Support desk — Monday to Friday, 08:30 to 17:30Client AreaGet help now →

Introducing Patch Sundays: EasyLifeIT’s Proactive Approach to System Security

Patching is the least interesting thing we do and one of the most consequential. The overwhelming majority of successful attacks on businesses of this size exploit something that had a fix available — often for months.

So the question is not whether to patch. It is how to patch reliably, across everything, without stopping people from working. Our answer to that is Patch Sundays.

What Patch Sundays is

On the third Sunday of every month, we apply the month’s updates across managed systems — operating systems, applications, and the infrastructure underneath them. It runs to a fixed schedule so that clients can plan around it, and it runs at a weekend so that nobody loses a working morning to a restart.

Why the third Sunday

Microsoft releases its monthly security updates on the second Tuesday of each month, the long-standing Patch Tuesday. The third Sunday falls a few days later.

That gap is deliberate and does two things. It leaves enough time for any serious problem with a release to surface publicly — patches occasionally break things, and finding that out from someone else’s estate is preferable. And it still lands comfortably inside the fourteen-day window that current Cyber Essentials requirements set for high-risk updates.

It also means the answer to “when will this be patched?” is a date rather than a shrug.

What it covers

The part that matters is the breadth. Turning on automatic Windows updates covers Microsoft’s products and nothing else, while a great deal of real-world risk sits in browsers, PDF readers, remote access tools, line-of-business applications and network hardware firmware.

Patch Sundays covers third-party applications alongside the operating system, with firmware handled on its own schedule where a reboot would take a service offline.

Quick check

Three things people get wrong about patching

Short, and the explanations are the point.

1. Windows Update is switched on. Is that patch management?
Windows Update handles Microsoft’s own products. It does nothing for browsers, PDF readers, Java, line-of-business applications, or firewall and router firmware — and those are where a large share of exploited vulnerabilities actually live.
2. How long do you have to apply a high-risk patch under current Cyber Essentials rules?
Fourteen days, measured from when the vendor released it rather than from when you noticed. A single missed high-risk patch outside that window, on any in-scope device, is an automatic failure.
3. A laptop has been off for three weeks while someone was on leave. What happens?
It will catch up eventually, but in the meantime it is an unpatched device that is about to be plugged back into your network. The important part is that somebody is monitoring compliance and can see it, rather than assuming.
Score: 0 of 3

What happens when something does not patch

This is the part that distinguishes a patching process from a patching intention.

Machines miss updates for ordinary reasons: the laptop was off, someone was on leave, a device dropped off the network. Without monitoring, those machines quietly stay unpatched and nobody finds out until an assessment or an incident.

Compliance is monitored after each cycle, exceptions are chased, and anything that cannot be patched — usually because a supplier has not released a fix, or an application will break — gets recorded with a reason rather than forgotten.

Where emergencies fit

A monthly cadence is right for the routine and wrong for the exceptional. When a vulnerability is being actively exploited in the wild, it does not wait for the third Sunday. Those are handled as they arise, out of cycle, with affected clients told what is happening and why.

The point of all this

A predictable schedule turns patching from something that happens when someone remembers into something with a date, a scope and a record. That record is what turns a Cyber Essentials assessment from an anxious exercise into a paperwork one — and, rather more importantly, it is what closes the gap that most attacks actually walk through.

If you are not certain when your systems were last fully patched, or whether anyone would notice a machine that stopped receiving updates, that is worth a conversation.

Found this useful?

We write these because the same questions keep coming up. If one of them is yours, the answer is usually a short conversation away.

Keep reading