Unpatched software is the leading cause of preventable data breaches. Here's why patch management matters, how attackers exploit vulnerable systems, and what a proper patching program looks like for a small business.
Every piece of software your business uses — Windows, Office, your browser, your firewall firmware, your printer drivers — contains code. Code has bugs. Some of those bugs create security vulnerabilities that attackers can exploit to compromise your systems, steal your data, or deploy ransomware.
Software vendors discover and fix these vulnerabilities regularly, releasing patches — software updates that close security holes. The critical window between when a patch is released and when you apply it is exactly when attackers strike. They know that most organizations are slow to patch, and they actively scan the internet for unpatched systems.
Patch management is the process of systematically identifying, testing, and applying these updates across your environment before attackers can exploit what you've left open.
How Attackers Exploit Unpatched Systems
The history of major cyberattacks is, in large part, a history of organizations that didn't patch in time.
Log4Shell (CVE-2021-44228)
In December 2021, a catastrophic vulnerability was discovered in Log4j, a Java logging library used in millions of applications worldwide — including enterprise software, gaming platforms, and cloud services. The flaw allowed attackers to execute arbitrary code on vulnerable systems with almost no effort.
Within hours of public disclosure, attackers began mass-scanning the internet for vulnerable systems. Exploitation attempts were counted in the millions within days. Organizations that patched Log4j quickly were protected; those that waited — or didn't know they even used Log4j — were compromised.
The Chicago area saw numerous businesses affected, including healthcare providers, manufacturers, and financial services firms. Many didn't know they were vulnerable because Log4j was embedded in third-party software they'd never heard of.
EternalBlue and the WannaCry/NotPetya Epidemics
In 2017, the EternalBlue exploit — which attacked a vulnerability in Windows' SMB protocol — powered both the WannaCry and NotPetya ransomware campaigns. WannaCry infected over 200,000 computers across 150 countries in a single weekend, causing an estimated $4–8 billion in damages.
The critical fact: Microsoft had released a patch for this exact vulnerability two months before the WannaCry attack. Organizations that had patched their Windows systems were immune. Those running unpatched Windows 7 and Windows Server 2003/2008 were devastated.
This pattern repeats constantly. Attackers frequently weaponize publicly known vulnerabilities, knowing that a substantial percentage of organizations will remain unpatched for weeks, months, or years.
Windows Update vs. Managed Patching
Most business owners are aware of Windows Update — the built-in mechanism that keeps Windows computers patched. But Windows Update alone is not a patch management strategy. Here's why:
Windows Update only covers Microsoft products. Third-party software — Chrome, Firefox, Adobe Acrobat, Java, Zoom, and hundreds of other applications your users have installed — is not updated by Windows Update. Yet many critical vulnerabilities exist in exactly these applications.
Windows Update doesn't cover servers the same way. Server operating systems often require more careful update management, and some updates must be deferred or tested before deployment.
Windows Update has no centralized visibility. If you have 30 computers, Windows Update gives you no easy way to confirm that all 30 are current. One missed machine is all an attacker needs.
Windows Update doesn't cover network equipment. Your firewall, switches, and access points have their own firmware that requires separate patching — and these devices often have some of the most critical vulnerabilities.
What a Proper Patching Program Looks Like
A managed patch management program addresses all of the above gaps systematically.
Patch Categories and Priority
Not all patches are equal. A structured patching schedule prioritizes by risk:
| Category | Patch Target | Maximum Window |
|---|---|---|
| Critical OS patches (actively exploited) | Servers and workstations | 24–72 hours |
| High-severity OS patches | Servers and workstations | 7 days |
| Medium-severity patches | All systems | 30 days |
| Low-severity patches | All systems | 90 days |
| Firmware (network gear, servers) | All infrastructure | 30 days (after testing) |
The Patch Testing Process
Blindly applying every patch the moment it's released can cause its own problems — poorly tested patches from vendors have occasionally caused system crashes or application compatibility issues. A responsible patch management workflow includes:
- Patch release: Vendor releases update
- Testing: Apply to a non-production test machine or small pilot group first (typically 24–72 hours)
- Validation: Confirm tested systems are stable and key applications still function
- Deployment: Roll out to all production systems via automated management tool
- Verification: Confirm all systems received and applied the patch
- Exception management: Document and track any systems that couldn't be patched (exceptions need compensating controls)
Patching Servers
Servers require more care than workstations because a reboot at the wrong time can affect business operations. Best practices:
- Schedule server patches during maintenance windows (typically late night or weekend)
- Test the reboot and post-patch application functionality before considering the patch cycle complete
- Never defer security patches on internet-facing servers beyond 7 days for critical vulnerabilities
Patching Network Equipment
Firewalls, routers, and switches are frequently the most neglected. Many small businesses are running firewalls with firmware that hasn't been updated in years — and these devices often have the most serious, most actively exploited vulnerabilities. TechniWorx includes network device firmware patching as part of every managed services engagement.
Third-Party Application Patching
A managed patching tool like NinjaRMM, ConnectWise Automate, Datto RMM, or Atera can detect, download, and install patches for hundreds of third-party applications automatically. Common high-priority applications include:
- Web browsers (Chrome, Firefox, Edge)
- Adobe products (Acrobat, Reader)
- Java Runtime Environment
- Zoom, Teams, and other collaboration tools
- 7-Zip, VLC, and other common utilities
What Automated Patch Management Tools Provide
A managed patching platform gives your IT provider (or internal IT team) the ability to:
- See the patch status of every device in the fleet from a single dashboard
- Automate patch deployment on a defined schedule
- Receive alerts when patches fail to install
- Generate compliance reports showing patching posture over time
- Test patches before broad deployment
- Exclude specific patches that cause known issues
For small businesses that don't have an internal IT team, this function is typically included in a managed IT services engagement.
The Business Case for Patching
The cost of a managed patching program is modest — typically included in managed IT services pricing. The cost of a ransomware event caused by an unpatched vulnerability averages $250,000+ for small businesses when downtime, recovery costs, and potential ransom payments are included.
This is one of the clearest risk-reduction investments available. Patch management is unglamorous, but it closes the single most commonly exploited attack vector against small businesses.
Need Help? TechniWorx manages patch management for businesses throughout the Chicago area — covering workstations, servers, network equipment, and third-party applications. We close the vulnerability gap before attackers find it. Schedule a free security assessment at techniworx.com.
