Patch applications
Patching applications means updating everyday software — browsers, office suites, email clients, PDF readers, antivirus — promptly when vendors release security fixes. Attackers routinely exploit known flaws in out-of-date software, often within days of a fix being published.
It is control 2 of the eight in the Australian Signals Directorate's Essential 8 (Essential Eight) baseline, assessed at maturity Levels 0–3.
Why this Essential 8 control comes up with insurers
Patch timeliness is one of the most common questions on cyber-insurance applications, because unpatched software is one of the most common ways small businesses are breached.
Maturity Level 1 — the baseline
Questions worth asking yourself, with the underlying ACSC requirement (November 2023 model) each one reflects:
If a critical security fix comes out for an online service you run (website, customer portal, webmail), is it applied within 48 hours?
ACSC requirement: “Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.”
Are updates for everyday apps — web browsers, office suites, email, PDF readers, antivirus — installed within two weeks of release?
ACSC requirement: “Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within two weeks of release.”
Have you removed software that no longer receives updates from its maker (for example old Office versions or Adobe Flash)?
ACSC requirement: “Office productivity suites, web browsers and their extensions, email clients, PDF software, Adobe Flash Player, and security products that are no longer supported by vendors are removed.”
Do you use a tool that automatically checks, at least weekly, for missing updates in browsers, office suites, email, PDF and antivirus software?
ACSC requirement: “A vulnerability scanner is used at least weekly to identify missing patches or updates for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products.”
Maturity Level 2 — the common target
Questions worth asking yourself, with the underlying ACSC requirement (November 2023 model) each one reflects:
Are all your other business applications updated within one month of a new release?
ACSC requirement: “Patches, updates or other vendor mitigations for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within one month of release.”
Maturity Level 3 — advanced
Questions worth asking yourself, with the underlying ACSC requirement (November 2023 model) each one reflects:
If a critical security fix comes out for browsers, office suites, email, PDF or antivirus software, is it installed within 48 hours?
ACSC requirement: “Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.”
These are the criteria assessed by our free self-assessment — a representative subset of the full ACSC model, which contains further requirements at each level. The full model is published at cyber.gov.au.
This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).