Skip to content
Menu

Essential Eight patch applications

Close known holes before attackers find them.

Patching applications means installing vendor security fixes for browsers, Office, PDF readers and anything reachable from the internet, within set deadlines.

A laptop on an office desk showing an update in progress, with a coffee mug and a notebook beside it.

At a glance

Control
02 of 08 · Prevent attacks
Stops
Exploits of known software flaws
Typical tools
Intune, a patch management platform, a vulnerability scanner
Effort
Medium, ongoing

What is application patching?

Where it stops an attack.

  1. The attack A flaw in a VPN or PDF reader is published, and attackers scan the internet for copies that haven’t been fixed.
  2. Stopped here The fix was installed inside the deadline, before the scan reached you.
  3. The result The known way in is already closed.
ML1 Maturity Level 1. ML2 Maturity Level 2. ML3 Maturity Level 3.
Online services 48 hours if critical or exploited, otherwise 2 weeks No change No change
Office, browsers, email, PDF and security software 2 weeks No change 48 hours if critical or exploited, otherwise 2 weeks
All other applications Not required 1 month No change
Asset discovery and scanning Discovery fortnightly. Scans daily for online services, weekly for common appsAdds fortnightly scans of other apps No change
Unsupported software Remove online services and common apps No change Remove all unsupported applications

Each level includes everything in the one before. A plain-English summary, not the requirement text. ASD Essential Eight Maturity Model (November 2023)

How to patch applications

Protection first, disruption last.

  1. 01

    Know what you have

    An automated software inventory across every device, refreshed at least fortnightly.
  2. 02

    Automate the common apps

    Browsers, Microsoft 365 apps and PDF readers update themselves, with reports to prove it.
  3. 03

    Fast-track internet-facing systems

    Firewalls, VPNs and remote access get a 48-hour process for critical or exploited flaws.
  4. 04

    Retire unsupported software

    If the vendor has stopped patching it, remove or replace it.
  • Trusting auto-update blindly

    Updates fail silently. Without reports you don’t know who is behind.

  • Forgetting the firewall and VPN

    They run software too, and attackers scan for them first.

  • Keeping old software “just in case”

    Unsupported PDF readers and runtimes are easy targets.

Application patching questions

What clients ask before we start.

How quickly do we need to patch applications?
Does Microsoft 365 patch itself?
What counts as an online service?

Find out where you stand on application patching.

Book a free 45-minute Essential Eight review with a Perth engineer. You get your maturity on all eight controls and what to fix first. The report is yours to keep.

Or call (08) 9467 2269

What’s bugging you
Staff

A Perth engineer, not a salesperson, replies within one business day.

We hold ISO/IEC 27001:2022 certification from BSI, certificate IS 840964.