How a small business keeps software and devices patched, and why default passwords must go
The fix for the flaw that let WannaCry ransomware tear through Britain's National Health Service in May 2017 had been available, free, for almost 2 months.[1][10] This guide explains how a small office keeps its computers, software and internet-facing devices patched without an IT department, which updates cannot wait, and why the password a device shipped with needs to be changed on day one.
What patching means, and why it matters
A patch is a software update that fixes a flaw. Some updates add features, but the ones that matter here close security holes that criminals already know about. Once a fix is published, attackers can study it to find the weakness and then look for everyone who has not installed it yet. The gap between "fix available" and "fix installed" is where many break-ins happen.
The Federal Trade Commission's basic advice for small businesses is to update apps, web browsers and operating systems, and to set updates to happen automatically.[2] Its guide drawn from enforcement cases adds that companies need a reasonable process for updating and patching the third-party software they rely on.[3]
Two cases where the fix already existed
WannaCry, 2017. On March 14, 2017, Microsoft released a critical update for a flaw in Windows file sharing.[10] On May 12, WannaCry began spreading on its own from computer to computer through that flaw. In England, at least 81 NHS trusts and hundreds of GP practices and other organizations were disrupted, and more than 19,000 appointments were cancelled. The National Audit Office found that every infected NHS organization was running Windows systems that were unpatched or too old to be supported.[1] Read the WannaCry case file.
Equifax, 2017. A serious flaw in a widely used web software component was disclosed with a fix on March 7, 2017. Equifax's consumer dispute website was never updated, and attackers got in on May 13 and stayed for about 76 days, reaching data on about 147 million people.[4] Equifax later agreed to a settlement with the FTC, the Consumer Financial Protection Bureau and the states worth at least $575 million.[5] See how the Equifax breach happened.
Neither needed a brilliant attacker. Both needed an update that was not installed.
What to patch first, and what cannot be patched
Not every update is equally urgent. Put these at the top of the list:
- Anything facing the internet. Your firewall or router, VPN or remote access gateway, email server if you run one, website and any portal clients log in to. These can be reached by anyone, anywhere.
- Flaws that are already being used by criminals. CISA keeps a free public list called the Known Exploited Vulnerabilities catalog. Federal agencies must fix newer entries within 2 weeks, and CISA encourages every organization to use the list to decide what to fix first.[6] Ask your IT provider to check it against your equipment.
- Operating systems and browsers. Windows, macOS, phones, Chrome, Edge and Safari. Automatic updates handle most of this.
- Business software. Practice management, tax, accounting and records software, plus the PDF reader and office apps everyone uses.
- Devices people forget. Printers, security cameras, video recorders, smart TVs in the waiting room, door systems and Wi-Fi access points.
Old equipment is a special case. Some software and devices reach "end of life," meaning the maker no longer sends security fixes. Windows 7, for example, stopped receiving regular updates in January 2020, yet an independent review of Ireland's health service found more than 30,000 of its computers still running it when ransomware hit in 2021.[7] See the Irish health service attack.
An unsupported device is a permanent open flaw. Make a list of anything that is out of support or will be within a year, and budget to replace it. If a piece of equipment truly cannot be replaced yet, such as a medical or imaging device tied to old software, ask your IT provider to keep it off the internet and on its own separate network.
Default passwords: the flaw that needs no patch
Many routers, cameras, printers and other devices come from the factory with a built-in administrator login, often the same on every unit and easy to look up. In 2016, the Mirai botnet took over hundreds of thousands of cameras, video recorders and routers largely by trying a short list of those factory logins, then used them to knock major websites offline.[8] Read how default passwords built the Mirai botnet.
CISA has urged manufacturers to stop shipping products with default passwords at all.[9] Until they all do, the job falls to you:
- Change the admin password before a device goes online. Use a long, unique password stored in a password manager.
- Turn off remote management you do not use. Many routers and cameras can be managed from the internet; if nobody needs that, switch it off.
- Keep devices on their own network. Cameras, smart TVs and guest Wi-Fi should not share a network with computers that hold client records. The Target breach showed how far a loosely divided network lets an intruder travel; see the Target case.
