it-service@brocent.com
Patch Management
Operating-system and third-party patch compliance, vulnerability exposure and remediation timeliness across the managed estate for the August 2026 reporting period.
Operating systems are fully patched; third-party software and reboots are the exposure
All 38 managed devices received the August cumulative Windows and macOS updates within the agreed maintenance window. No security-classified operating-system patch remains outstanding at the end of the period, and mean time to patch for critical updates improved from 6.4 to 4.1 days.
Residual risk sits in two places. Six devices have a pending reboot and are therefore running unpatched code in memory despite reporting as compliant; and 41 third-party application vulnerabilities remain open across four titles, one of which — a browser engine flaw — appears on the CISA Known Exploited Vulnerabilities catalogue. Both are addressable inside September without a change window.
Patch position at period end
Compliance counts a device as patched only when the update is installed and any required restart has completed. Third-party coverage is the share of discovered application titles that the patch engine can update automatically.
Four items require action
Evidence. A browser-engine memory-corruption flaw listed on the CISA KEV catalogue is present on three endpoints. The vendor fix is staged and validated; installation completes only after the browser is fully closed and the device restarted.
Impact. Active in-the-wild exploitation makes this the single highest-likelihood compromise route in the estate. A drive-by page visit is sufficient.
Recommendation. Approve a forced restart outside trading hours on the three devices this week. BCS Support Center will notify the users 24 hours ahead and confirm the fixed version afterwards.
Evidence. Six endpoints have installed updates awaiting a restart; uptime on two exceeds 14 days and on one exceeds 30. Users have deferred the prompt repeatedly.
Impact. The device reports as patched while still executing vulnerable code, which overstates compliance to both management and any auditor sampling the estate.
Recommendation. Introduce a seven-day deferral cap with a forced restart at 02:00 local time, applied by policy rather than by request.
Evidence. A PDF reader, an archive utility, a market-data terminal and a video-conferencing client account for 34 of the 41 open vulnerabilities. Three are not supported by the patch engine; the terminal is vendor-updated only.
Impact. These titles will remain a recurring finding every period until either the packaging work is done or the software is replaced.
Recommendation. Package the three unsupported titles for automated deployment; agree a vendor-driven update window with the market-data provider.
Evidence. Five of 614 deployments failed on first attempt — three from insufficient disk space, two from a network interruption during download. All succeeded on retry within the same window.
Recommendation. Add a pre-deployment free-space check at 12 GB and alert below threshold, removing the most common failure cause.
The July backlog of 104 open vulnerabilities was reduced to 41. The two devices reported last period as more than 60 days behind on cumulative updates are now current, and the macOS fleet moved to the supported major release on 2026-08-19.
Four of five service levels met
| Committed service level | Target | Actual | Status | Note |
|---|---|---|---|---|
| Critical OS patches deployed | ≤ 7 days of release | 4.1 days avg | MET | 38 of 38 devices |
| OS patch compliance at period end | ≥ 98% | 100% | MET | No outstanding security patch |
| Third-party critical remediation | ≤ 14 days | 21 days (1 title) | MISSED | Awaiting restart approval |
| Maintenance window adherence | 100% | 100% | MET | No deployment in trading hours |
| Monthly report issued | By 5th working day | 3rd working day | MET | Issued 2026-09-03 |
Three-period movement
| Metric | Jun 2026 | Jul 2026 | Aug 2026 | Direction of travel |
|---|---|---|---|---|
| OS patch compliance | 94.6% | 97.4% | 100% | Third consecutive improvement; now above target. |
| Mean time to patch (critical) | 8.9 d | 6.4 d | 4.1 d | Halved since June as the ring deployment matured. |
| Open vulnerabilities | 147 | 104 | 41 | Backlog burn-down on plan; remainder concentrated in 4 titles. |
| Known-exploited (KEV) | 2 | 1 | 1 | Flat — the residual item needs a restart, not a patch. |
| Reboot pending | 3 | 4 | 6 | Rising; user-deferred restarts need a policy cap. |
| Third-party coverage | 68% | 73% | 82% | Improving as titles are packaged for automation. |
Bars are scaled to the 41 open items. Severity here is the vendor CVSS band, not the operational severity used for findings.
