Most breaches don’t start with a clever attacker. They start with a known flaw nobody got around to fixing. Patch management closes those gaps, and it sits near the top of the Essential Eight. For Australian SMBs the hard part isn’t the tooling. It’s proving the process runs, with records to show for it.
Key Takeaways
- Patching applications and operating systems are two of the eight strategies.
- Maturity Level One sets a 48 hour deadline for critical flaws in online services.
- Small business cybercrime reports averaged $56,600 in 2024-25 (ASD Annual Cyber Threat Report).
- Assessors want evidence: scan records, patch logs and documented exceptions.
What The Essential Eight Requires
| What needs patching | Level One deadline |
|---|---|
| Online services, critical or exploited | 48 hours |
| Online services, non-critical | Two weeks |
| Office suites, browsers, email, PDF, security products | Two weeks |
| Internet-facing servers and devices, critical | 48 hours |
| Workstations and non-internet-facing systems | One month |
| Unsupported products | Remove or replace |
Quotable
Essential Eight patching is measured in hours and days, not quarters. Maturity Level One asks for automated asset discovery at least fortnightly, daily vulnerability scanning of online services, and patches applied inside 48 hours whenever a vendor rates a flaw critical or a working exploit already exists.
Why Smbs Fall Behind, And How To Fix It

Nobody skips patching on purpose. It slips because patching competes with billable work, because one legacy application breaks on reboot, and because nobody owns the schedule.
ASD’s Annual Cyber Threat Report 2024-25 logged over 84,700 cybercrime reports, one every six minutes. The fix is ownership: fold patching into a managed IT plan alongside your cyber security controls.
- Discover assets automatically at least fortnightly, including remote devices.
- Keep emergency patching separate from routine monthly maintenance.
- Log every deferral with an owner and a review date.
Quotable
Evidence matters as much as action. An Essential Eight assessment looks for scan records, patch deployment logs and documented exceptions with review dates. A business that patches diligently but keeps no records will still be assessed at Maturity Level Zero for that strategy.
Frequently Asked Questions
It’s mandatory for non-corporate Commonwealth entities and increasingly written into contracts, insurance policies and tenders. Most private SMBs aren’t legally bound, but clients and insurers now ask. Maturity Level One is a sensible baseline, and our guide to cybersecurity for Australian small businesses covers the rest.
Not on their own. Automatic updates handle part of the workload, but they don’t give you asset discovery, vulnerability scanning or the deployment records an assessor asks for. Pairing them with monitoring, such as a SIEM, closes the visibility gap on firmware and third-party apps.
Talk To Tecnic About Your Patching Gaps
Not sure where your patching sits against Maturity Level One? Tecnic Group’s Perth team covers operating systems and third-party software in every managed plan, including our IT services for small business. Get in touch for a straight answer on where your gaps are.



