Blog / Practical controls
Practical controls
Patch Management for a Small Business: Why 43 Days Is Too Slow for the Firewall and Fine for the Printer
Patch management for a small business: which devices need updates within days, which can wait, and why the firewall nobody reboots is the one that gets you.
The firewall nobody wanted to reboot
The office manager at a 30-person medical billing company keeps a list on her whiteboard of things IT has promised to do. Item four has been there since last spring: "firewall firmware update, needs after-hours window".
There is always a reason. The billing team works claims until seven. The Saturday crew posts payments. The IT contractor charges extra after six, and the last time the firewall rebooted it took 14 minutes to come back and a physician's office called to complain the portal was down. So the firewall runs firmware from two years ago, and everyone agrees it will be handled in the next quiet week.
The quiet week never comes, but a scanner does. On a Tuesday night an automated tool, run by someone who has never heard of the company, finds the firewall's VPN page and checks its version against a public list of flaws with working exploits. The version matches. By Thursday a person is logged in with the firewall's own admin rights, reading claims files full of patient names, dates of birth and insurance IDs, through the one device whose job was to keep him out.
The update that would have closed the hole was published 22 months earlier. It was free. It needed 14 minutes.
What the heck does this mean
Patching means installing the fixes a vendor publishes for flaws in its software. Vulnerability management is the grown-up version: knowing every device and program you run, knowing which ones have a flaw, and fixing the dangerous ones fast and the rest on a schedule.
What the heck is an edge device? Anything that sits on the border between your network and the internet: the firewall, the VPN appliance, the remote-access gateway, the email filter. Those are the devices attackers scan for, because a flaw there needs no phishing email and no insider. It is a door with a broken lock on a public street.
Not every patch is equally urgent. A flaw with a published exploit on an internet-facing device is a days problem. The same severity rating on a printer only the office can reach is a next-maintenance-window problem. The skill is sorting them, and the free tool for sorting is CISA's Known Exploited Vulnerabilities catalog, the KEV list, a running record of the flaws criminals are using right now.
The numbers that matter
Vulnerability exploitation became the top way attackers get in, at 31% of breaches, in the Verizon 2026 Data Breach Investigations Report. Not phishing. Not stolen passwords. A flaw somebody had already published a fix for.
The median time to fully patch a vulnerability reached 43 days in the same Verizon 2026 report. The scanner that found the billing company's firewall did not need 43 days. It needed one night.
29% of opportunistic breaches at small and medium businesses involved an unpatched edge device, according to the Verizon 2026 DBIR's small-business findings. Opportunistic is the operative word. Nobody chose that billing company. Its firewall answered the scan.
For readers in the Emirates, a 2026 review of the UAE threat landscape by Rescana listed exploited Ivanti, Microsoft and Cisco edge flaws among the year's leading intrusion routes. Same brands, same doors, different time zone.
What to do this week
- List everything that touches the internet directly: firewall, VPN, remote-access gateway, web server, email filter, the camera system somebody installed. Write down the firmware version of each and the date it was released. If nobody can find the release date, that is a finding too. (CIS 2 Inventory and Control of Software Assets)
- Check each version against the CISA KEV catalog. Anything on that list gets patched this week, business hours or not, with the 14-minute outage announced by email the day before. Nobody has ever lost a customer to a scheduled reboot. (CIS 7 Continuous Vulnerability Management)
- Write a patching schedule with two lanes: internet-facing devices and anything on the KEV list within seven days; workstations and internal servers monthly, with automatic updates on. The printer, the door controller and the conference-room screen get a quarterly pass. (CIS 7 Continuous Vulnerability Management)
- Turn off remote administration on the firewall's public side so the admin page is reachable only from inside, and put MFA on the VPN. Even an unpatched firewall is harder to abuse when its management page is not on the street. (CIS 4 Secure Configuration of Enterprise Assets and Software)
- Scan your public addresses from outside once a month and keep the report. The attacker's scanner is already running. Yours should see what his sees, first. (CIS 7 Continuous Vulnerability Management)
- Retire what the vendor no longer patches. An end-of-life firewall cannot be brought up to date, and the flaw found next month will never be fixed. (CIS 2 Inventory and Control of Software Assets)
Where AccuSights fits
Our assessment starts with the outside view: what your public addresses show a scanner, which firmware versions they admit to, and which of those sit on the KEV list. Then it works inward to the patch schedule, the automatic-update settings and the devices nobody listed. The Cyber Hygiene Test takes three minutes and asks when the firewall was last updated. A 15-minute call with an engineer follows, exploited flaws ranked first.
Our assessment is mapped to your regulators, and the read-only compliance agent shows which devices are behind on patches, which are past end of life, and which flaws are on the exploited list, refreshed as that list changes. We have no access and do not remediate; you or your IT partner apply the update, we show you where.
Questions people ask
What is the CISA KEV list? The Known Exploited Vulnerabilities catalog is a public list kept by the US Cybersecurity and Infrastructure Security Agency of software flaws that attackers are actively using. It is free, it is updated as new exploits appear, and it is the fastest way to decide which patch cannot wait. If a device on your network runs a version on that list, treat it as an open door, not a maintenance item.
Should I turn on automatic updates for business computers? Yes, for workstations, laptops and phones, with a short deferral so a bad update does not hit everyone at once. The rare update that breaks something costs an afternoon. The missing update that lets an attacker in costs a great deal more. Servers and the firewall still need a person and a scheduled window, but the window has to actually happen.
How do I patch devices I did not know I had? Find them first. A network scan from inside shows every address that answers, including the camera recorder, the smart thermostat and the print server from 2019. Compare that against your inventory, name an owner for each device, and put it in one of two lanes: patch it on a schedule, or unplug it. A device nobody owns is a device nobody patches.
Item four came off the whiteboard the week of the breach. It turns out there was an after-hours window all along.
Questions people ask
What is the CISA KEV list?
The Known Exploited Vulnerabilities catalog is a public list kept by the US Cybersecurity and Infrastructure Security Agency of software flaws that attackers are actively using. It is free, it is updated as new exploits appear, and it is the fastest way to decide which patch cannot wait. If a device on your network runs a version on that list, treat it as an open door, not a maintenance item.
Should I turn on automatic updates for business computers?
Yes, for workstations, laptops and phones, with a short deferral so a bad update does not hit everyone at once. The rare update that breaks something costs an afternoon. The missing update that lets an attacker in costs a great deal more. Servers and the firewall still need a person and a scheduled window, but the window has to actually happen.
How do I patch devices I did not know I had?
Find them first. A network scan from inside shows every address that answers, including the camera recorder, the smart thermostat and the print server from 2019. Compare that against your inventory, name an owner for each device, and put it in one of two lanes: patch it on a schedule, or unplug it. A device nobody owns is a device nobody patches.
Controls this post maps to
CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.
Sources
Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →
Keep reading
Three more from the same shelf.
How to Read Your Cyber Hygiene Score: What 77 Percent Coverage Means and the Three Fixes That Move It
Your cyber hygiene score is coverage, not a grade. What 77 percent coverage means, why the number moves, and the three fixes that raise it fastest.
Practical controlsMulti-Factor Authentication for a Small Business: Where It Belongs, Which Kind Works, and Why Outlook Alone Is Not Enough
Multi-factor authentication for a small business: the five doors it must be on, which kind survives a fake login page, and why Outlook alone is not enough.
Practical controlsA Backup Strategy for a Small Business That Survives Ransomware: 3-2-1-1-0 and the Restore Test Nobody Runs
A backup strategy for a small business that survives ransomware: why sync is not backup, what 3-2-1-1-0 means, and the monthly restore test nobody runs.
