The process
It starts with an up to date inventory of devices and software, since what is not inventoried is not patched. New updates are then identified, prioritised, tested where needed, deployed and verified. Exceptions, such as a legacy system that cannot be updated, are documented with compensating measures like isolating it from the network.
Prioritising by real risk
Not every patch is equally urgent. A practical rule combines the CVSS severity, whether the flaw is being exploited (the CISA KEV catalogue is a good signal) and whether the affected system is exposed to the internet. A critical vulnerability on a VPN gateway should be fixed in days, not at the next monthly cycle.
Common gaps
Laptops are usually well covered by automatic updates. The gaps tend to be servers, firewalls, VPN appliances, third party applications, browser extensions and devices nobody owns. Our article on what your company exposes online shows why internet facing systems come first.
Where it shows up in compliance
ISO 27001 requires the management of technical vulnerabilities (Annex A 8.8). The ENS, NIS2 and SOC 2 all expect vulnerabilities to be fixed within defined timeframes, and auditors ask for evidence of patching levels and exceptions.