A simple monthly routine
Patching works best as a habit, not a project. For a small office, a routine like this is enough:
- Keep an inventory. A simple list of every computer, phone, router, printer, camera and piece of business software, with who looks after it.
- Turn on automatic updates everywhere it is offered. Computers, phones, browsers and most apps.
- Set a monthly check. Microsoft releases its regular security updates on the second Tuesday of each month. Use the following week to confirm every computer actually installed them.
- Fix internet-facing and actively exploited flaws within days. Do not wait for the monthly cycle.
- Check that updates happened. An alert that was sent is not a patch that was installed. The NHS had been warned; what was missing was anyone confirming the work was done.[1]
- Restart. Many updates only take effect after a restart. A computer that has not been rebooted in months is often not as patched as it looks.
Who owns patching in a small office
The most common reason patches are missed is not laziness. It is that nobody is sure whose job it is. The office manager assumes the IT provider handles it, the IT provider covers the computers but not the cameras, and the phone vendor thinks the router belongs to the internet company. Everyone is responsible, so nobody is.
Fix this with one line per item on your inventory: the name of the person or company that keeps it updated. If a line is blank, that device is almost certainly behind. Review the list whenever you add equipment or change providers, and ask each owner for a quick confirmation each month. This one small habit turns patching from a vague hope into something you can check.
Your patching checklist
- Inventory of every device and program. Updated when you buy something new, with a named owner for each.
- Automatic updates on. Everywhere they are offered.
- Internet-facing gear patched within days. Routers, firewalls, VPNs and portals first.
- Known exploited flaws checked. Your IT provider compares your equipment with CISA's catalog.
- Monthly confirmation. Someone checks that updates installed and machines restarted.
- No default passwords. Every device's admin login changed before it goes online.
- End-of-life plan. Unsupported equipment replaced, or isolated until it can be.
Common questions
Can an update break something?
Occasionally. That is why larger organizations test updates first. A small office can get most of the benefit with a simple approach: let one computer update first, wait a day or two, then roll the update to the rest. For critical flaws in internet-facing equipment, the risk of waiting usually outweighs the risk of a bad update.
Does my IT provider handle this?
Possibly, but do not assume. Ask them in writing which devices they patch, how quickly for critical flaws, whether that includes your router, firewall, printers and cameras, and how they confirm it happened. Ask for a short monthly report. Our vendor access guide has more questions to ask.
Is antivirus enough if I am behind on updates?
No. Antivirus helps catch known malicious files, but it does not close the flaw a criminal uses to get in. WannaCry spread through a Windows flaw on its own, without anyone opening a file.[1] Patching and antivirus do different jobs, and you need both.
Put it in writing
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Employee offboarding checklist: how to cut off a former employee's access the same day
- How to stop fake invoices, changed bank details and fake-boss payment requests
- How to verify callers before password resets, and protect your phone number from SIM swaps
- Backups that survive ransomware: offline copies, tested restores and a one-page plan
- Which two-step login actually stops phishing, and how a small office rolls it out
- How to manage vendor, IT provider and contractor access to your systems
- Cases behind these controls
General guidance, not legal advice. Check requirements specific to your industry with a qualified adviser.
- National Audit Office: Investigation: WannaCry cyber attack and the NHS (press release)
- FTC: Cybersecurity Basics
- FTC: Start with Security: A Guide for Business
- House Committee on Oversight and Government Reform: The Equifax Data Breach (Majority Staff Report, December 2018)
- Federal Trade Commission: Equifax to Pay $575 Million as Part of Settlement with FTC, CFPB, and States Related to 2017 Data Breach
- CISA: BOD 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities
- The Stack: PwC's HSE hack post-incident report
- Forbes: Hacked cameras behind the Dyn attack that hit Twitter and Netflix
- CISA: Secure by Design Alert: How Manufacturers Can Protect Customers by Eliminating Default Passwords
- Canadian Centre for Cyber Security: Microsoft critical security bulletins summary, March 2017