Guide · Patching

How a small business keeps software and devices patched, and why default passwords must go

Published 2026-09-29 · 6 min read

The fix for the flaw that let WannaCry ransomware tear through Britain's National Health Service in May 2017 had been available, free, for almost 2 months.[1][10] This guide explains how a small office keeps its computers, software and internet-facing devices patched without an IT department, which updates cannot wait, and why the password a device shipped with needs to be changed on day one.

What patching means, and why it matters

A patch is a software update that fixes a flaw. Some updates add features, but the ones that matter here close security holes that criminals already know about. Once a fix is published, attackers can study it to find the weakness and then look for everyone who has not installed it yet. The gap between "fix available" and "fix installed" is where many break-ins happen.

The Federal Trade Commission's basic advice for small businesses is to update apps, web browsers and operating systems, and to set updates to happen automatically.[2] Its guide drawn from enforcement cases adds that companies need a reasonable process for updating and patching the third-party software they rely on.[3]

Two cases where the fix already existed

WannaCry, 2017. On March 14, 2017, Microsoft released a critical update for a flaw in Windows file sharing.[10] On May 12, WannaCry began spreading on its own from computer to computer through that flaw. In England, at least 81 NHS trusts and hundreds of GP practices and other organizations were disrupted, and more than 19,000 appointments were cancelled. The National Audit Office found that every infected NHS organization was running Windows systems that were unpatched or too old to be supported.[1] Read the WannaCry case file.

Equifax, 2017. A serious flaw in a widely used web software component was disclosed with a fix on March 7, 2017. Equifax's consumer dispute website was never updated, and attackers got in on May 13 and stayed for about 76 days, reaching data on about 147 million people.[4] Equifax later agreed to a settlement with the FTC, the Consumer Financial Protection Bureau and the states worth at least $575 million.[5] See how the Equifax breach happened.

Neither needed a brilliant attacker. Both needed an update that was not installed.

What to patch first, and what cannot be patched

Not every update is equally urgent. Put these at the top of the list:

Old equipment is a special case. Some software and devices reach "end of life," meaning the maker no longer sends security fixes. Windows 7, for example, stopped receiving regular updates in January 2020, yet an independent review of Ireland's health service found more than 30,000 of its computers still running it when ransomware hit in 2021.[7] See the Irish health service attack.

An unsupported device is a permanent open flaw. Make a list of anything that is out of support or will be within a year, and budget to replace it. If a piece of equipment truly cannot be replaced yet, such as a medical or imaging device tied to old software, ask your IT provider to keep it off the internet and on its own separate network.

Default passwords: the flaw that needs no patch

Many routers, cameras, printers and other devices come from the factory with a built-in administrator login, often the same on every unit and easy to look up. In 2016, the Mirai botnet took over hundreds of thousands of cameras, video recorders and routers largely by trying a short list of those factory logins, then used them to knock major websites offline.[8] Read how default passwords built the Mirai botnet.

CISA has urged manufacturers to stop shipping products with default passwords at all.[9] Until they all do, the job falls to you:

A simple monthly routine

Patching works best as a habit, not a project. For a small office, a routine like this is enough:

Who owns patching in a small office

The most common reason patches are missed is not laziness. It is that nobody is sure whose job it is. The office manager assumes the IT provider handles it, the IT provider covers the computers but not the cameras, and the phone vendor thinks the router belongs to the internet company. Everyone is responsible, so nobody is.

Fix this with one line per item on your inventory: the name of the person or company that keeps it updated. If a line is blank, that device is almost certainly behind. Review the list whenever you add equipment or change providers, and ask each owner for a quick confirmation each month. This one small habit turns patching from a vague hope into something you can check.

Your patching checklist

Common questions

Can an update break something?

Occasionally. That is why larger organizations test updates first. A small office can get most of the benefit with a simple approach: let one computer update first, wait a day or two, then roll the update to the rest. For critical flaws in internet-facing equipment, the risk of waiting usually outweighs the risk of a bad update.

Does my IT provider handle this?

Possibly, but do not assume. Ask them in writing which devices they patch, how quickly for critical flaws, whether that includes your router, firewall, printers and cameras, and how they confirm it happened. Ask for a short monthly report. Our vendor access guide has more questions to ask.

Is antivirus enough if I am behind on updates?

No. Antivirus helps catch known malicious files, but it does not close the flaw a criminal uses to get in. WannaCry spread through a Windows flaw on its own, without anyone opening a file.[1] Patching and antivirus do different jobs, and you need both.

Close the same gap

Put it in writing

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More guides

General guidance, not legal advice. Check requirements specific to your industry with a qualified adviser.

Sources
  1. National Audit Office: Investigation: WannaCry cyber attack and the NHS (press release)
  2. FTC: Cybersecurity Basics
  3. FTC: Start with Security: A Guide for Business
  4. House Committee on Oversight and Government Reform: The Equifax Data Breach (Majority Staff Report, December 2018)
  5. Federal Trade Commission: Equifax to Pay $575 Million as Part of Settlement with FTC, CFPB, and States Related to 2017 Data Breach
  6. CISA: BOD 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities
  7. The Stack: PwC's HSE hack post-incident report
  8. Forbes: Hacked cameras behind the Dyn attack that hit Twitter and Netflix
  9. CISA: Secure by Design Alert: How Manufacturers Can Protect Customers by Eliminating Default Passwords
  10. Canadian Centre for Cyber Security: Microsoft critical security bulletins summary, March 2017