Patch Management for Small Business | IT Checklist

Tom Reed
Read time: 7 minutes
Patch Management for Small Business | IT Checklist

Patch Management for Small Business: IT Checklist

Patch management is the repeatable process of finding, testing, approving, and installing software and OS updates across company devices and servers — so known vulnerabilities and bugs get fixed before they become outages or breaches. For roughly 20–100 person companies, good patch management is less about buying an “enterprise” console and more about knowing what you own, piloting risky updates (especially Windows and VPN/softphone apps), scheduling maintenance windows that do not kill calling, and having a rollback path when a patch breaks something. This playbook is a practical patch-management checklist for IT managers: inventory, rings, policy, and a 30-day cadence — without fake tool rankings or a hosted-PBX pitch.

What is patch management (and what is it not)?

Patch management is the cadence of discovering available updates, deciding which ones to take, testing them on a small group, rolling them out, and verifying devices came back healthy. It covers operating systems (Windows, macOS), browsers, office suites, VPN clients, softphone/SIP apps, endpoint agents, and any servers or appliances you still run.

It is not the same as:

Patch management is routine update cadence and rings. IR and BCP are what you use when a bad patch — or something else — becomes an outage.

Why does a small business need a patch cadence if “Windows Update just works”?

Consumer Windows Update is a start. It is not a company process.

At 20–100 people you usually have mixed hardware, deferred reboots, remote laptops that miss the office network, and third-party apps that never appear in Windows Update. Feature updates can break VPN or softphone audio. Someone always clicks “remind me tomorrow” for three weeks. Firewalls and VPN appliances sit on old firmware until someone remembers.

A light patch management process gives you:

  • A named owner per device class
  • Pilot rings before company-wide push
  • Maintenance windows staff can plan around
  • An emergency path for critical security fixes without waiting for habit alone
  • Metrics you can actually see (% current, open deferrals, failed installs) — not invented industry benchmarks

You do not need a “best patch management tool” winner. You need inventory, rings, and rollback.

How do you inventory what needs patching without a huge CMDB?

Skip the enterprise CMDB fantasy. Use a spreadsheet or your MDM/RMM export and list device classes, not every cable:

  1. Windows / Mac laptops (and desktops if any)
  2. Phones / tablets that get work apps
  3. Servers / VMs (if you still run them)
  4. Firewalls / VPN appliances
  5. Critical third-party apps: browsers, Office, VPN client, softphone/SIP apps, RMM agents

Name an owner for each class: who approves, who installs, who tests email/VPN/calling after. While you inventory, note unmanaged personal installs of work tools — that is shadow IT, and those copies skip your rings.

Joiners should leave day one on a managed, patchable image — fold patch expectations into your device onboarding and offboarding checklist. Softphone clients are optional inventory/retest hygiene after updates — not the hero of the programme; use the softphone setup checklist when you retest calling.

IT technician with laptop performing maintenance in a server room — testing updates before company-wide rollout

How do you run pilot rings and approve updates without freezing the company?

Define three rings:

  1. IT / pilot — 5–10 people who can tolerate a rough morning
  2. Early adopters — willing volunteers or one department
  3. Everyone else — only after the pilot survives a full workday of email, VPN, and softphone calls

Prefer built-in controls first (Intune / Jamf / MDM, Windows Update for Business, vendor auto-update where you trust it). Shortlist a paid patch/RMM tool only if inventory or remote install is broken — and shortlist with criteria, not blog awards. Use the same judgment as any other buy: SaaS vendor evaluation for small business.

Document maintenance windows (for example Tuesday/Thursday evenings) and how you warn staff. Add an emergency path: out-of-band critical CVE — who can force a same-day patch, and who communicates downtime.

If a patch breaks calling, treat widespread failure as an incident, roll back the ring, and widen the next pilot before the company push. If “the patch broke calls” is actually network or QoS drift, check VoIP network requirements.

What does a 30-day patch management checklist look like?

