Updates You’re Probably Not Catching
Your operating system is probably the best-patched software on your computers. Modern Windows and macOS update themselves reasonably well, and if you have automated operating system patching in place, the platform mostly takes care of itself. The problem is everything else.
A typical business laptop runs dozens of applications on top of the operating system: a web browser and its extensions, a PDF reader, video conferencing, design and productivity tools, and whatever line-of-business software your team depends on. Each of those updates on its own schedule, through its own mechanism, or not at all. Control 7.4 is about closing that gap, because the software attackers reach for most often is rarely the operating system. It’s the browser, the document reader, and the everyday tools that quietly fall behind.
What this control actually says (in plain English)
Here’s the translation: the applications installed on your computers should update themselves automatically, on a schedule you set, the same way you’d expect your operating system to.
Now the official version. Control 7.4 says you should perform automated application patch management, applying updates to the software running on your enterprise assets on a monthly or more frequent cadence.
It sounds like a small addition to operating system patching. It isn’t. It’s where most of the real exposure lives.
Why this is the half that gets missed
Earlier in this series, I made the case for automating operating system patching in Perform Automated Operating System Patch Management. This is its companion, and I’d argue it’s the more important of the two. If you automate operating system updates and stop there, you’ve secured the foundation and left the doors and windows open.
Think about where your people actually spend their day. They live in a browser. They open documents from clients and vendors. They join meetings in conferencing software. Those are the same applications attackers study hardest, precisely because they’re installed everywhere and are so often out of date. A single unpatched browser or PDF reader is a more reliable way in than any flaw in the operating system underneath it. Patching the platform while ignoring the software running on it protects the part of the machine attackers are least interested in.
Why it’s harder, and why that’s the point
I’ll be honest about this one. Application patching takes more effort than operating system patching, and pretending otherwise sets you up to fail. There is no single built-in updater for your whole application estate. Some applications update themselves cleanly. Some need administrative rights the user doesn’t have. Some have been abandoned by the vendor entirely. And some are line-of-business tools nobody wants to touch for fear of breaking them.
That sprawl is exactly why this needs to be a system rather than a good intention. It’s also why it depends on the groundwork we laid earlier in the series. You can’t patch an application you don’t know is installed, which is why a real software inventory matters even more here than it did for the operating system. If you read the earlier spotlight on Why a Software Inventory Is More Than a Security Requirement, this is where that work pays off: the inventory tells you what has to stay current, and it surfaces the abandoned software that can no longer be patched at all.
What “good” looks like
You don’t need to chase every application by hand. You need a tool doing it for you and a short list of decisions that are yours to make. Here’s the practical path.
Automate the common applications. Use your RMM platform’s third-party patching, Microsoft Intune Enterprise App Management, or a dedicated third-party patching tool to keep widely installed applications current automatically. This is the engine that replaces manual chasing.
Lock down the highest-risk software first. Enforce automatic updates for browsers and their extensions, PDF readers, and conferencing tools, and set the policy so users can’t turn it off. These are the most-installed and most-attacked applications you own, so they earn the first attention.
Manage Macs the same way. Use Jamf or Intune to push and enforce application updates on macOS so your standard stays consistent across platforms.
Retire what you can’t patch. Any application the vendor no longer updates is a standing risk with no fix coming. Removing it is often cheaper and safer than defending it, and your software inventory is where you find these.
Verify by application, not just by machine. Pull a coverage report that shows which applications are current across the fleet, track exceptions on purpose, and treat anything that can’t be automated as a decision rather than a blind spot.
The payoff
Automating application patching does two things leaders feel quickly. It shrinks your attack surface where attackers actually operate, and it quietly removes a steady stream of “please update this” tickets that were never a good use of anyone’s time. It also produces the same evidence that operating system patching does: a record of what is current, what is behind, and what exceptions exist, across the software your business truly runs on.
Operating system patching secures the platform. Application patching secures the tools your people use to do the work. Automate both, hold them to a schedule you can verify, and you close the gap that quiet, out-of-date software leaves open. That is what essential cyber hygiene looks like in practice, and it’s well within reach for any organization willing to let a system do the remembering.
