Patch operating systems
Patching operating systems means keeping Windows, macOS, and the firmware on servers, firewalls and routers up to date with security fixes — and replacing systems so old they no longer receive updates. Internet-facing devices matter most, because attackers can probe them directly.
It is control 6 of the eight in the Australian Signals Directorate's Essential 8 (Essential Eight) baseline, assessed at maturity Levels 0–3.
Why this Essential 8 control comes up with insurers
Unsupported or unpatched operating systems are a frequent factor in claims, so insurers commonly ask about OS patch timeframes and end-of-life systems like Windows 7.
Maturity Level 1 — the baseline
Questions worth asking yourself, with the underlying ACSC requirement (November 2023 model) each one reflects:
If a critical security fix is released for your internet-facing servers, firewalls or routers, is it applied within 48 hours?
ACSC requirement: “Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.”
Are operating system updates (Windows, macOS) installed on staff computers and internal servers within one month of release?
ACSC requirement: “Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release.”
Have you replaced devices running operating systems that no longer get security updates (for example Windows 7 or 8)?
ACSC requirement: “Operating systems that are no longer supported by vendors are replaced.”
Do you use a tool that automatically checks, at least fortnightly, for missing operating system updates on staff computers and internal servers?
ACSC requirement: “A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices.”
Maturity Level 3 — advanced
Questions worth asking yourself, with the underlying ACSC requirement (November 2023 model) each one reflects:
If a critical operating system fix comes out, is it installed on staff computers and internal servers within 48 hours?
ACSC requirement: “Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.”
Are your devices running the latest (or previous) release of their operating system?
ACSC requirement: “The latest release, or the previous release, of operating systems are used.”
These are the criteria assessed by our free self-assessment — a representative subset of the full ACSC model, which contains further requirements at each level. The full model is published at cyber.gov.au.
This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).