Patch Management for Australian SMBs: Meeting Essential Eight Requirements

IT technician reviewing a patch management dashboard in a Perth office

Most breaches don’t start with a clever attacker. They start with a known flaw nobody got around to fixing. Patch management closes those gaps, and it sits near the top of the Essential Eight. For Australian SMBs the hard part isn’t the tooling. It’s proving the process runs, with records to show for it.

Key Takeaways

  • Patching applications and operating systems are two of the eight strategies.
  • Maturity Level One sets a 48 hour deadline for critical flaws in online services.
  • Small business cybercrime reports averaged $56,600 in 2024-25 (ASD Annual Cyber Threat Report).
  • Assessors want evidence: scan records, patch logs and documented exceptions.

What The Essential Eight Requires

The Essential Eight names patching twice, once for applications and once for operating systems. ASD’s Essential Eight maturity model sets firm deadlines at Maturity Level One: 48 hours for critical vulnerabilities in online services, two weeks for most other software. Daily vulnerability scanning is mandatory too.
What needs patchingLevel One deadline
Online services, critical or exploited48 hours
Online services, non-criticalTwo weeks
Office suites, browsers, email, PDF, security productsTwo weeks
Internet-facing servers and devices, critical48 hours
Workstations and non-internet-facing systemsOne month
Unsupported productsRemove or replace

Quotable

Essential Eight patching is measured in hours and days, not quarters. Maturity Level One asks for automated asset discovery at least fortnightly, daily vulnerability scanning of online services, and patches applied inside 48 hours whenever a vendor rates a flaw critical or a working exploit already exists.

Why Smbs Fall Behind, And How To Fix It

IT technician reviewing a patch management dashboard in a Perth office

Nobody skips patching on purpose. It slips because patching competes with billable work, because one legacy application breaks on reboot, and because nobody owns the schedule.

ASD’s Annual Cyber Threat Report 2024-25 logged over 84,700 cybercrime reports, one every six minutes. The fix is ownership: fold patching into a managed IT plan alongside your cyber security controls.

  • Discover assets automatically at least fortnightly, including remote devices.
  • Keep emergency patching separate from routine monthly maintenance.
  • Log every deferral with an owner and a review date.

Quotable

Evidence matters as much as action. An Essential Eight assessment looks for scan records, patch deployment logs and documented exceptions with review dates. A business that patches diligently but keeps no records will still be assessed at Maturity Level Zero for that strategy.

Frequently Asked Questions

Does every Australian SMB have to comply with the Essential Eight?

It’s mandatory for non-corporate Commonwealth entities and increasingly written into contracts, insurance policies and tenders. Most private SMBs aren’t legally bound, but clients and insurers now ask. Maturity Level One is a sensible baseline, and our guide to cybersecurity for Australian small businesses covers the rest.

What maturity level should a small business aim for?
Start at Maturity Level One across all eight strategies before pushing any single one higher. ASD is explicit about this: strong progress on one strategy while the others lag still leaves exploitable gaps. Most SMBs without government contracts sit comfortably at Level One.
Can automatic updates alone meet the requirement?

Not on their own. Automatic updates handle part of the workload, but they don’t give you asset discovery, vulnerability scanning or the deployment records an assessor asks for. Pairing them with monitoring, such as a SIEM, closes the visibility gap on firmware and third-party apps.

Talk To Tecnic About Your Patching Gaps

Not sure where your patching sits against Maturity Level One? Tecnic Group’s Perth team covers operating systems and third-party software in every managed plan, including our IT services for small business. Get in touch for a straight answer on where your gaps are.

Related articles

Security analyst reviewing SIEM dashboards on dual monitors

What Is a SIEM, and Does Your Small Business Need One?

Every system in your business writes a log: firewall, laptops, email, Microsoft 365. Thousands of events an hour, and nobody reads them. A SIEM is the tool that does the reading. Here’s what it is, what it costs, and whether your business needs one at all. Key Takeaways: A SIEM

Read more