Back to Glossary

Entry · Business

Patch Management

Patch management is the repeatable process of finding, prioritising, obtaining, installing and verifying software and firmware updates across an organisation. It includes security fixes, bug fixes and upgrades. The aim is to reduce exposure without unnecessarily disrupting business systems.

From the Money Master HQ dictionary, founded by Shihan Sheriff (FCMA, VP of Finance at Nomod, CFO at Esanjo Ventures). How these definitions are written.

What it means

A vendor discovers a flaw in a software product and releases an update, but installing it on one laptop does not protect the other laptops, servers and devices using that product. Patch management makes the response consistent across the business.

NIST describes identifying, prioritising, acquiring, installing and verifying updates, and these steps are preventive maintenance, not a single monthly click. First build an inventory that includes laptops, servers, phones, network gear, cloud workloads, applications and embedded systems where practical, because an unknown system cannot be patched systematically.

Record software versions, since the same product may need different fixes by version or operating system and a device list without installed versions misses that distinction. Assign owners who approve maintenance windows, operate update tools and handle exceptions, with security teams setting policy while system owners validate service effects.

Track vendor notices from authentic vendor channels rather than random download links, since vendors publish fixes, supported versions and sometimes emergency instructions. Prioritise risk, because a flaw already exploited by attackers can deserve urgent action, and CISA's Known Exploited Vulnerabilities catalogue is one input, not a complete list of every risk.

Look at exposure and business impact too, since a public web server and an isolated test device can face different immediate risks, and define deadlines by risk, because a single "patch everything within 30 days" target can leave urgent systems exposed and the exact time limit belongs in the organisation's risk policy. Test where needed, since an update can affect a billing system or medical device differently from an ordinary laptop, and use representative systems before broad rollout.

Stage deployment by trying a small group, then larger groups, while checking failures, though an urgent exploit may require a faster path with compensating controls. Plan downtime for server restarts and application dependencies by agreeing maintenance windows and telling affected teams, and take backups with a rollback plan, remembering that a backup is useful only if restoration has been tested.

Install from trusted sources such as central tools and verified vendor channels, which reduce the chance of counterfeit updates, and record the target version. Verify installation, because a successful deployment job is not proof that a system is protected, so check version, reboot status and vulnerability scan results as appropriate.

Investigate failures such as offline devices, insufficient storage and incompatible applications, and retry or create a documented exception rather than marking the campaign complete. Track unsupported software, firmware and third-party applications, since a vendor may no longer provide fixes, routers and other devices may need special update methods, and browsers, document readers and business plugins can carry exploitable flaws that operating-system updates do not cover.

Document exceptions with owner, reason, risk, mitigation and review date, measure coverage by reporting how many in-scope devices have the required updates and how long urgent gaps stay open, because a headline percentage can hide one exposed crown-jewel server, and separate patching from vulnerability management, since scanning finds weaknesses and patching is one response among configuration changes, isolation or retirement. After an incident, ask whether a missing inventory item, delayed decision or failed verification allowed exposure, budget for automation, testing and maintenance windows as ordinary operating maintenance, and remember that for an owner the key question is whether the business knows what needs fixing, fixes it in risk order and checks that the fix actually landed.

In practice

Real-world examples.

1

Example

A company rolls out tested monthly laptop updates and confirms reboot completion. A small pilot group receives the update first, and the wider rollout follows once no failures appear. The dashboard shows both deployment and verified versions.

2

Example

An internet-facing server with a known exploited flaw gets an urgent change window. The team takes a backup, applies the vendor fix outside the monthly cycle and checks the installed version afterwards. The change is documented with the risk reason.

3

Example

A dashboard flags 30 offline devices that missed an update campaign. The team contacts owners, retries the installation when devices reconnect and records a documented exception for any that cannot be updated. The campaign is not marked complete until the gaps are resolved.

Formula

Calculation

Patch compliance = in-scope devices verified current / total in-scope devices x 100. If 470 of 500 are verified current, the illustrative rate is 94%. Report the 30 remaining devices and their risk as well. Worked example with risk weighting: of the 30 devices still unpatched, 25 are laptops in the office and 5 are internet-facing servers with a known exploited flaw. The headline rate of 94% looks healthy, but the 5 servers represent 5 / 500 = 1% of devices and most of the risk. Verified urgent coverage for the exploited flaw is 0 of 5 = 0%, so the team escalates those servers first, even though the overall figure is high.

Case study

Seen in the real world.

Entirely fictional case: Summit Clinics finds an old server that missed a security patch for months because it was absent from inventory. It isolates the server, assesses exposure and tests the vendor update. After installation, the team verifies the version and adds an inventory check. A claimed 95% coverage figure would not excuse a remaining high-risk server. The review also finds that the monthly report counted deployment attempts as successes.

Summit changes the report to show verified versions and the age of every urgent gap. The case is invented and shows a process lesson, not a prediction for any real organisation. Leaders at Summit then agree a modest annual budget for inventory tooling and test devices. They treat the cost as ordinary operating maintenance, in the same way as servicing clinical equipment.

Watch out

Common mistakes.

  • Delaying a known exploited fix because it is outside a monthly cycle.
  • Counting deployment attempts as successful patches without verification.
  • Leaving unsupported systems or offline devices outside the inventory.

Questions

People also ask.

What is patch management?

It is the process of identifying, prioritising, installing and verifying updates across systems.

Why does it matter?

Unpatched flaws can create avoidable security and reliability risks.

How fast should patches be applied?

Set deadlines by exploit evidence, exposure and business impact, with an urgent path for high-risk flaws.

Was this explanation helpful?

From the founder's library

Accounting Fundamentals: A Non-Finance Manager's Guide to Finance and Accounting, by Shihan Sheriff

Take it further with the book.

Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.

US$2.24US$2.99

25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.

View the book and save 25%
Last updated · October 8, 2026
Browse all terms →

Disclaimer

The information provided in this finance dictionary is for educational and informational purposes only. It should not be construed as financial, investment, legal, or tax advice. Always consult with a qualified professional before making any financial decisions. Money Master HQ makes no representations or warranties about the accuracy, completeness, or suitability of this information. Use of this content is at your own risk.