Cybersecurity

Your machines say up to date. That is not the same as patched.

An update arrow dropping into a tray beside a clock face, representing security updates waiting to be installed inside a deadline

Open Settings on any machine in your office and it will almost certainly say the same thing. You're up to date. Last checked: today. Reassuring. Also quite narrow.

That message covers Windows. It says nothing about the PDF reader, the browser extension somebody installed in March, the firewall in the comms cupboard, or the accounts package that stopped receiving security updates the month its subscription lapsed. Most of what gets exploited on a small business network is not Windows itself. It is the other twenty pieces of software on the machine, and the tick in Settings is silent about every one of them.

The clock starts when the vendor ships, not when you notice

There are two published timescales worth knowing, and they are not the same number.

Cyber Essentials sets the one most people have heard. All critical and high risk updates, plus any update where the vendor provides no details, must be installed within 14 days of release by the vendor. That last clause does more work than it looks like it does. A release note reading bug fixes and stability improvements tells you nothing, so it counts as if it were serious.

The threshold is defined too. IASME describes critical or high risk as a CVSS v3 base score of 7 or above, which at least makes the argument checkable rather than a matter of opinion between you and an assessor.

NCSC's own vulnerability management guidance asks for considerably more. Its table gives 5 days for internet-facing services and software, 7 days for operating systems and applications, and 14 days for internal or air-gapped systems. So the fourteen days everybody quotes is the slowest row on NCSC's chart, applied to the systems least exposed to anything. For the laptop your sales manager takes to a coffee shop, the number NCSC has in mind is seven.

NCSC does add a sensible caveat: for business-critical systems, balance those timescales against availability. Nobody is asking you to reboot the till system at half past two on a Saturday. But that is a reason to schedule properly, not a reason to run three months behind.

One detail from the same guidance is worth carrying around, because it changes how you think about skipping an update you have judged unimportant. Vendors publish advisories for some vulnerabilities and, in NCSC's own word, silently fix others without ever saying so. Miss a release and you also miss the fixes nobody announced. You will never know which ones they were.

Windows Update patches Windows. That is roughly the extent of it.

This is the single biggest gap we see, and it is invisible from the machine itself, because Windows reports honestly on the only thing it was asked about.

Microsoft's other products are not automatically included. Office, and the rest of the Microsoft catalogue, arrive through Windows Update only when the AllowMUUpdateService policy is turned on. Where it isn't, the machine can be genuinely up to date on Windows and running an Office install that has not been touched in a year.

Everything that isn't Microsoft is on its own entirely. Chrome and Firefox update themselves quietly and do it well, provided somebody restarts the browser occasionally. Zoom, Adobe Reader, your line-of-business application and whatever the accounts department downloaded in 2021 all have their own updaters, and their own habit of waiting for an administrator password nobody in the room has.

Cyber Essentials does not accept any of that as an excuse, and its scope list is specific: the operating system, firmware for firewalls and routers, the web browser and its extensions, all applications, anti-virus, and hypervisors. Browser extensions being named individually is telling. An extension runs inside the browser with access to everything on the page, updates through a store that a user with a personal account may well control, and appears on no inventory anybody keeps.

Since 26 April 2026 this is graded harder than it used to be. Two questions in the Danzell set became automatic fails: A6.4 covers operating systems and router and firewall firmware, A6.5 covers applications including associated files and extensions. Miss either and the assessment fails, whatever the rest of your answers look like.

Downloaded is not installed

Quality updates normally land on the second Tuesday of the month. What happens next is where estates quietly drift.

An update that has downloaded and is waiting for a restart has not been applied. The vulnerability is still there. The machine will still tell the user everything is fine, because from its point of view it has done its part and is waiting on a human. Ask around any office how many people shut down at night rather than closing the lid, and you have your answer for how long that state lasts on laptops.

Then there are the settings somebody chose once and nobody has looked at since. Quality updates can be deferred by up to 30 days as a matter of policy. They can be paused for up to 35, after which the pause expires by itself. Both numbers are longer than the fourteen days you are supposed to be working to, which means an estate can be fully compliant with its own configuration and out of compliance with the standard at the same time.

Pausing is worse than it sounds, and Microsoft's documentation is admirably blunt about it. Activating a pause clears active restart notifications, cancels any pending restarts, cancels any pending update installations, and an installation that happens to be running at that moment will attempt to roll back. So the person who pauses updates on the morning of a client presentation is not merely delaying the next patch. They may be reversing one that had already gone on.

Two more defaults are worth checking while you are in there. Drivers can be excluded from quality updates with a single policy, which some businesses set years ago after one bad printer driver and never revisited. And optional updates are not installed by default at all.

The boxes with a web interface and no update button

Firewall and router firmware sits inside the auto-fail question, which puts it on a level with the operating system. It rarely gets treated that way.

Network kit in a small office usually does not update itself. There is no monthly prompt, no notification area icon, and nobody signed up for the vendor's advisory mailing list when the device was installed. It will run happily on the firmware it shipped with for as long as the hardware lasts. The only thing that changes that is somebody logging in on purpose, on a date somebody wrote down.

The same goes for anything else with an IP address and a login page. Network storage, the CCTV recorder, the wireless access points in the ceiling. Check whether the manufacturer still issues firmware for them at all, because a device that stopped receiving updates in 2022 is in the same position as an unsupported operating system, just harder to notice.

The software you are not allowed to patch

Sometimes the update is not available to you, and the reasons are worth separating.

Licensing is the one that surprises people. IASME says it plainly: some software requires annual subscriptions to be in place to receive security updates. Let a renewal lapse and the application keeps running, keeps opening files, and stops getting fixed. Nothing warns you. It is the same failure as an expired backup licence, and it turns up in exactly the same way, which is late.

