The problems with patching
Applying patches may be a basic security principle, but that doesn't mean it's always easy to do in practice.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening

The ways that we patch our organisations' IT may change over time, but patching - in general - has always been good for security. This blog explains why the NCSC repeats the 'patch your boxes' advice so often, whilst acknowledging the challenges that patching often presents.
Vulnerabilities in technology are always being discovered and in response, vendors regularly issue security updates to plug the gaps. Applying these updates - a process commonly known as patching - closes vulnerabilities before attackers can exploit them. Patching can also fix bugs, add new features, increase stability, and improve look and feel (or other aspects of the user experience).
So patching matters for more than just security reasons. It ensures you're getting most from your IT, and that it's working smoothly with other people and organisations.
For all these reasons, patching remains the single most important thing you can do to secure your technology, and is why applying patches is often described as 'doing the basics'. But although applying patches may be a basic security principle, that doesn't mean it's always easy to do in practice.
There are lots of reasons why your approach to patching can't simply be 'patch all of things, all of the time'. These include:
None of the above are reasons not to patch as much you can, but they do explain why you need to plan your patching regime carefully.
Your approach to patching will depend on what your organisation does, how you approach security, and how much you have to spend. Security always involves combining different defences, and often making trade-offs, to try and reduce your overall business risk to acceptable levels. Our vulnerability management guidance tells you how to get started with creating a patching strategy that works for your organisation by assessing and prioritising vulnerabilities, and my colleague Andrew's blog post has ideas on how to make patching part of your organisation's 'business-as-usual'.
When patching is hard or impossible, this is where your defence-in-depth tactics come to the fore. You can:
reduce ways to exploit attacks through architecture and configuration
manage your assets well (know what you have and what it's doing, and have ways of finding out when something changes)
have a security monitoring capability, to help with problem detection and cleanup
All this will help you prevent attacks where you can, and detect, respond and clean up where you can't.
What else helps you and your organisations to manage this tricky security problem well? What else would be useful to you, that you don't have now? We'd love to hear your thoughts and experiences - please share them with us by contacting our Enquiries service, or letting us know on social media.
Emma W
Head of Advice and Guidance


