Patch the things attackers can reach from the internet within a week, patch everything else monthly, and keep a written list of the three systems you cannot patch at all. That is a complete patch management policy for a business under a hundred people, and it fits on an index card. The reason to write it down is not compliance theatre. It is that the alternative, patching whatever the dashboard shouts loudest about, reliably leaves the edge of your network six weeks behind.

The number that should change your mind
For years the sensible summary of breach data was that attackers log in rather than break in. Stolen credentials led the charts, and the advice followed: multi-factor authentication first, everything else later. That changed in the 2026 Data Breach Investigations Report. Verizon, drawing on more than 31,000 incidents and over 22,000 confirmed breaches across 145 countries, reported that exploitation of vulnerabilities had become the number one breach entry point, overtaking stolen credentials for the first time in the report’s nineteen-year history. Credential abuse accounted for 13% of breaches.
The reason given is not subtle. Automated tooling, increasingly machine-assisted, finds and weaponises known flaws faster than defenders install the fixes. CISA put the defensive side of that equation in numbers in June 2026: across 2025 organisations fully remediated just 26% of the vulnerabilities on the Known Exploited Vulnerabilities catalogue, down from 38% the previous year, and the median time to full resolution rose to 43 days. These are flaws confirmed to be exploited in the wild, with a free public list of exactly which ones they are. Three-quarters were still outstanding.
If you take one thing from that, make it this: you do not need better intelligence than everyone else. Most organisations are not acting on the free, public list of flaws that are definitely being exploited right now. Acting on it puts you ahead.
Start by knowing what you actually run
You cannot patch an inventory you do not have, and inventory is where almost every small business patching programme quietly dies. The good news is that the version you need is far cruder than the one a vendor will sell you.
Build one spreadsheet with five columns: the thing, who owns it, whether it is reachable from the internet, what updates it and how often, and what breaks if it goes down for an hour. Include the laptops, the router, the NAS in the cupboard, the WordPress site, the printer with a web interface, and the two cloud services you self-manage. Half a day of work and you will find at least one thing nobody knew was online.
- The router or firewall’s own firmware, which usually updates manually and therefore never.
- A network-attached storage box bought years ago, still reachable because remote access was enabled once for a weekend.
- WordPress or plugin updates on a marketing site that a departed agency used to manage.
- Remote desktop or VPN appliances, which are the single most attacked category on the KEV catalogue.
- A personal device that has the company email account on it and has not been updated in a year.
Keep the internet-exposure column honest. Reachable means reachable by a stranger without a credential, including through port forwarding somebody set up in 2021. The quickest way to check is to look at your router’s forwarding rules and your DNS records, and to be suspicious of anything you cannot explain.
Four signals that decide what gets patched first
Four signals, in this order. Severity scores come last, which surprises people.
| Signal | What it tells you | Where to get it free | How to use it |
|---|---|---|---|
| Internet exposure | Whether a stranger can reach the flaw without credentials | Your own firewall rules, DNS records and hosting console | Promotes anything exposed to the front of the queue regardless of score |
| Known exploitation (CISA KEV) | Real-world exploitation has been confirmed, not theorised. 1,730 entries as of 30 September 2026, 246 added in 2026 | The KEV catalogue and its JSON feed on cisa.gov | Treat a KEV match on an exposed system as this week’s work |
| Exploitation probability (EPSS) | A daily-updated probability, from 0 to 1, that a given CVE will be exploited in the next 30 days | FIRST’s EPSS data and API | Use it to triage the long tail that is not on the KEV catalogue |
| Severity score (CVSS) | A 0 to 10 technical severity rating of the flaw itself | The NIST National Vulnerability Database | Use it last, as a tie-breaker. A 9.8 on an isolated internal box beats a 7.5 on your VPN only in theory |
The common mistake is to sort by CVSS and work down. That produces a queue dominated by critical-rated flaws in software nobody can reach, while a medium-rated authentication bypass in your VPN appliance sits at position forty. Exposure first, evidence of exploitation second, probability third, severity last.

