Why this matters
Attackers quickly exploit known flaws in popular software. Patching applications promptly closes those gaps and is one of the Essential Eight strategies.
What you'll need
- Your list of installed software
- Admin access or device management
Step-by-step instructions
Step 1
Know what is installed
Use your asset register or device management reports to list applications across devices.
Step 2
Turn on automatic updates
Enable automatic updates for browsers (Edge, Chrome, Firefox), Microsoft 365 Apps, PDF readers and security software.
Step 3
Set patching timeframes
At Maturity Level One, the ACSC expects patches for internet-facing services within two weeks (or 48 hours where a working exploit exists) and for common apps such as Office, browsers, email clients and PDF software within two weeks. Check cyber.gov.au for current timeframes.
Step 4
Scan for missing patches
Use a vulnerability scanner or device management tool to find devices that are behind.
Step 5
Remove unsupported software
Uninstall applications that are no longer supported by the vendor, as they will not receive security fixes.
Step 6
Check and report monthly
Review patch status every month and follow up on devices that are out of date.
Summary
Automatic updates, clear timeframes and monthly checks keep applications patched with minimal effort.
Still Need Help?
Some IT problems are easier to solve with a professional. If you've followed the guide and still need help, the Omnicron team can assist.