Internet-facing services are patched for critical vulnerabilities within 2 weeks (or 48 hours if an exploit exists). Office productivity suites, web browsers, email clients, PDF software, and security products are patched within 1 month.
Patch applications
Keeping your software up to date so it has the latest security fixes.
The case for it
What you lose without application patching.
Most cyberattacks exploit known vulnerabilities in software. The patches have usually been available for months. The attackers aren't clever; the defenders are slow. Patching your applications quickly removes the easiest way into your business.
Where you need to be
What each maturity level asks of application patching.
The Australian Cyber Security Centre (ACSC) sets a requirement for this control at each maturity level, ML1 through ML3. Your overall Essential Eight score is your weakest control rather than an average, so a gap here pulls the whole score down.
Patches for internet-facing services with known exploits are applied within 48 hours. Office productivity suites and similar are patched within 2 weeks.
All software patches are applied within 48 hours of release when an exploit exists. Applications no longer supported by vendors are removed.
Not sure which level you should aim for?
Three questions about your regulatory position and the data you keep will point you at the right target.
Take the maturity pickerThe rollout
Setting up application patching in your environment.
Patching follows a schedule you agree with us, inside your Maintenance Window. Internet-facing services are patched within 48 hours when an exploit is known in the wild. Browsers and office software follow a monthly cycle, measured against the ACSC minimums. A patch that breaks something is rolled back automatically and investigated the same day. Nothing vulnerable stays running while someone reviews it.
Free self-assessment
No email required.
Score yourself on all eight controls.
Eight questions, your estimated Essential Eight maturity level, and a branded PDF report you can share with your board, insurer, broker or auditor. Runs entirely in your browser. Nothing is sent to us unless you choose to book a call.
Take the self-assessmentAsked on client calls
Questions we get about application patching.
- What's the difference between this and OS patching?
- Operating system patching covers Windows, macOS and Linux themselves. Application patching covers everything you install on top: browsers, Adobe, Office, Teams, your line-of-business software. Attackers use whichever one is stale, so you need both.
- What about line-of-business software that can't be patched?
- Then you have a decision with a clock on it. Either the vendor will patch it, and we wait, or the vendor has abandoned it, and it needs replacing or isolating. We will help you put that to the vendor, or scope a replacement. Leaving it unpatched on your network is not a valid answer at maturity level 1 or above.
- Will my staff get constant reboot prompts?
- No. Reboots are scheduled inside your Maintenance Window with 2 to 4 hours' notice. A critical exploit can trigger an out-of-band patch at shorter notice. That is rare, and we tell you first.
- How do you know what's installed on every device?
- Intune inventory and our remote monitoring and management (RMM) agent give us a live software list across every managed device. A new application installed anywhere in the fleet shows up in our next sweep. You get the inventory report as part of your quarterly review.
Where to go next
Essential Eight controls that work with application patching.
Control 06
Patch operating systems
Keeping Windows, macOS, Linux and your server operating systems up to date.
Read the controlControl 01
Application control
Only letting approved programs run on your computers. Everything else is blocked by default.
Read the controlControl 04
User application hardening
Turning off features in web browsers and Office that attackers commonly abuse.
Read the controlThe maturity level summaries on this page are a plain-English version of the ACSC's published Essential Eight Maturity Model. For the full text, see the ACSC Essential Eight Maturity Model .
The qualifier
Let's see if we're a fit.
Seven questions, one moment of your time. We'd rather tell you now than three months in.