What CISA changed in 2026, and why it matters to a small business
In June 2026 CISA replaced its long-standing patching directives with Binding Operational Directive 26-04, ‘Prioritizing Security Updates Based on Risk’. The new directive superseded and revoked both BOD 19-02 from 2019 and BOD 22-01 from 2021. It only binds US federal civilian agencies, but the reasoning is directly useful to anyone running a small estate, and CISA explicitly encourages other organisations to borrow it.
The old rule was a single clock. Under BOD 22-01, anything added to the KEV catalogue had to be remediated within two weeks if its CVE identifier was assigned in 2021 or later, and within six months for older identifiers. Every KEV entry was treated as equally urgent. The new rule asks four questions about each vulnerability instead.
- Is the affected asset publicly exposed?
- Can an attacker fully automate exploitation?
- Does exploitation give the attacker total control of the system?
- Is there evidence of real-world exploitation, meaning it is on the KEV catalogue?
Only vulnerabilities that tick all four get the shortest clock, which CISA set at three calendar days and paired with a requirement to carry out a forensic triage of the asset to check whether it has already been compromised. Everything else gets a longer timeline, and the directive explicitly allows the lowest-risk items to be deferred until the next system upgrade.
| BOD 22-01 (2021, revoked) | BOD 26-04 (2026, current) | |
|---|---|---|
| Trigger | Any entry added to the KEV catalogue | Four risk characteristics assessed per vulnerability instance |
| Shortest clock | Two weeks for CVE IDs assigned 2021 or later | Three calendar days, plus forensic triage of the asset |
| Older vulnerabilities | Six months for CVE IDs assigned before 2021 | Judged on the same four characteristics as everything else |
| Lowest-risk items | Still carried the catalogue deadline | May be deferred to the next system upgrade |
| Observed effect at one large agency | Every KEV entry an equal fire | 1% of vulnerability instances in the three-day tier, over 60% deferred |
That last row is the figure worth remembering. At one large civilian agency’s first pass, only 1% of vulnerability instances fell into the three-day category, and more than 60% qualified for deferral to the next system upgrade. A risk-based queue is not a longer queue. It is a much shorter one, aimed at the right end of your network.
CISA, ‘Patch Smarter, Not Harder’, June 2026Only the highest risk vulnerabilities must be patched within three days.
A cadence that survives a busy quarter
Here is the cadence. It assumes one person spends about three hours a month on this, which is realistic for a business of twenty to eighty people.
- Weekly, 20 minutes. Check the KEV catalogue additions against your inventory’s internet-facing column. Patch any match now. If you cannot patch it today, take it off the internet today.
- Monthly, 90 minutes. Apply operating system and application updates across laptops and servers. Let the platform’s own update service do the work; your job is to confirm it ran, not to install anything by hand.
- Monthly, 30 minutes. Firmware on the router, firewall, switches, access points and NAS. This is the category that silently falls two years behind.
- Quarterly, 60 minutes. Review the exception list. For each thing you cannot patch, confirm the containment is still in place and still works.
- Annually, half a day. Rebuild the inventory from scratch rather than updating it. You will find things that have been added without anyone telling you.
Automate the monthly layer entirely. Windows Update for Business, managed software updates on macOS, unattended-upgrades on Debian or Ubuntu, and automatic minor-version updates in WordPress all do the boring 90% without supervision. Reserve human attention for the weekly exposure check and the exception list, because those are the two places judgement is actually required.

The awkward cases: firmware, appliances and that one old server
Every small business has three or four things it cannot patch. A machine running software that only works on an old operating system. An appliance whose vendor stopped shipping firmware. A line-of-business application that breaks when the database is updated. Pretending otherwise is how the policy becomes fiction.