Then there is software the vendor has abandoned. Cyber Essentials allows one route out, and it is narrower than most people assume: legacy software can be excluded from scope only by moving it into a well-defined, segregated and separately managed sub-set that prevents all traffic to and from the internet. A machine on the same flat network as everything else is not segregated because you have agreed among yourselves that it is special. If the old application can reach the internet, or anything that can, it is in scope.

If this describes a machine you kept back when the rest of the office moved on, our guide to Windows 10 reaching end of support covers the same problem at operating-system level, including what the extended security updates actually buy you.

What this looks like on a twenty-machine estate

None of the following needs a large budget. It needs somebody to own it.

Start with a list, because you cannot patch software you do not know about. Every machine, every network device, and the applications actually installed rather than the ones on the standard build from three years ago. Nearly every estate we look at has software on it nobody in the business can account for.

Set automatic updates as the default and leave them that way. NCSC's position is that operating system and application updates should be applied automatically, as soon as an update is published, with a phased rollout of something like ten percent of the estate a day so a bad release can be paused or rolled back before it reaches everyone. Small businesses tend to invert this, testing nothing and delaying everything, which gets the worst of both.

Deal with restarts separately from updates. They are a different problem with a different fix, which is usually a deadline policy and a conversation about shutting machines down at night rather than a technical control.

Put non-Microsoft software on a proper updating tool rather than trusting each application's own nagging. This is the part that needs software of some kind, and it is the part that closes the gap the tick in Settings hides.

Then produce evidence monthly. Not a feeling that it is probably fine, but a list of machines with their patch state, the ones that failed, and the ones nobody has seen online for six weeks because they are in a drawer. A machine that stopped reporting is the most useful line on that report and the easiest to skim past.

Worth saying: patching is not a substitute for the other controls, and none of them substitute for it either. It sits alongside multi-factor authentication and endpoint detection, and it is one of the first things an insurer asks about on a cyber insurance proposal form.

Where we come into it

Said plainly, because this article quotes Cyber Essentials requirements throughout and it would be easy to read something into that. Alpha IT does not hold Cyber Essentials or Cyber Essentials Plus, and we are not an assessor. We use the requirements because they are published and free for anyone to read, which makes them a better yardstick than our opinion.

What we do is the ordinary version. Our Essential plan, at £50 per user per month excluding VAT, includes automated patch management, the asset register this all depends on, and a monthly health report so the patch state is something you can look at rather than something you assume. If you want the full picture of what is on your network first, including the machines nobody has thought about since they were bought, that is what the free IT health check is for.

The question worth asking in your own office this week is a small one. Not are updates on, because they will be. Ask how many machines are currently sitting on a downloaded update, waiting for somebody to restart them.

Frequently asked questions

How quickly do we actually have to install security updates?+

It depends which standard you are being measured against. Cyber Essentials requires all critical and high risk updates, and any update where the vendor gives no details, to be installed within 14 days of the vendor releasing it. NCSC's own vulnerability management guidance is tighter than that: 5 days for internet-facing services and software, 7 days for operating systems and applications, and 14 days for internal or air-gapped systems. The 14 days people quote is the certification floor, not the recommendation.

What counts as a critical or high risk update?+

IASME gives a number for it. Critical or high risk can also be described as a CVSS v3 base score of 7 or above. The awkward part is the second half of the rule: updates with no details provided count too. Plenty of vendors ship a release note saying nothing more useful than bug fixes and stability improvements, and you cannot score what you cannot see, so those are treated as if they matter.

Does Windows Update cover everything on the machine?+

No, and this is the gap that catches most small businesses. Windows Update handles Windows. Other Microsoft products such as Office only come through it when the AllowMUUpdateService policy is switched on, and everything that isn't Microsoft updates on its own schedule or not at all. Cyber Essentials puts all of it in scope by name, including browser extensions, firewall and router firmware, anti-virus and hypervisors.

We have automatic updates switched on. Isn't that enough?+

It is the right default and it is not the whole job. An update that has downloaded and is waiting for a restart has not been applied, and a laptop that gets its lid closed every evening instead of being restarted can sit in that state for weeks. Check what your machines are actually running rather than what they have been offered.

Does pausing updates for a few days matter?+

More than people expect. Microsoft's own documentation says that activating a pause cancels any pending restarts, cancels any pending update installations, and that an installation already running when the pause starts will attempt to roll back. Somebody pausing updates the morning of a client presentation can undo a patch that had already gone on. The pause expires by itself after 35 days, which is past the 14-day window.

What about the firewall and the router?+

Firmware for firewalls and routers is named in the Cyber Essentials scope list, and since 26 April 2026 it sits inside question A6.4, which is an automatic fail. Most small business network kit does not update itself, nobody gets an email when a release comes out, and the device is quite happy to run four-year-old firmware indefinitely. Put it on a calendar or give it to somebody whose job is checking.

We have one old application that cannot be updated. What now?+

Two honest options, and neither is ignoring it. Replace it, or move it out of scope properly, which Cyber Essentials defines as a well-defined, segregated and separately managed sub-set that prevents all traffic to and from the internet. A machine sitting on the same flat network as everything else is not segregated because you have written down that it is special.

Do we need Cyber Essentials for any of this to be worth doing?+

No. The certification is a useful checklist and some contracts require it, but the reason to patch is that unpatched software is how most small businesses get compromised. Alpha IT does not hold Cyber Essentials or Cyber Essentials Plus and is not an assessor, so nothing here is us marking anyone's homework. We use the requirements because they are published, specific and free to read.

Call usFree consultation