Patch management is the ongoing process of finding out which software updates your devices and systems need, testing them, installing them on a schedule and confirming they actually went in. It covers operating systems, applications, browsers, firmware on network equipment and the software running on servers. Some patches fix security flaws; others correct bugs or improve compatibility and reliability. Attackers routinely exploit known flaws in systems that were never updated, so a reliable patching process is one of the most basic protections a company has.
At a glance
- Patching is a repeatable process, not a one-off task: inventory, assess, test, deploy, verify, report.
- It usually covers operating systems, third-party applications, browsers, server software and device firmware.
- Security patches are typically prioritized by severity, whether the flaw is being exploited, and how exposed the system is.
- Endpoint management or dedicated patching tools automate much of the work for laptops and many servers.
- Proof that patches were applied matters as much as applying them, for insurers, auditors and customers.
What problem it solves
Software vendors release fixes constantly, and attackers study those fixes to work out what was broken. Once a flaw is public, unpatched systems become easy targets, and many ransomware and data theft incidents begin with a known vulnerability that had a fix available. A company with hundreds of laptops, a few dozen servers, firewalls, switches and a long tail of applications cannot keep up by hand.
The practical problems are familiar: nobody is sure which devices are missing which updates, remote laptops rarely connect to the office network, an update once broke a line-of-business application so people are wary of the next one, and network gear and specialized systems get skipped entirely. Patch management turns this into a defined process with owners, schedules, exceptions and evidence, so updates go in predictably and gaps are visible rather than discovered after an incident.
How it works
Inventory. You can only patch what you know about. The process starts with a list of devices, operating systems, applications and versions, usually collected by an agent from your unified endpoint management (UEM) or patching tool, plus records for network equipment and servers.
Assessment and prioritization. New updates are matched against that inventory. Security updates are ranked by severity, by whether the flaw is known to be exploited, and by exposure: an internet-facing server comes before an isolated test machine. Results from vulnerability management scans often feed this step.
Testing. Updates are installed on a small pilot group first, often IT staff or a representative set of machines, to catch problems before a broad rollout. Critical servers may need testing in a separate environment.
Deployment. Updates roll out in rings or waves on a schedule, with maintenance windows for servers and network devices. Tools handle downloading, installing, restarting and retrying, including on laptops that work off the corporate network.
Verification and reporting. The tool reports which devices succeeded, failed or are still pending. Failures get followed up, exceptions are recorded with a reason and a review date, and summary reports show patch levels over time.
When it matters for buyers
- When cyber insurance renews. Insurers often ask how quickly critical patches are applied and how you track it; vague answers can affect coverage or premium.
- After an audit or security questionnaire. Customers and auditors frequently ask for evidence of patch levels, not just a policy.
- When choosing an MSP or help desk provider. Patching is often part of a managed IT contract, but scope varies: confirm whether third-party apps, servers and network firmware are included.
- When replacing endpoint management tools. Patching capability differs widely between tools, especially for third-party applications and non-Windows devices.
- When you still run end-of-life software. Systems the vendor no longer updates need a compensating plan or replacement.
Unpatched endpoints are a common entry point for ransomware, and patch levels are one of the measurable parts of your overall security posture. Our vulnerability management overview covers finding and ranking the weaknesses that patching fixes.
Questions to ask vendors
- Which operating systems, third-party applications, servers and network devices does your patching cover, and what is excluded?
- How do you patch laptops that rarely or never connect to our office network?
- What are your target timeframes by severity, and how are they measured and reported?
- How do you test updates before broad rollout, and how do you roll back a bad one?
- How are exceptions handled and documented, and who approves them?
- What reports can we hand to an insurer, auditor or customer as evidence?
- If you are a managed provider, who is responsible when a patch fails or breaks an application?
How it differs from vulnerability management
Vulnerability management is the wider discipline of finding security weaknesses across your environment, ranking them by risk and tracking them until they are resolved. Patch management is the operational process of getting vendor updates installed. They overlap heavily, since installing a patch is the most common way to fix a vulnerability, but they are not the same: some vulnerabilities are fixed by configuration changes or by removing software rather than patching, and some patches add features or fix bugs with no security impact. In practice, vulnerability scanning tells you what is exposed, and patch management is how much of it gets fixed.
