What is application patching?
Where it stops an attack.
- The attack A flaw in a VPN or PDF reader is published, and attackers scan the internet for copies that haven’t been fixed.
- Stopped here The fix was installed inside the deadline, before the scan reached you.
- The result The known way in is already closed.
Essential 8 patching timeframes for applications
What changes at each level.
Each level includes everything in the one before. A plain-English summary, not the requirement text. ASD Essential Eight Maturity Model (November 2023)
How to patch applications
Protection first, disruption last.
- 01
Know what you have
An automated software inventory across every device, refreshed at least fortnightly. - 02
Automate the common apps
Browsers, Microsoft 365 apps and PDF readers update themselves, with reports to prove it. - 03
Fast-track internet-facing systems
Firewalls, VPNs and remote access get a 48-hour process for critical or exploited flaws. - 04
Retire unsupported software
If the vendor has stopped patching it, remove or replace it.
Common application patching mistakes
Where rollouts go wrong.
-
Trusting auto-update blindly
Updates fail silently. Without reports you don’t know who is behind.
-
Forgetting the firewall and VPN
They run software too, and attackers scan for them first.
-
Keeping old software “just in case”
Unsupported PDF readers and runtimes are easy targets.