B BROCENT
Brocent — Your Asia IT Team
BCS Support Center · Hong Kong
it-service@brocent.com
Monthly client report · 02 of 09

Patch Management

Operating-system and third-party patch compliance, vulnerability exposure and remediation timeliness across the managed estate for the August 2026 reporting period.

Client
Acme Capital Limited
Reporting period
2026-08-01 → 08-31
Issued
2026-09-03
Reference
PATCH-2026-08
Scope
35 patchable endpoints · 3 servers
Sources
RMM patch engine, WUfB, CVE feed
Prepared by
BCS Support Center
Classification
Confidential
01 · Executive summary

Operating systems are fully patched; third-party software and reboots are the exposure

All 38 managed devices received the August cumulative Windows and macOS updates within the agreed maintenance window. No security-classified operating-system patch remains outstanding at the end of the period, and mean time to patch for critical updates improved from 6.4 to 4.1 days.

Residual risk sits in two places. Six devices have a pending reboot and are therefore running unpatched code in memory despite reporting as compliant; and 41 third-party application vulnerabilities remain open across four titles, one of which — a browser engine flaw — appears on the CISA Known Exploited Vulnerabilities catalogue. Both are addressable inside September without a change window.

Service verdict
Met, with action
Four of five patch service levels were met. The third-party remediation target of 14 days was missed on one title. One known-exploited vulnerability requires client approval for an out-of-hours restart, tracked as PATCH-R01.
02 · Key indicators

Patch position at period end

OS patch compliance
100%
▲ +2.6 pts
Mean time to patch
4.1 d
▲ −2.3 d
Open vulnerabilities
41
▲ −63 vs Jul
Known exploited (KEV)
1
— unchanged
Reboot pending
6
▼ +2 vs Jul
Patches deployed
614
▲ +58 vs Jul
Deployment success
99.2%
▲ +0.7 pts
Third-party coverage
82%
▲ +9 pts

Compliance counts a device as patched only when the update is installed and any required restart has completed. Third-party coverage is the share of discovered application titles that the patch engine can update automatically.

03 · Key findings

Four items require action

One known-exploited browser vulnerability remains unpatched on three devices
CRITICAL

Evidence. A browser-engine memory-corruption flaw listed on the CISA KEV catalogue is present on three endpoints. The vendor fix is staged and validated; installation completes only after the browser is fully closed and the device restarted.

Impact. Active in-the-wild exploitation makes this the single highest-likelihood compromise route in the estate. A drive-by page visit is sufficient.

Recommendation. Approve a forced restart outside trading hours on the three devices this week. BCS Support Center will notify the users 24 hours ahead and confirm the fixed version afterwards.

Owner Client IT (approval) Target 2026-09-09 Ref PATCH-2026-08-01
Six devices carry a pending reboot, two for longer than fourteen days
HIGH

Evidence. Six endpoints have installed updates awaiting a restart; uptime on two exceeds 14 days and on one exceeds 30. Users have deferred the prompt repeatedly.

Impact. The device reports as patched while still executing vulnerable code, which overstates compliance to both management and any auditor sampling the estate.

Recommendation. Introduce a seven-day deferral cap with a forced restart at 02:00 local time, applied by policy rather than by request.

Owner BCS Support Center Target 2026-09-15 Ref PATCH-2026-08-02
Four third-party titles are outside automated patching · carried forward (2 periods)
MEDIUM

Evidence. A PDF reader, an archive utility, a market-data terminal and a video-conferencing client account for 34 of the 41 open vulnerabilities. Three are not supported by the patch engine; the terminal is vendor-updated only.

Impact. These titles will remain a recurring finding every period until either the packaging work is done or the software is replaced.

Recommendation. Package the three unsupported titles for automated deployment; agree a vendor-driven update window with the market-data provider.

Owner BCS Support Center Target 2026-10-15 Ref PATCH-2026-07-03
Five deployment failures required a retry
LOW

Evidence. Five of 614 deployments failed on first attempt — three from insufficient disk space, two from a network interruption during download. All succeeded on retry within the same window.

Recommendation. Add a pre-deployment free-space check at 12 GB and alert below threshold, removing the most common failure cause.

Owner BCS Support Center Target 2026-10-31 Ref PATCH-2026-08-04
Closed this period · 63 vulnerabilities remediated, including 9 high-severity
RESOLVED

The July backlog of 104 open vulnerabilities was reduced to 41. The two devices reported last period as more than 60 days behind on cumulative updates are now current, and the macOS fleet moved to the supported major release on 2026-08-19.

