We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

Blog / Practical controls

Practical controls

Patch Management for a Small Business: Why 43 Days Is Too Slow for the Firewall and Fine for the Printer

Patch management for a small business: which devices need updates within days, which can wait, and why the firewall nobody reboots is the one that gets you.

Sam KhanSam Khan The Cyber MonkFounder and CEO2 September 2026 · 6 min read

The firewall nobody wanted to reboot

The office manager at a 30-person medical billing company keeps a list on her whiteboard of things IT has promised to do. Item four has been there since last spring: "firewall firmware update, needs after-hours window".

There is always a reason. The billing team works claims until seven. The Saturday crew posts payments. The IT contractor charges extra after six, and the last time the firewall rebooted it took 14 minutes to come back and a physician's office called to complain the portal was down. So the firewall runs firmware from two years ago, and everyone agrees it will be handled in the next quiet week.

The quiet week never comes, but a scanner does. On a Tuesday night an automated tool, run by someone who has never heard of the company, finds the firewall's VPN page and checks its version against a public list of flaws with working exploits. The version matches. By Thursday a person is logged in with the firewall's own admin rights, reading claims files full of patient names, dates of birth and insurance IDs, through the one device whose job was to keep him out.

The update that would have closed the hole was published 22 months earlier. It was free. It needed 14 minutes.

What the heck does this mean

Patching means installing the fixes a vendor publishes for flaws in its software. Vulnerability management is the grown-up version: knowing every device and program you run, knowing which ones have a flaw, and fixing the dangerous ones fast and the rest on a schedule.

What the heck is an edge device? Anything that sits on the border between your network and the internet: the firewall, the VPN appliance, the remote-access gateway, the email filter. Those are the devices attackers scan for, because a flaw there needs no phishing email and no insider. It is a door with a broken lock on a public street.

Not every patch is equally urgent. A flaw with a published exploit on an internet-facing device is a days problem. The same severity rating on a printer only the office can reach is a next-maintenance-window problem. The skill is sorting them, and the free tool for sorting is CISA's Known Exploited Vulnerabilities catalog, the KEV list, a running record of the flaws criminals are using right now.

The numbers that matter

Vulnerability exploitation became the top way attackers get in, at 31% of breaches, in the Verizon 2026 Data Breach Investigations Report. Not phishing. Not stolen passwords. A flaw somebody had already published a fix for.

The median time to fully patch a vulnerability reached 43 days in the same Verizon 2026 report. The scanner that found the billing company's firewall did not need 43 days. It needed one night.

29% of opportunistic breaches at small and medium businesses involved an unpatched edge device, according to the Verizon 2026 DBIR's small-business findings. Opportunistic is the operative word. Nobody chose that billing company. Its firewall answered the scan.

For readers in the Emirates, a 2026 review of the UAE threat landscape by Rescana listed exploited Ivanti, Microsoft and Cisco edge flaws among the year's leading intrusion routes. Same brands, same doors, different time zone.

What to do this week

  1. List everything that touches the internet directly: firewall, VPN, remote-access gateway, web server, email filter, the camera system somebody installed. Write down the firmware version of each and the date it was released. If nobody can find the release date, that is a finding too. (CIS 2 Inventory and Control of Software Assets)
  2. Check each version against the CISA KEV catalog. Anything on that list gets patched this week, business hours or not, with the 14-minute outage announced by email the day before. Nobody has ever lost a customer to a scheduled reboot. (CIS 7 Continuous Vulnerability Management)
  3. Write a patching schedule with two lanes: internet-facing devices and anything on the KEV list within seven days; workstations and internal servers monthly, with automatic updates on. The printer, the door controller and the conference-room screen get a quarterly pass. (CIS 7 Continuous Vulnerability Management)
  4. Turn off remote administration on the firewall's public side so the admin page is reachable only from inside, and put MFA on the VPN. Even an unpatched firewall is harder to abuse when its management page is not on the street. (CIS 4 Secure Configuration of Enterprise Assets and Software)
  5. Scan your public addresses from outside once a month and keep the report. The attacker's scanner is already running. Yours should see what his sees, first. (CIS 7 Continuous Vulnerability Management)
  6. Retire what the vendor no longer patches. An end-of-life firewall cannot be brought up to date, and the flaw found next month will never be fixed. (CIS 2 Inventory and Control of Software Assets)

Where AccuSights fits

Our assessment starts with the outside view: what your public addresses show a scanner, which firmware versions they admit to, and which of those sit on the KEV list. Then it works inward to the patch schedule, the automatic-update settings and the devices nobody listed. The Cyber Hygiene Test takes three minutes and asks when the firewall was last updated. A 15-minute call with an engineer follows, exploited flaws ranked first.

Our assessment is mapped to your regulators, and the read-only compliance agent shows which devices are behind on patches, which are past end of life, and which flaws are on the exploited list, refreshed as that list changes. We have no access and do not remediate; you or your IT partner apply the update, we show you where.

Questions people ask

What is the CISA KEV list? The Known Exploited Vulnerabilities catalog is a public list kept by the US Cybersecurity and Infrastructure Security Agency of software flaws that attackers are actively using. It is free, it is updated as new exploits appear, and it is the fastest way to decide which patch cannot wait. If a device on your network runs a version on that list, treat it as an open door, not a maintenance item.

Should I turn on automatic updates for business computers? Yes, for workstations, laptops and phones, with a short deferral so a bad update does not hit everyone at once. The rare update that breaks something costs an afternoon. The missing update that lets an attacker in costs a great deal more. Servers and the firewall still need a person and a scheduled window, but the window has to actually happen.

How do I patch devices I did not know I had? Find them first. A network scan from inside shows every address that answers, including the camera recorder, the smart thermostat and the print server from 2019. Compare that against your inventory, name an owner for each device, and put it in one of two lanes: patch it on a schedule, or unplug it. A device nobody owns is a device nobody patches.

Item four came off the whiteboard the week of the breach. It turns out there was an after-hours window all along.

Questions people ask

What is the CISA KEV list?

The Known Exploited Vulnerabilities catalog is a public list kept by the US Cybersecurity and Infrastructure Security Agency of software flaws that attackers are actively using. It is free, it is updated as new exploits appear, and it is the fastest way to decide which patch cannot wait. If a device on your network runs a version on that list, treat it as an open door, not a maintenance item.

Should I turn on automatic updates for business computers?

Yes, for workstations, laptops and phones, with a short deferral so a bad update does not hit everyone at once. The rare update that breaks something costs an afternoon. The missing update that lets an attacker in costs a great deal more. Servers and the firewall still need a person and a scheduled window, but the window has to actually happen.

How do I patch devices I did not know I had?

Find them first. A network scan from inside shows every address that answers, including the camera recorder, the smart thermostat and the print server from 2019. Compare that against your inventory, name an owner for each device, and put it in one of two lanes: patch it on a schedule, or unplug it. A device nobody owns is a device nobody patches.

Controls this post maps to

CIS 7 Continuous Vulnerability ManagementCIS 4 Secure Configuration of Enterprise Assets and SoftwareCIS 2 Inventory and Control of Software Assets

CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Check, then repeat. We provide read-only insight so you prioritize the right things and keep an eye on them.

We have no access and do not remediate. You or your IT partner fix; we show you where, mapped to your regulators. Thirty minutes with an engineer draws the map for your organization.

Compliance is not security. The audit is not the exam; the attacker is.