One of the eight mitigation strategies in the Essential Eight, checked against 9 tests at Maturity Level One.
Patching applications means keeping the software on your devices current, browsers, office suites and PDF readers included, and retiring software the vendor no longer supports.
Why it matters
Attackers weaponise known application flaws within days of disclosure. Most organisations carry a long tail of line-of-business software, so one unpatched system is a realistic route to sensitive data.
Where Intelligence Group fits
- Keep a live inventory of every application in use
- Patch internet-facing and high-risk applications inside the required window
- Find missing patches with a vulnerability scanner, not just the vendor's updater
- Remove applications the vendor no longer supports
- Record patch dates as evidence you can hand to an assessor
Where Intelligence Group fits
Intelligence Group rates this strategy from the evidence your organisation already generates, reports the maturity level it supports, and sets out the next step to lift it.
Official guidance: ASD Essential Eight Maturity Model

