When major vulnerabilities like Log4Shell, ProxyShell, and PrintNightmare emerged, organisations worldwide faced urgent patching deadlines. Yet months later, security researchers were still finding unpatched systems being actively compromised. The common thread: these organisations possessed patches but failed to deploy them.
Why Vulnerabilities Are Exploited So Quickly
The attack window has collapsed dramatically. Security researchers and attackers alike now routinely develop working exploits within 24–72 hours of a patch being released. Patches themselves create vulnerability roadmaps for malicious actors. Automated scanning tools continuously probe internet-facing infrastructure. Attackers don't require specific targets — they scan IP ranges, identify vulnerable systems, and exploit them at massive scale. An exposed Exchange server can face compromise within hours of a critical vulnerability being published.
Why SMBs Consistently Fall Behind on Patching
Most small-to-medium businesses demonstrate significant patch debt upon initial assessment. Contributing factors include:
No Dedicated IT Resource
Many SMBs depend on part-time IT staff, generalist employees, or reactive contractors. Patching lacks immediate visible value and receives deprioritisation without clear accountability structures.
Fear of Breaking Things
Patches occasionally disrupt applications, creating rational-seeming but ultimately dangerous incentives to postpone updates. The proper solution involves implementing testing and rollback procedures, not abandoning patches entirely.
No Visibility Across the Fleet
Without Remote Monitoring and Management (RMM) tools, organisations cannot track patch status comprehensively. Home-based laptops, ageing servers, and dormant network devices remain invisible and unpatched.
Third-Party Application Blindspot
Organisations frequently update Windows while neglecting third-party software — Adobe Reader, Chrome, Java, 7-Zip, VLC — that also contain exploitable vulnerabilities and represent significant attack surfaces.
The Right Approach to Patch Management
RMM-Based Automated Patching
RMM platforms enable automated patch deployment across managed devices on scheduled timelines. Typical targets involve OS patches within 14 days of release (faster for critical exploits) and third-party patches within 30 days. Dashboard visibility confirms which devices comply with patch policies.
Patch Windows and Testing
Patches deploy during designated maintenance windows — commonly after business hours — minimising operational disruption. Properly configured RMM systems can stagger rollouts, beginning with test machines and expanding upon validation. Most patches deploy without incident; breakage concerns frequently exceed actual risk.
Essential Eight Alignment
Australia's ACSC Essential Eight framework includes two patch-related controls: Patch Applications and Patch Operating Systems. The target is critical patches within 48 hours for internet-facing software and two weeks for standard applications. Maturity Level 2 demands automated patching with documented processes and exception management — capabilities delivered through well-configured RMM systems.
Key Takeaways
- Exploitation occurs within hours or days following vulnerability disclosure, not weeks.
- SMBs delay patching due to insufficient IT resources, breakage concerns, and fleet visibility gaps.
- Third-party applications demand equivalent patching urgency as operating systems yet receive lower priority.
- RMM-based automated patching with maintenance windows represents the only reliable SMB solution.