Patch Management

Last updated

Definition

Patch management is the recurring process of identifying, testing, deploying, and verifying software updates – operating system, firmware, and third-party application patches – across every managed endpoint and server. It closes known vulnerabilities on a schedule. It is distinct from vulnerability management, which discovers and prioritizes weaknesses, including ones no patch addresses.

Why it matters to an MSP

Patching is the cheapest security control an MSP delivers. It is CIS Controls Safeguards 7.3 and 7.4 at IG1, it appears on every cyber insurance application as a yes-or-no question, and a documented cadence is now a standard underwriting minimum alongside MFA, EDR, and tested backups. Economically it is automation or nothing: with an RMM policy configured once per deployment ring, patching a thousand endpoints costs a few technician hours a month for exceptions and failed installs; by hand it is a full-time job. That is why it belongs in the base managed plan rather than as an add-on – leaving it out produces the breach you get blamed for anyway. OS patches are easy; third-party applications (browsers, PDF readers, runtimes) are where coverage quietly fails because RMM catalogs vary. Reboots outside a maintenance window generate tickets and resentment. A patch pushed fleet-wide without a test ring breaks printing at forty clients at once. A legacy line-of-business app pinned to an old runtime becomes permanent exposure unless the exception has a compensating control, a review date, and the client's written risk acceptance. Report on it: patch compliance per client – typically targeting 95% or better within 14 days of release for critical updates – is a QBR number business owners understand and insurers ask for. The ring structure, windows, and emergency procedure are in the patch management process.

Related terms: Vulnerability Management, RMM, CIS Controls, Endpoint