Module 3 of StartCloud's Essential Eight for Australian Business learning pathway, in five short units with a knowledge check: why the Australian Signals Directorate lists patch applications and patch operating systems first, why internet-facing systems run on a tighter clock than internal ones, why the timeframes depend on your target maturity level and live in the maturity model appendices, the blind spots that make patching fail (forgotten software, browser extensions, the one odd PC, firmware), and honest options for software and operating systems that can no longer be patched.
Patching: The Two That Matter Most
Why these two sit at the top
Two of the eight controls are about keeping software up to date. Patch applications, then patch operating systems. The Australian Signals Directorate lists them first and second, ahead of multi-factor authentication, ahead of everything else.
That order catches people out, because patching is the least interesting thing on the list. There is no product to buy, nothing impressive to show the board, and nobody has ever been thanked for a quiet Tuesday of updates. It is housekeeping, and it sits at the top of Australia's national security baseline anyway.
Here is why. A patch is a repair for a hole that somebody found. The moment the vendor publishes the fix, the hole stops being a secret. Release notes describe what was broken, researchers write it up in detail, and working exploit code often follows within days. The patch closes the door, and it also announces that the door was ever open, to everyone, at the same time.
The vendor publishes a fix and a short note about what it fixes. Your business sees an update prompt. Attackers see a description of a weakness, and a list of everyone who has not applied it yet. Both sides got the same email.
Exploit code gets packaged up and passed around. Scanning tools get taught the new trick. From then on it takes no skill at all to use, which is the part that matters for a business of twelve people in Osborne Park. You are not being singled out. You are being swept up.
Most businesses do not fail this because they refuse to patch. They fail it because patching is somebody's fifth priority, the update prompt gets postponed on a busy morning, and three months later nobody can say what is running where. The control is not asking for heroics. It is asking for a routine that keeps happening when everyone is flat out, which is a very different problem.
ASD does not treat every system the same, and this is the single most useful thing to take away from the patching controls. What changes the urgency is whether the system is internet-facing, meaning someone on the other side of the world can reach it without needing an account, an email, or a person to trick.
The whole internet gets scanned continuously, all day, by automated tools looking for known holes. There is no targeting involved. Your VPN appliance is not interesting to anyone, right up until it is running a version with a published flaw, at which point it becomes interesting to everyone at once.
- Your VPN or remote access gateway, the thing people connect to from home
- The firewall or router itself, including its management interface
- A web server, customer portal, booking system or online store you run yourself
- Mail gateways and any filtering appliance sitting in front of your email
- Remote desktop of any flavour, especially if it was opened up quickly during a busy period
- Staff laptops and desktops, and the software people use all day on them
- File servers and line of business applications sitting on your internal network
- Printers, scanners, cameras and the assorted boxes nobody thinks of as computers
- Anything a person has to already be inside the network to reach
ASD sets tighter patching windows for internet-facing services than for other systems, and tighter again where a working exploit is already circulating. The precise windows live in the appendices of the maturity model, they differ by maturity level, and ASD updates them. Anyone who quotes you a single number for "the Essential Eight patching rule" is oversimplifying. Check the current maturity model, or ask whoever is assessing you which level you are being held to, then read the windows for that level.
"What of ours can be reached from the internet, and who is responsible for updating it?" Plenty of businesses cannot answer that in a hurry, and the honest answer is often a firewall installed years ago by someone who has since moved on. Finding the list is most of the work. Keeping it patched is the easy half.
Both patching controls quietly assume something before they start: that you know what you are running. That assumption is where most small businesses come unstuck, well before anyone argues about timeframes.
ASD's answer is a scanner. A vulnerability scanner is an automated tool that looks across your systems, works out what versions of what software are installed, and compares that against a database of known weaknesses. The maturity model expects scanning to happen regularly, using a database that is itself kept current. How often, and across which systems, depends on the level you are working to.
Software nobody remembers installing
A PDF tool from a trial in 2021, a screen recorder someone needed once, a database viewer from a project that ended. It never gets opened, so it never prompts to update, so it sits there at whatever version it arrived as.
