
Patch management without an IT team: survival for 20-PC offices
Windows Update alone is not enough with QuickBooks, Adobe, and custom VPN clients. Realistic patch cadence for SMBs in PR.
CISA KEV catalog lists actively exploited vulnerabilities — late patching is not "technical debt", it is gambling. SMBs in Puerto Rico with external MSPs sometimes assume "they patch"; without documented SLA, nobody patches legacy Java on the accounting machine.
Practical model: endpoint and critical software inventory, c
Practical model: endpoint and critical software inventory, communicated monthly maintenance window, automatic OS patches + monthly manual review of line-of-business apps, documented exceptions with expiry. Critical KEV CVE = out-of-band within 72 hours.
Use WSUS, Intune, or MSP RMM with reporting visible to owner
Use WSUS, Intune, or MSP RMM with reporting visible to owner — not just closed ticket. Test patches on pilot machines before fleet-wide if legacy apps require; do not use pilot as permanent three-year excuse.
Servers: snapshot before patch, order database → app → web, post-reboot verification. Cloud VMs follow rules — outdated AMIs in AWS are forgotten endpoints.
Patching is hygiene, not a sexy project. But Krebs documents enough incidents from CVEs patched months ago to stop postponing "until after Three Kings."

Operations and execution — connecting strategy with what the team ships every week.


