Patch applications
Patching applications means installing security fixes for your everyday software (browsers, office suites, email clients, PDF readers, antivirus) soon after vendors release them. Attackers go after known flaws in out-of-date software, often within days of a fix coming out. Under the Essential 8 (Essential Eight), the bar rises with each maturity level. A set patch timeframe, sometimes called application patch management, replaces the "patch it when we remember" habit.
It is control 2 of the eight in the Australian Signals Directorate's Essential 8 (Essential Eight) baseline, assessed at maturity Levels 0–3.
Why this Essential 8 control comes up with insurers
Patch timeliness is one of the most common questions on cyber-insurance applications, because unpatched software is one of the most common ways small businesses get breached. Essential 8 patch management is assessed separately for applications and operating systems. Good patching on one does not cover a gap on the other.
Maturity Level 1: the baseline
Ask yourself these. Under each is the ACSC requirement (November 2023 model) it comes from:
If a critical security fix comes out for an online service you run (website, customer portal, webmail), is it applied within 48 hours?
ACSC requirement: “Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.”
Are updates for everyday apps (web browsers, office suites, email, PDF readers, antivirus) installed within two weeks of release?
ACSC requirement: “Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within two weeks of release.”
Have you removed software that no longer receives updates from its maker (for example old Office versions or Adobe Flash)?
ACSC requirement: “Office productivity suites, web browsers and their extensions, email clients, PDF software, Adobe Flash Player, and security products that are no longer supported by vendors are removed.”
Do you use a tool that automatically checks, at least weekly, for missing updates in browsers, office suites, email, PDF and antivirus software?
ACSC requirement: “A vulnerability scanner is used at least weekly to identify missing patches or updates for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products.”
Maturity Level 2: the common target
Ask yourself these. Under each is the ACSC requirement (November 2023 model) it comes from:
Are all your other business applications updated within one month of a new release?
ACSC requirement: “Patches, updates or other vendor mitigations for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within one month of release.”
Maturity Level 3: advanced
Ask yourself these. Under each is the ACSC requirement (November 2023 model) it comes from:
If a critical security fix comes out for browsers, office suites, email, PDF or antivirus software, is it installed within 48 hours?
ACSC requirement: “Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.”
These are the criteria our free self-assessment checks. They are a representative subset of the full ACSC model, which has more requirements at each level. You can read the full model at cyber.gov.au.
This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).