Week 1 — Inventory & policy

  1. List device classes: Windows/Mac laptops, phones/tablets, servers/VMs (if any), firewalls/VPN appliances, and critical third-party apps (browsers, Office, VPN client, softphone/SIP apps, RMM agents).
  2. Name owners for each class (who approves, who installs, who tests calling/email after).
  3. Write a one-page patch policy: critical security patches within X days; feature updates on a slower ring; no “forever defer” for internet-facing systems.
  4. Confirm backups/restore tests exist for anything you will reboot or upgrade — patch ≠ backup; see business continuity and incident response.

Week 2 — Rings & tooling

  1. Define rings: IT/pilot (5–10 people) → early adopters → everyone else. Hold the company ring until the pilot survives a workday of email, VPN, and softphone calls.
  2. Prefer built-in controls first (Intune/Jamf/MDM, Windows Update for Business, vendor auto-update where you trust it) — shortlist paid patch/RMM tools only if inventory or remote install is broken; do not invent “#1 patch tool” claims.
  3. Document maintenance windows (e.g. Tue/Thu evenings) and how staff are warned.
  4. Add emergency path: out-of-band critical CVE — who can force a same-day patch and who communicates downtime.

Week 3 — First full cycle

  1. Push a known-safe month’s cumulative updates through Pilot → Early → All; log failures (boot loops, VPN drops, softphone audio issues).
  2. Patch browsers and high-risk desktop apps the same week as OS updates when vendors ship.
  3. Confirm SaaS / IdP / email admin consoles are on vendor-managed updates (you still track *your* side: MFA, password vault, access reviews — link those posts above).
  4. Reboot policy: who can defer, how long, and how IT remotes stuck devices.

Week 4 — Harden & handoff

  1. Add patch steps to joiner device setup and leaver wipe (device onboarding/offboarding).
  2. Review shadow IT apps discovered while inventorying (shadow IT) — unpatched personal installs of work tools are a gap.
  3. Capture metrics you can actually see: % devices current within SLA, open deferrals, failed installs — no fake industry benchmarks.
  4. Schedule a quarterly tabletop: “patch broke VPN/softphone — rollback + IR handoff.”

Optional company softphone trials stay on sessiontalk.io — inventory/retest hygiene after client updates, not the reason you build a patch programme.

Office worker holding a tablet displaying a software update progress screen — endpoint patch cadence

How do patch management, backups, and incident response fit together?

  • Practice: Patch management — Job: Ship tested updates on a cadence — Not the same as: Incident response (contain/restore after something breaks)
  • Practice: Backups / BCP — Job: Recover data and keep operating — Not the same as: Patching (prevention + maintenance)
  • Practice: MFA / password vault — Job: Prove identity / store secrets — Not the same as: Closing OS/app CVEs
  • Practice: Device onboarding — Job: Joiners get a managed, updatable device — Not the same as: Ongoing monthly patch rings

Patching reduces how often you need IR. Backups and BCP decide how painful a bad reboot is. Identity tools stop stolen passwords — they do not replace monthly OS rings. Keep the runbooks linked, not merged into one vague “security” doc.

FAQ

What is patch management?

The process of finding, testing, approving, and installing OS and application updates across the devices and systems you own — on a defined schedule with rollback.

Is Windows Update enough for a small business?

It is a start for consumer-grade PCs, but IT still needs inventory, pilot rings, deferred risky feature updates, and coverage for non-Windows apps (browsers, VPN, softphones, firewalls).

How often should we patch?

Follow a monthly cadence for routine updates, plus an emergency path for critical security fixes — exact days depend on vendor release calendars and your maintenance windows.

What if a patch breaks calling or VPN?

Roll back or isolate the ring, restore from known-good config/backup if needed, and treat widespread outage as an incident — then widen the next pilot before company-wide push.

Do SaaS apps need patch management?

The vendor patches the service; you still patch clients/endpoints, keep MFA and vault hygiene, and track admin-console access — different job than OS patch rings.

Related Articles

More from the SessionTalk blog