DTNK

DTNK / INSIGHTS

Patch management for businesses: prioritise, test and document updates

A traceable patch process combines inventory, risk-based prioritisation, controlled testing, maintenance windows and verification.

Author: DTNK Redaktion
Published:

Illustration of protected IT infrastructure representing controlled patch management.
AI-generated illustration

A dependable process starts with an inventory

Record products, versions, owners, business dependencies and whether systems are internet-facing. Support status must be checked for each product and version because vendor lifecycles differ. Group comparable systems into maintenance cohorts, while keeping a separate path for rarely connected devices and specialist applications.

Prioritise according to risk and business impact

Confirm whether the exact deployed version is affected, whether exploitation has been observed, how exposed the system is and which business process depends on it. The CISA Known Exploited Vulnerabilities Catalog is a useful prioritisation signal, but deadlines for US federal agencies are not transferred to German businesses. Vendor information and your own exposure assessment remain necessary.

Use a representative test group and a rollback plan

The BSI module on patch and change management calls for planned, approved and documented changes, suitable testing and rollback options. Start with representative devices or systems and define stop criteria, decision owners and the practical route back to a usable state.

Separate routine maintenance from emergency patching

Plan routine updates within agreed maintenance windows and tell affected teams what to expect. For urgent security updates, use a predefined accelerated path. NIST recommends retaining a small test group for emergency patching where the situation allows. Temporary mitigations need a documented owner, review date and controlled removal once a permanent remedy is available.

Verify installation and usability

A deployment message is not complete evidence. Confirm the intended version on relevant systems, test important applications and follow up devices that were offline. Record each exception with its reason, owner, compensating measure and next review date.

Use a practical seven-point review

Inventory systems and owners; monitor vendor sources; assess exposure and impact; define pilot, approval and stop criteria; document routine and emergency paths; verify installation and important functions; and track exceptions until they are resolved or formally reassessed. Related DTNK service areas include workplace management, server infrastructure, monitoring and IT security.

Sources and editorial basis

Sources checked: 11 October 2026. Primary references: BSI OPS.1.1.3, NIST SP 800-40 Rev. 4, the CISA KEV Catalog and the Microsoft Lifecycle FAQ. Product status and vendor deadlines can change and should be checked for the specific version in use.

DTNK / SERVICES

Related services

Your first step

Let’s get to know
your IT.

Free. No obligation. Easy to understand.

Request your IT check