04 · Service level attainment

Four of five service levels met

Committed service levelTargetActualStatusNote
Critical OS patches deployed ≤ 7 days of release 4.1 days avg MET 38 of 38 devices
OS patch compliance at period end ≥ 98% 100% MET No outstanding security patch
Third-party critical remediation ≤ 14 days 21 days (1 title) MISSED Awaiting restart approval
Maintenance window adherence 100% 100% MET No deployment in trading hours
Monthly report issued By 5th working day 3rd working day MET Issued 2026-09-03
05 · Trend

Three-period movement

MetricJun 2026Jul 2026Aug 2026Direction of travel
OS patch compliance 94.6% 97.4% 100% Third consecutive improvement; now above target.
Mean time to patch (critical) 8.9 d 6.4 d 4.1 d Halved since June as the ring deployment matured.
Open vulnerabilities 147 104 41 Backlog burn-down on plan; remainder concentrated in 4 titles.
Known-exploited (KEV) 2 1 1 Flat — the residual item needs a restart, not a patch.
Reboot pending 3 4 6 Rising; user-deferred restarts need a policy cap.
Third-party coverage 68% 73% 82% Improving as titles are packaged for automation.
Open vulnerabilities by severity · 41 total
Critical
2
High
9
Medium
22
Low
8

Bars are scaled to the 41 open items. Severity here is the vendor CVSS band, not the operational severity used for findings.

06 · Detail data

Where the remaining exposure sits

The 41 distinct open items appear as 118 instances across 12 devices. Distinct items drive the remediation plan; instances drive the deployment effort. Both counts are stated wherever they differ.

Remediation status · 41 distinct items
Overdue · 6 Due within 14 days · 14 Due later · 21

Deadlines follow the agreed remediation windows by CVSS band, not the vendor release date. All six overdue items belong to the four titles outside automated patching.

Fix availability · 41 distinct items
Fixable now · 32 Vendor-dependent · 9

Thirty-two items have a vendor fix that BCS can deploy in the next window. The nine vendor-dependent items are all in the market-data terminal and require the provider's own update.

Open items by CVE publication year · 41 distinct
2
2022
4
2023
8
2024
15
2025
12
2026

Twenty-seven of 41 items were published in the last two years, which is the expected profile for a patched estate. The six items older than 2024 all sit in the two titles awaiting packaging — age here indicates a coverage gap, not a delayed decision.

Open instances per device · top 6 of 12
ACM-WS-004
12
ACM-WS-011
11
ACM-WS-015
11
ACM-WS-019
10
ACM-WS-022
10
ACM-WS-027
9
Critical High Medium Low

Bars are scaled to the highest device count (12). The remaining six devices carry 55 instances between them, none above eight. The three Critical instances are the same known-exploited browser item.

Version sprawl

The same application running at different versions across the estate is the leading cause of recurring vulnerabilities. Consolidating each title to a single version removes the drift at source.

ApplicationVersionsInstallsConsolidation action
PDF reader431Package the current release and force-upgrade all 31 installs.
Browser (Chromium engine)338Restart the three lagging devices; auto-update handles the rest.
Video conferencing338Enforce the managed installer so users cannot pin an old build.
Archive utility224Replace with the built-in OS tool; removes the title entirely.
Java runtime24Retire alongside the legacy tool it supports.

Vulnerabilities by software title

All titles carrying an open vulnerability at period end. The full CVE-level listing is delivered as a separate machine-readable export.

Software titleInstallsOpenHighestAutomatedPosition
Browser (Chromium engine)34CRITICALYesFix staged; awaiting restart approval. Includes the KEV item.
PDF reader3112HIGHNoNot supported by the patch engine; packaging in progress.
Market-data terminal179HIGHVendorVendor-controlled updates; window to be agreed.
Archive utility248MEDIUMNoCandidate for replacement with the built-in OS tool.
Video conferencing385MEDIUMYesAuto-update enabled; clears on next client launch.
Java runtime43LOWYesRetained for one legacy tool; removal proposed.

