Skip to content
Under attack?Get emergency help now
All articles
5 October 2026F1 IT Solutions

Patching Is Not Vulnerability Management

CybersecurityVulnerability ManagementPatch ManagementManaged ITRisk

Ask most business owners whether their systems are secure and the answer starts with patching. "Windows updates run every month." That is a good habit, but it is only one part of a bigger job. Patching is an activity. Vulnerability management is a process, and the difference decides whether a known weakness gets closed before someone uses it.

What patching actually covers

Patching installs fixes that vendors release for their own software. In most small and mid-sized businesses, that means Windows and perhaps Microsoft 365 apps, pushed out on a schedule.

What it often misses is everything around those machines:

  • Firewalls, switches and Wi-Fi access points running old firmware
  • Third-party software such as PDF readers, browsers, remote access tools and accounting packages
  • Servers nobody has logged into for a year
  • Laptops that are rarely on the office network, so they miss the update window
  • Cloud services and web applications with misconfigured settings rather than missing patches

A weakness does not need to be a missing patch to be dangerous. An open remote desktop port, a default password on a printer or a storage bucket set to public are all vulnerabilities too, and no Windows update will fix them.

Why "we patch monthly" leaves a gap

There are three common problems with a patch-only approach.

You cannot patch what you cannot see. Every environment has devices and software that were never formally recorded. If an asset is not on the list, it is not on the patch schedule either. Finding it is the first job of any vulnerability programme.

Monthly is slower than attackers. When a serious flaw becomes public, exploit code often appears quickly. A cycle that waits for the next maintenance window can leave a critical weakness open for weeks. Urgent fixes need a fast lane.

Nobody checks that the patch worked. Updates fail, machines reboot late and some devices quietly drop out of management. Without a scan that confirms what is actually installed, "deployed" and "fixed" are easily confused.

What a vulnerability management cycle looks like

Done properly, this is a loop that never really stops.

1. Discover

Build and maintain a live picture of every device, server, application and cloud service. Scanning the network and checking agents on laptops both help, because each finds things the other misses.

2. Assess

Scan those assets against known vulnerabilities and misconfigurations. A scan on its own produces a long list, and long lists get ignored. The next step is what makes it useful.

3. Prioritise

Not every finding deserves the same urgency. A sensible ranking asks a few plain questions:

  • Is it exposed to the internet, or only reachable from inside?
  • Is there evidence that attackers are already exploiting it?
  • What does the affected system hold, and how much would losing it hurt?
  • Is there a simple compensating control, such as blocking a port, until the fix is ready?

This is where experience matters. A medium-rated flaw on a public-facing server can be a bigger risk than a high-rated flaw on an isolated test machine.

4. Remediate

Fix the issue through a patch, a configuration change, a replacement or, where that is not possible yet, a documented workaround. Agree on target timeframes by severity, so everyone knows what "urgent" means.

5. Verify and report

Rescan to confirm the weakness is gone, then record it. A short monthly report showing what was found, what was closed and what remains open gives management a real view of risk, and it is useful evidence for auditors and insurers.

The end-of-life problem

Some vulnerabilities cannot be patched at all because the software no longer receives fixes. This is the situation many businesses face with older Windows versions, which we covered in Still on Windows 10? Your Grace Year Ends This October. For these systems the honest options are to upgrade, isolate them from the rest of the network, or accept a documented risk. Leaving them in place and hoping is not a plan.

Where this fits in a wider defence

Finding weaknesses early reduces the number of doors an attacker can try. It does not replace detection and response, which is why we describe ransomware protection as a stack rather than a single product. Continuous vulnerability management sits alongside 24/7 monitoring, tested backups and well-trained staff, and each layer covers for the gaps in the others.

For many smaller businesses, running this in-house is hard to sustain. Scanning tools need tuning, results need interpreting, and fixes need scheduling around the working day. That is why it is commonly delivered as part of managed IT services or a wider cybersecurity service, with one team responsible for the whole loop.

A simple place to start

You do not need a large project to improve things this month. Try these three steps:

  1. Ask your IT provider for a list of every device and application they manage, then compare it with what you know is in use.
  2. Ask when your environment was last scanned for vulnerabilities, not just patched, and who reviewed the results.
  3. Ask how long a critical finding takes to fix, and how that is measured.

If the answers are vague, that is useful information in itself. Clear answers usually mean the basics are already in good shape, and a short conversation can confirm where the remaining gaps are.

Want this handled for you?

Talk to the F1 team about cybersecurity, AI and managed IT for your business.