Where the remaining exposure sits
The 41 distinct open items appear as 118 instances across 12 devices. Distinct items drive the remediation plan; instances drive the deployment effort. Both counts are stated wherever they differ.
Deadlines follow the agreed remediation windows by CVSS band, not the vendor release date. All six overdue items belong to the four titles outside automated patching.
Thirty-two items have a vendor fix that BCS can deploy in the next window. The nine vendor-dependent items are all in the market-data terminal and require the provider's own update.
Twenty-seven of 41 items were published in the last two years, which is the expected profile for a patched estate. The six items older than 2024 all sit in the two titles awaiting packaging — age here indicates a coverage gap, not a delayed decision.
Bars are scaled to the highest device count (12). The remaining six devices carry 55 instances between them, none above eight. The three Critical instances are the same known-exploited browser item.
Version sprawl
The same application running at different versions across the estate is the leading cause of recurring vulnerabilities. Consolidating each title to a single version removes the drift at source.
| Application | Versions | Installs | Consolidation action |
|---|---|---|---|
| PDF reader | 4 | 31 | Package the current release and force-upgrade all 31 installs. |
| Browser (Chromium engine) | 3 | 38 | Restart the three lagging devices; auto-update handles the rest. |
| Video conferencing | 3 | 38 | Enforce the managed installer so users cannot pin an old build. |
| Archive utility | 2 | 24 | Replace with the built-in OS tool; removes the title entirely. |
| Java runtime | 2 | 4 | Retire alongside the legacy tool it supports. |
Vulnerabilities by software title
All titles carrying an open vulnerability at period end. The full CVE-level listing is delivered as a separate machine-readable export.
| Software title | Installs | Open | Highest | Automated | Position |
|---|---|---|---|---|---|
| Browser (Chromium engine) | 3 | 4 | CRITICAL | Yes | Fix staged; awaiting restart approval. Includes the KEV item. |
| PDF reader | 31 | 12 | HIGH | No | Not supported by the patch engine; packaging in progress. |
| Market-data terminal | 17 | 9 | HIGH | Vendor | Vendor-controlled updates; window to be agreed. |
| Archive utility | 24 | 8 | MEDIUM | No | Candidate for replacement with the built-in OS tool. |
| Video conferencing | 38 | 5 | MEDIUM | Yes | Auto-update enabled; clears on next client launch. |
| Java runtime | 4 | 3 | LOW | Yes | Retained for one legacy tool; removal proposed. |
Devices requiring attention
| Hostname | Site | OS build | Last patched | Uptime | Open vulns | Reboot | Action |
|---|---|---|---|---|---|---|---|
| ACM-WS-004 | HK | 26100.7920 | 2026-08-14 | 34 d | 7 | PENDING | Forced restart 02:00 |
| ACM-WS-011 | HK | 26100.7920 | 2026-08-14 | 19 d | 6 | PENDING | Forced restart 02:00 |
| ACM-WS-019 | SZ | 26100.7920 | 2026-08-15 | 11 d | 5 | PENDING | Scheduled 2026-09-06 |
| ACM-WS-022 | SZ | 26100.7920 | 2026-08-15 | 9 d | 4 | PENDING | Scheduled 2026-09-06 |
| ACM-WS-027 | HK | 26100.7920 | 2026-08-16 | 8 d | 4 | PENDING | Scheduled 2026-09-06 |
| ACM-WS-033 | HK | 26100.7920 | 2026-08-16 | 7 d | 3 | PENDING | Scheduled 2026-09-06 |
| ACM-SRV-01 | HK | 20348.2966 | 2026-08-17 | 17 d | 2 | NONE | Next window 2026-09-20 |
Deployment activity
| Deployment ring | Devices | Patches | Success | Window |
|---|---|---|---|---|
| Ring 0 — pilot | 3 | 48 | 100% | 2026-08-13, 20:00–23:00 HKT |
| Ring 1 — back office | 14 | 231 | 99.6% | 2026-08-14, 20:00–01:00 HKT |
| Ring 2 — front office | 18 | 298 | 98.7% | 2026-08-16, Saturday daytime |
| Servers | 3 | 37 | 100% | 2026-08-17, Sunday 02:00–05:00 |
Open items carried between periods
| Ref | Risk | Severity | Owner | Due | Status | Next action |
|---|---|---|---|---|---|---|
| PATCH-R01 | Known-exploited vulnerability live in the estate — 3 devices pending restart | CRITICAL | Client IT | 2026-09-09 | Open | Approve out-of-hours forced restart; BCS to confirm fixed version. |