Devices requiring attention

HostnameSiteOS buildLast patchedUptimeOpen vulnsRebootAction
ACM-WS-004HK26100.79202026-08-1434 d7PENDINGForced restart 02:00
ACM-WS-011HK26100.79202026-08-1419 d6PENDINGForced restart 02:00
ACM-WS-019SZ26100.79202026-08-1511 d5PENDINGScheduled 2026-09-06
ACM-WS-022SZ26100.79202026-08-159 d4PENDINGScheduled 2026-09-06
ACM-WS-027HK26100.79202026-08-168 d4PENDINGScheduled 2026-09-06
ACM-WS-033HK26100.79202026-08-167 d3PENDINGScheduled 2026-09-06
ACM-SRV-01HK20348.29662026-08-1717 d2NONENext window 2026-09-20

Deployment activity

Deployment ringDevicesPatchesSuccessWindow
Ring 0 — pilot348100%2026-08-13, 20:00–23:00 HKT
Ring 1 — back office1423199.6%2026-08-14, 20:00–01:00 HKT
Ring 2 — front office1829898.7%2026-08-16, Saturday daytime
Servers337100%2026-08-17, Sunday 02:00–05:00
07 · Risk register

Open items carried between periods

RefRiskSeverityOwnerDueStatusNext action
PATCH-R01 Known-exploited vulnerability live in the estate — 3 devices pending restart CRITICAL Client IT 2026-09-09 Open Approve out-of-hours forced restart; BCS to confirm fixed version.
PATCH-R02 User-deferred restarts mask true compliance — no deferral cap in policy HIGH BCS + Client IT 2026-09-15 In progress Apply a 7-day cap with a 02:00 forced restart.
PATCH-R03 Third-party titles outside automation — recurring vulnerability source MEDIUM BCS Support Center 2026-10-15 In progress Package 3 titles; agree vendor window for the terminal.
PATCH-R04 No documented emergency patch procedure — zero-day response is ad hoc MEDIUM BCS + Client IT 2026-11-30 Open Draft a one-page out-of-band patch procedure with pre-agreed approval.
PATCH-R05 Low disk space causes deployment failures — 3 devices below 12 GB free LOW BCS Support Center 2026-10-31 Open Add a pre-deployment free-space check and alert.

Next period commitments

BCS Support Center willClient is asked to
Clear the KEV item and confirm the fixed browser version on all three devices. Approve the out-of-hours forced restart by 2026-09-08.
Apply the seven-day restart deferral cap across the estate. Endorse the deferral cap in the endpoint policy.
Package the PDF reader and archive utility for automated patching. Decide whether the archive utility is retained or replaced.
Add free-space pre-checks and report deployment failures by cause. Introduce BCS to the market-data vendor's technical contact.
Appendix · Method and definitions

How this report was produced

SourceExtractedRecordsUsed for
RMM patch engine 2026-09-01 02:15 HKT 614 deployments Deployment results, compliance state, reboot flags.
Vulnerability assessment 2026-09-01 03:40 HKT 41 open items Open vulnerabilities by title and severity.
CISA KEV catalogue 2026-09-01 1 match Known-exploited flagging.
Windows Update for Business 2026-09-01 33 devices OS build verification and ring assignment.
Change and ticket record 2026-08-31 9 changes Maintenance window adherence, retries, approvals.

Method and definitions

Patch compliance counts a device as compliant only when every security-classified update released more than seven days before period end is installed and any required restart has completed. A device with a pending reboot is counted as non-compliant for that patch, which is stricter than the vendor tooling's own reporting.

Mean time to patch is measured from vendor release to successful installation across the estate, not from the date the patch was approved internally.

Severity. Finding severity reflects operational and due-diligence risk (Critical 24 hours, High five business days, Medium next cycle, Low backlog). Vulnerability severity in section 06 is the vendor CVSS band; the two scales are deliberately separate and are never mixed in one column.

Exclusions. Firmware and BIOS updates are handled under a separate change process; network appliance firmware is reported in the Availability Monitoring report. Personal unmanaged devices are out of scope.

Anonymisation notice

This copy is an anonymised sample prepared for illustration. The client name, hostnames and software vendor names have been replaced with fictitious or generic values; counts, ratios, dates and findings reflect a representative managed estate. No real client data appears in this document.

Questions on this report
BCS Support Center · it-service@brocent.com
Brocent — Your Asia IT Team
Frequently asked

Questions clients ask about this report

How quickly should critical patches be deployed?

Our commitment is critical operating-system patches within 14 days of vendor release and security patches within 30 days. The report states attainment against those targets by device class, and names every device that missed with the reason.

What happens to devices that cannot be patched on schedule?

They become documented exceptions with an owner, a compensating control and an expiry date. An exception without an expiry date is reported as a finding, not as an exception.

Do you patch third-party applications as well as Windows and macOS?

Yes. Browsers, runtimes, PDF readers and collaboration clients are patched on the same cycle, and are reported separately because they are the most common exploited path on a well-patched operating system.

Next step

See what your own Patch Management report would say

A free IT health check produces a first version of this report against your real estate, at no cost and with no obligation. It takes about a week and needs a few hours of your team’s time.

Book a free IT health check Contact BCS Support Center