CertIQ
All guides
Essential Eight guide G3 · 8 points toward CertIQ Ready

Patching: why 48 hours matters and how to make it achievable

7 min read +8 pts toward CertIQ Ready ASD Essential Eight aligned Reviewed by Ben Webster

Published by CertIQ · Essential Eight guide G3 · 8 points toward CertIQ Ready


Many cyber attacks on Australian SMEs do not need a sophisticated zero-day exploit or a state-sponsored intrusion. One of the most common entry points is a known vulnerability in software that has been public for weeks — sometimes months — that the business simply has not patched.

The Australian Signals Directorate is consistent on this point: its Annual Cyber Threat Report 2024–25 notes that malicious cyber actors commonly exploit vulnerable devices and software, and that patching internet-facing systems quickly when critical vulnerabilities emerge remains a key strategy for preventing intrusions. Patching is not glamorous. It is also one of the most reliably effective cyber controls available to any business.

This guide explains what the ASD expects from patching, what "48 hours" actually means in practice, and how to build a patching process that is achievable without a dedicated IT team.


7 more sections

Read the rest of this guide

The rest of Patching: why 48 hours matters and how to make it achievable covers exactly what to do, step by step. Sign in with your email to read it — and to keep every other guide, your scan results and your report in one place.

No password. We email you a link — free, and no sales call.

See how this applies to your business
Scan your domain to see your CertIQ score and the specific findings this guide speaks to.
Run a scan