- If it is installed, it counts, whether or not anyone uses it
- The cheapest patch is uninstalling something you no longer need
- Do a clear-out before you buy any tooling, it shrinks the problem
Browser extensions and add-ins
Extensions are software too, they update on their own schedule, and they can read a lot of what happens in the browser. Office add-ins are in the same boat. Most businesses have never once looked at the list.
- Ask what is installed across the team, not just on your own machine
- Extensions change hands, and a useful one can be sold to someone less careful
- Fewer is genuinely better here
The one machine that runs the important thing
Every business has it. The PC in the corner that drives the label printer, the old laptop that talks to the workshop equipment, the box running the accounting package that nobody dares touch during end of month.
- It is usually the least patched machine you own
- It is often the one with the widest access to everything else
- Name it, write down what it does, and plan for it deliberately
Network gear, printers and firmware
Routers, switches, access points, network printers and the video recorder for the cameras all run software, all get security fixes, and almost none of them nag you about it. Some of them are internet-facing without anyone intending it.
- Firmware updates are patches, they just have a different name
- Check whether any management interface is reachable from outside
- Default passwords on these devices are a whole separate problem
For a business without a dedicated IT team, turning on automatic updates across Windows, macOS, browsers and the main applications does more for your patching posture than any amount of policy writing. Central management makes it verifiable, which is what an assessor wants, but the security benefit arrives the moment updates stop depending on somebody remembering.
An insurer or an assessor will not accept "we keep on top of updates". They want to see a list of your systems, scan results with dates on them, and a record showing patches going out. If your IT provider already does this, ask them for last month's report. If nobody can produce one, that gap is the finding, not the patching itself.
Now the awkward part, and the reason this module exists rather than being one line on a checklist. Some software cannot be patched. Not "has not been", cannot be.
The vendor went under. The product was discontinued. The version you run was customised years ago and updating it breaks the integration that half the business depends on. Or the supplier will happily update it, for a five figure sum and a project nobody has budget for this year.
- Replace it. Painful, and usually the answer eventually, so start pricing it now rather than in a crisis
- Cut it off from the internet entirely, so the only way to reach it is from inside
- Separate it from the rest of the network, so a problem there does not become a problem everywhere
- Write down the risk, who accepted it, and the date you will revisit the decision
- Hoping. It is the most popular option and it has never once succeeded
- Assuming you are too small to be found by an automated scanner
- Telling your insurer you are compliant and leaving this bit out of the answer
- Leaving it exposed to the internet because moving it is a hassle
When a vendor ends support for an operating system, patching does not get slower. It stops. Every hole found from that day forward stays open permanently, and researchers keep finding them for years afterwards. This is why ASD's position on unsupported software is to replace it rather than manage around it. An operating system that has run out of road is not a patching problem you can catch up on, it is a replacement decision with a date attached, and the date has already passed.
ASD designed the Essential Eight for internet-connected IT networks. It was not written for operational technology, the gear that runs machinery, plant and building systems, and it was not written for enterprise mobility either. If your unpatchable thing is a controller on a workshop floor, the answer is not to force it into this framework. It is a different conversation, and saying so is a legitimate response rather than an excuse.
The good news, and there is some, is that patching is the control where a small business can make the most progress in the least time. Turn on automatic updates, get a list of what you own, uninstall what you do not need, and deal with the two or three things that are genuinely stuck. That sequence takes a week of attention and moves you further than most of the rest of the framework combined.
- cyber.gov.au: Essential Eight explained, Australian Signals Directorate
- cyber.gov.au: Essential Eight maturity model, including the patching timeframes by level
Current at the time of writing (August 2026). ASD updates the maturity model regularly, and the specific patching windows sit in its appendices, so read them there for the level you are being assessed against rather than relying on a number quoted anywhere else.
Knowledge check
5 quick questions. Get 4 right and the module is yours.
1. Why does ASD put the two patching controls at the top of the Essential Eight?
2. What does 'internet-facing' mean, and why does it change the urgency?
3. Someone tells you the Essential Eight requires patching 'within 48 hours, full stop'. What is the right response?
4. Which of these is most likely to be the least patched machine in a small business?
5. A line of business application can no longer be patched because the vendor is gone. What is a legitimate way forward?