Patch management
The scheduled process of testing and applying operating system and software updates across every machine in a company.
Patching is the least interesting work in IT and the most likely to be quietly skipped, because nothing visibly breaks when it does not happen. It breaks later, usually through a vulnerability that had a fix available for months.
The part most small offices miss is third-party software. Windows nags loudly enough to eventually get done; the browser, the PDF reader and the conferencing client are the ones with the exploited vulnerabilities and the ones nobody thinks about.
Done properly it runs on a schedule with a short soak period, so a bad vendor patch does not reach every machine on day one, and with retry and escalation on anything that fails twice.
What it costs
Typically inside a per-user plan. Where it is billed separately expect $5 to $15 per endpoint per month, which is worth questioning.
Related questions
How often should patches be applied?
Monthly for routine operating system and application updates, with a short soak before general rollout. Genuine emergencies get handled out of cycle.
What if an update breaks something?
That is what the soak period is for. Rolling back a bad patch should be support, not a separate charge.
Related service: Patch management · Patch Management Pricing