indefinitely, ignore update prompts, and disable automatic updates when they find them inconvenient. Security cannot depend on individual behaviour.

Patching workstations but not servers

Server patches often require more careful testing and scheduled downtime, so they are deferred. But servers are higher-value targets - a compromised domain controller gives an attacker control of the entire network. Server patching must be systematic, not ad hoc.

Forgetting network hardware

Firewalls, switches, and access points are permanently on and internet-facing, but rarely patched. A vulnerability in firewall firmware can give an attacker a foothold without ever touching an endpoint.

No visibility of patch status

Without a centralised dashboard, you cannot know which devices are patched and which are not. "We do updates" is not the same as "we have confirmed patch compliance across all 47 managed devices."

The Essential Eight and Patch Management

The Australian Cyber Security Centre's Essential Eight mitigation strategies include two directly related to patching: patch applications and patch operating systems. These are not aspirational guidelines - they are the baseline expectation for Australian businesses handling sensitive data.

At Maturity Level 1 (the minimum): patches must be applied within 30 days of release. At Maturity Level 2: within 14 days. At Maturity Level 3: critical patches within 48 hours.

Frequently Asked Questions

How quickly do attackers actually exploit a newly disclosed vulnerability?

Often within days of a patch being released, sometimes faster for high-profile vulnerabilities. The 2023 MOVEit vulnerability, for example, was being actively exploited within 24 hours of disclosure, which is why relying on getting to updates 'when there's time' leaves a real window of exposure.

Isn't Windows Update enough to keep us patched?

It covers Microsoft software, but it misses everything else running in your business, browsers, Adobe products, and other third-party applications all need their own patching. A proper managed patching setup covers the operating system and the other software people use every day, plus network hardware like firewalls that's easy to forget.

What patching timeframe should we actually be aiming for?

The Essential Eight framework gives a useful benchmark, at minimum maturity level patches should be applied within 30 days of release, tightening to 14 days at the next level and 48 hours for critical patches at the highest level. Businesses working with regulated data or government contracts should check what timeframe applies to their specific situation.

Why not just let staff apply their own updates when prompted?

In practice that isn't reliable, staff routinely defer restarts, dismiss update prompts, or turn off automatic updates because it's inconvenient at the time. A managed, automated patching process with scheduled maintenance windows gets updates applied consistently without depending on individual behaviour.

Automated patch management is included in all our managed IT service plans - covering Windows, macOS, servers, third-party applications, and network firmware.

Managed IT Services →

Is your Perth business keeping up with patches?

Call 0433 087 091 - we'll audit your current patch status and show you exactly where your gaps are.

Book a Security Review

For related reading, see our guides to How to Safely Dispose of Old IT Equipment in Perth and Windows 10 End of Support: A Checklist for Perth Businesses.

Share this article