Write each one down with four fields: what it is, why it cannot be patched, what you have done instead, and when you will revisit the decision. Containment usually means one or more of: remove it from the internet, put it on its own network segment with no outbound access, restrict which machines can talk to it, and take more frequent backups of whatever it holds. CISA’s own guidance makes a related point: attackers compromising core networks tend to use valid credentials and exploitable configurations rather than product flaws, which is why segmentation and phishing-resistant multi-factor authentication do so much of the work. Our multi-factor authentication guide covers that side.
The revisit date matters more than it looks. An exception with no date becomes permanent within a year. An exception with a date gets argued about, and sometimes the argument ends with somebody finally replacing the thing.
Testing when you have no test environment
Small businesses rarely have a staging environment, and building one for patch testing is usually not worth the money. Three cheaper habits get you most of the safety.
- Stagger by group. Patch your own machine and two volunteers’ machines first, wait 48 hours, then do everyone else. This is what update rings are, and both Windows and macOS management tools do it for free.
- Snapshot before you touch a server. A virtual machine snapshot or a filesystem snapshot takes seconds and turns a bad update into a five-minute rollback. Delete the snapshot a week later so it does not become your backup strategy.
- Know your rollback before you start. For each tier 1 system, write down the one-line answer to ‘how do I undo this’. If there is no answer, that is the finding, not the patch. Our ransomware protection guide covers the restore testing that underpins all of this.
One exception to the staggering rule: when something on your internet-facing list is actively exploited, patch it immediately on everything. The risk calculation inverts. A broken application is an inconvenience you can fix in an afternoon; a compromised edge device is an incident that takes weeks.
What to measure, and what to ignore
Two numbers tell you whether the cadence is holding. First, the age of the oldest unpatched internet-facing system, in days. Second, the number of items on your exception list. Both should be small, and both are easy to produce without a tool.
Ignore total vulnerability counts. A scanner that reports 4,000 findings across thirty machines is telling you about library versions, not about risk, and the number only ever goes up. Ignore patch compliance percentages too, for the same reason: 97% compliant sounds excellent until the 3% is your firewall.
If you want the weekly exposure check and the monthly automation set up once and then left running, that is a small piece of work. Our cybersecurity services cover the inventory, the automation and the exception register, delivered remotely. And because patching and phishing are the two routes that account for most small-business incidents, it is worth reading our guide to stopping phishing attacks alongside this one.
Frequently asked questions
Is monthly patching good enough in 2026?
For internal systems, yes. For anything reachable from the internet, no. The split matters more than the frequency: a weekly check against CISA’s KEV catalogue for your exposed systems, plus monthly automated updates everywhere else, is a defensible policy for a small business and takes about three hours a month to run.
We have no security team. Who should own this?
One named person, usually whoever owns IT alongside another job, with a calendar entry and a one-page policy. Ownership matters more than expertise here, because the work is mostly checking that automation ran and that nothing new appeared on the internet-facing list. Escalate the judgement calls rather than the routine.
Should we pay for a vulnerability scanner?
Eventually, but it is not the first purchase. Start with the inventory, the KEV catalogue and your platform’s own update reporting, all free. Buy a scanner when you have more machines than you can list from memory, or when a customer or insurer asks for scan evidence. A scanner without an inventory just produces a longer list of things you will not fix.
What is EPSS, and do we need it?
The Exploit Prediction Scoring System, published by FIRST, estimates the probability that a given vulnerability will be exploited in the next 30 days. It is free and updated daily. For a small estate it is a nice-to-have: the KEV catalogue already tells you what is being exploited now, and EPSS mainly helps you sort the much larger set of flaws that are not on it yet.
How do we handle a vendor that stops shipping updates?
Treat it as an exception with a replacement date, not as a permanent state. In the meantime take it off the internet, restrict which machines can reach it, and back up whatever it holds more often. Unsupported software on an isolated segment is a managed risk; the same software with a public IP address is an open door.
If your patching currently means clicking update when a prompt gets annoying, we can set up the inventory, the weekly exposure check and the automation, then hand it back to you documented. Get in touch with Eudora Technology to talk about your project.



