Skip to content

Patch operating systems

Patching operating systems means keeping Windows, macOS, and the firmware on servers, firewalls and routers up to date with security fixes — and replacing systems so old they no longer receive updates. Internet-facing devices matter most, because attackers can probe them directly.

It is control 6 of the eight in the Australian Signals Directorate's Essential 8 (Essential Eight) baseline, assessed at maturity Levels 0–3.

Why this Essential 8 control comes up with insurers

Unsupported or unpatched operating systems are a frequent factor in claims, so insurers commonly ask about OS patch timeframes and end-of-life systems like Windows 7.

Maturity Level 1 — the baseline

Questions worth asking yourself, with the underlying ACSC requirement (November 2023 model) each one reflects:

  • If a critical security fix is released for your internet-facing servers, firewalls or routers, is it applied within 48 hours?

    ACSC requirement: “Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

  • Are operating system updates (Windows, macOS) installed on staff computers and internal servers within one month of release?

    ACSC requirement: “Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release.

  • Have you replaced devices running operating systems that no longer get security updates (for example Windows 7 or 8)?

    ACSC requirement: “Operating systems that are no longer supported by vendors are replaced.

  • Do you use a tool that automatically checks, at least fortnightly, for missing operating system updates on staff computers and internal servers?

    ACSC requirement: “A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices.

Maturity Level 3 — advanced

Questions worth asking yourself, with the underlying ACSC requirement (November 2023 model) each one reflects:

  • If a critical operating system fix comes out, is it installed on staff computers and internal servers within 48 hours?

    ACSC requirement: “Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

  • Are your devices running the latest (or previous) release of their operating system?

    ACSC requirement: “The latest release, or the previous release, of operating systems are used.

These are the criteria assessed by our free self-assessment — a representative subset of the full ACSC model, which contains further requirements at each level. The full model is published at cyber.gov.au.

This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).