| PATCH-R02 | User-deferred restarts mask true compliance — no deferral cap in policy | HIGH | BCS + Client IT | 2026-09-15 | In progress | Apply a 7-day cap with a 02:00 forced restart. |
| PATCH-R03 | Third-party titles outside automation — recurring vulnerability source | MEDIUM | BCS Support Center | 2026-10-15 | In progress | Package 3 titles; agree vendor window for the terminal. |
| PATCH-R04 | No documented emergency patch procedure — zero-day response is ad hoc | MEDIUM | BCS + Client IT | 2026-11-30 | Open | Draft a one-page out-of-band patch procedure with pre-agreed approval. |
| PATCH-R05 | Low disk space causes deployment failures — 3 devices below 12 GB free | LOW | BCS Support Center | 2026-10-31 | Open | Add a pre-deployment free-space check and alert. |
Next period commitments
| BCS Support Center will | Client is asked to |
|---|---|
| Clear the KEV item and confirm the fixed browser version on all three devices. | Approve the out-of-hours forced restart by 2026-09-08. |
| Apply the seven-day restart deferral cap across the estate. | Endorse the deferral cap in the endpoint policy. |
| Package the PDF reader and archive utility for automated patching. | Decide whether the archive utility is retained or replaced. |
| Add free-space pre-checks and report deployment failures by cause. | Introduce BCS to the market-data vendor's technical contact. |
How this report was produced
| Source | Extracted | Records | Used for |
|---|---|---|---|
| RMM patch engine | 2026-09-01 02:15 HKT | 614 deployments | Deployment results, compliance state, reboot flags. |
| Vulnerability assessment | 2026-09-01 03:40 HKT | 41 open items | Open vulnerabilities by title and severity. |
| CISA KEV catalogue | 2026-09-01 | 1 match | Known-exploited flagging. |
| Windows Update for Business | 2026-09-01 | 33 devices | OS build verification and ring assignment. |
| Change and ticket record | 2026-08-31 | 9 changes | Maintenance window adherence, retries, approvals. |
Method and definitions
Patch compliance counts a device as compliant only when every security-classified update released more than seven days before period end is installed and any required restart has completed. A device with a pending reboot is counted as non-compliant for that patch, which is stricter than the vendor tooling's own reporting.
Mean time to patch is measured from vendor release to successful installation across the estate, not from the date the patch was approved internally.
Severity. Finding severity reflects operational and due-diligence risk (Critical 24 hours, High five business days, Medium next cycle, Low backlog). Vulnerability severity in section 06 is the vendor CVSS band; the two scales are deliberately separate and are never mixed in one column.
Exclusions. Firmware and BIOS updates are handled under a separate change process; network appliance firmware is reported in the Availability Monitoring report. Personal unmanaged devices are out of scope.
This copy is an anonymised sample prepared for illustration. The client name, hostnames and software vendor names have been replaced with fictitious or generic values; counts, ratios, dates and findings reflect a representative managed estate. No real client data appears in this document.
BCS Support Center · it-service@brocent.com
Questions clients ask about this report
Our commitment is critical operating-system patches within 14 days of vendor release and security patches within 30 days. The report states attainment against those targets by device class, and names every device that missed with the reason.
They become documented exceptions with an owner, a compensating control and an expiry date. An exception without an expiry date is reported as a finding, not as an exception.
Yes. Browsers, runtimes, PDF readers and collaboration clients are patched on the same cycle, and are reported separately because they are the most common exploited path on a well-patched operating system.
See what your own Patch Management report would say
A free IT health check produces a first version of this report against your real estate, at no cost and with no obligation. It takes about a week and needs a few hours of your team’s time.