Managed patching and vulnerability management

Patched safely, and every known flaw tracked until it is closed.

Updates are read, tried in a lab and rolled out in waves, so a bad one is caught by a handful of computers, not your whole office. When a serious flaw is announced, we work out which of your machines it touches and fix them.

Read, lab, pilot, wavesServers in a windowFlaws tracked to closed
Patching · fleet watchtypical activity
$ patch watch --fleet

Illustrative. These are the kinds of steps taken; names and times are made up.

What is covered

Patching and vulnerabilities are one job, not two.

Patching is the routine. Vulnerability management is knowing which flaws matter, and proving they are gone. We do both from the same list.

Windows and Microsoft updates

Security updates for every computer and server, read for the problems they may cause before they go anywhere near your office.

Browsers and Java

The third-party software attackers go after most is kept current too, along with anything else that poses a security threat.

Servers, in a window

Patched at night or on a weekend, in a window agreed with you, and checked afterwards.

Vulnerability tracking

Known flaws that affect your machines are gathered, ranked by risk and tracked until they are gone.

A restart people can live with

A prompt with reminders and a choice of time, then a countdown, never a surprise reboot in the middle of a call.

Unsupported systems

Old machines that no longer get updates are flagged, with a plan, instead of quietly becoming the weak point.

A patch cycle

From release to report, in seven stages.

Step through it. Each stage says who does the work, and where a person decides.

Stage 1 of 7

Updates are released

Microsoft publishes its monthly security updates, and software makers publish theirs through the month.

Updates are releasedWho: automatic
We read what is in them
Tried in a lab first
A small pilot group
Everyone else
Servers, in their window
Proof and a report
The shape of a cycle. Exact timing is agreed with each customer.

Watch it work

Four patching days, step by step.

The agents read, test and track. Where a step changes a server or removes a machine from service, it stops for a person.

Monthly · security updates

Microsoft releases this month's security updates.

Read first, tried second, rolled out in waves. A bad update is caught at the pilot, not by your whole office.

Press “Watch it work” to see each step, in order.

Illustrative walk-through. Names, times and machines are made up; the order of steps and the approval gate are how it really works.

The restart

The part people notice, done kindly.

Updates only protect a computer after it restarts. Here is what your people see, and why we do not simply force it.

What your people see

A polite nudge, and a choice.

After patching, a computer that needs a restart shows this in the corner of the screen. People can restart now, or pick a time that suits them.

Customers can choose reminders only, for a computer, a person or the whole company. Those machines are reminded and never restarted by us.

A preview. It restarts nothing, and the times shown are examples.

Why it works

Fix the old flaws first, and fix them safely.

Most breaches use old flaws

Attackers favour known problems that have had a fix available for months. Closing them quickly is among the most effective things a small business can do.

Read first, then deploy

An update that breaks your accounting software is its own outage. We read what is in each release and try it before it reaches you.

Waves, not a big bang

A small pilot group goes first. If something is wrong, it stops there, with a handful of computers affected, not all of them.

Faster when it matters

A flaw that attackers are already using does not wait for the monthly cycle. It goes through the same process, sooner.

The policy we build to

Written down, agreed with you.

Every customer is different, so the policy is too. Windows, restart rules and which machines are reminded rather than restarted are set with you, and then followed the same way every month.

PATCH POLICYexample · set per customer
Workstations
pilot group first, then everyone in waves
Servers
maintenance window agreed with you, checked after
Third-party software
browsers, Java and anything that poses a threat
Serious vulnerability
fixed as soon as a patch exists, same process
Restart
reminders first, no delay after 24 hours
Reminders only
available per computer, person or company
Unsupported
flagged as a risk with a plan to replace
Timing is agreed with each customer. We do not promise a number of days.

See what is unpatched right now.

Book a patching review. We will list what is behind, what is exposed and what a safe plan looks like.

(888) 851-0237