← Back to blog

2026-10-08 · Security Basics

Monthly Update Day: A 30-Minute Patch Routine for Small Offices

A 30-minute monthly routine for small offices: check CISA's KEV list first, then confirm Windows, Microsoft 365, browsers and router firmware, and log it.

This is a calendar habit. It isn't a full patch-management program.

Our other checklists give updates a single row. This post opens that row into one block a month where someone confirms that Windows, Microsoft 365 Apps, browsers, and the router or firewall are current. Anything on CISA's (the Cybersecurity and Infrastructure Security Agency) list of actively exploited flaws goes first.

It's for an owner or office manager at a business of about 5 to 50 people, whether you or an IT host does the updating. Once you have a device list, it takes about 30 minutes. The first one runs longer while you build that list.

How should a small office keep its software updated? Turn on automatic updates wherever they're offered, then book one Update Day a month to confirm they happened. Check CISA's Known Exploited Vulnerabilities catalog first for anything you use, then Windows, Microsoft 365 Apps, each browser, and the router or firewall firmware, and log one dated line per item.

Why a fixed day helps

Automatic updates do most of the work. CISA's Understanding Patches and Software Updates says: "If automatic options are available, the Cybersecurity and Infrastructure Security Agency (CISA) recommends that you take advantage of them." What they don't do is tell you they worked. A laptop that hasn't restarted in weeks, or a router nobody signs in to, can fall behind without anyone noticing.

NIST (the National Institute of Standards and Technology) explains the problem in its patch planning guide, SP 800-40 Rev. 4. Reboots and other interruptions mean routine patching "is often postponed and neglected." NIST adds that "Delaying routine patching also makes emergency patching more difficult, time-consuming, and disruptive," because older patches have to go on first.

CISA's Four Cybersecurity Essentials for Businesses says: "Work with your IT team to establish regular patching procedures and tests." Update Day is a small version of that. Current software reduces risk but doesn't remove it, so this habit sits alongside MFA and tested backups, not in place of them.

When to book it

Microsoft's Windows Update client policies page says: "Typically quality updates are released on the second Tuesday of each month, though they can be released at any time." The Microsoft 365 Apps update channels overview lists security updates on the same schedule: "Once a month, on the second Tuesday of the month."

We book it a few days after the second Tuesday, so the month's updates have had time to install, at an hour when a restart won't interrupt anyone.

Build the list once

CISA's Cybersecurity Performance Goals 2.0 include goal 2.A, Manage Organizational Assets: "Maintain a regularly updated inventory of all organizational assets." For Update Day, your list only needs each PC, which Microsoft 365 Apps and browsers it runs, the router or firewall brand and model, any VPN or remote-access tool, and who updates each one.

Step 1: Check the KEV catalog first (5 minutes)

The Known Exploited Vulnerabilities (KEV) catalog is CISA's list of software flaws that have been used in real attacks. The catalog page says: "Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework." CISA's page on reducing the risk of known exploited vulnerabilities recommends that organizations "prioritize remediation of the listed vulnerabilities to reduce the likelihood of compromise by known threat actors." One of its criteria for listing a flaw is that "There is a clear remediation action for the vulnerability, such as a vendor-provided update."

  • Open the catalog, set Date Added to the last 30 days, and filter Vendor/Project for the names on your list: Microsoft, your router or firewall maker, your VPN or remote-access tool.
  • For each match, write the CVE number (the flaw's ID) in your log, along with the entry's answer to "Known To Be Used in Ransomware Campaigns?"
  • For each match, ask your IT host: "Is this fixed on our equipment, and when?"

Each entry also shows a due date. Those deadlines are for federal agencies: "All federal civilian executive branch (FCEB) agencies are required to remediate vulnerabilities in the KEV catalog within prescribed timeframes." For a small business, a match just moves that item to the top of the list.

Step 2: Windows (8 minutes)

On each PC, open Start > Settings > Windows Update (Windows 11) or Settings > Update & Security > Windows Update (Windows 10) and check for updates. Microsoft's Windows Update FAQ shows where to confirm the result on Windows 11: Start > Settings > Windows Update > Update history. Write down the date of the latest quality update, and restart if Windows asks. Four Essentials says to "Make it a policy that staff reboot their devices regularly and pay attention to update notifications."

If your IT host manages Windows updates

That's common, so ask for a monthly report instead of checking each PC. Two things to know:

  • Microsoft calls Windows Update client policies (formerly Windows Update for Business) "a free service" for the Pro, Education, and Enterprise editions of Windows 10 and 11. Home edition isn't on that list.
  • They're applied through Group Policy or a device-management tool such as Microsoft Intune. Microsoft's Intune licensing page says "An Intune license is required for any user or device that benefits directly or indirectly from the Microsoft Intune service." Microsoft's device enrollment guide says Microsoft 365 Business Premium includes Intune Plan 1. Ask your IT host whether your plan includes it.

Step 3: Microsoft 365 Apps (5 minutes)

Office updates separately from Windows. Microsoft notes that "Versions of Office that are installed by using Click-to-Run can't be updated by using Windows Update client policies."

Microsoft's How to update Microsoft 365 or Office for Windows gives the path: open Word, go to File > Account, then Update Options > Update Now. If the button isn't there, Microsoft explains that "you either have a volume license install or your company is using Group Policy to manage Microsoft 365 or Office updates." In that case, ask your IT host for a version report. Either way, log the version.

Step 4: Browsers (5 minutes)

Microsoft's Edge update settings page says: "By default, Microsoft Edge automatically updates when you restart your browser." Open Settings and more > Help and feedback > About Microsoft Edge (or edge://settings/help) to see whether it's up to date. Chrome and Firefox have similar About pages. Check every browser on the machine, not just the one people use most. If the update toggles are greyed out, Microsoft notes they "may be unavailable" when your organization manages Edge settings, so ask your IT host instead.

Step 5: Router and firewall firmware (5 minutes)

CISA's Four Cybersecurity Essentials for Businesses says: "Prioritize critical vulnerabilities, especially for public-facing or legacy systems." A router or firewall sits at the edge of your network, so its firmware belongs on that list. CPG 2.0 goal 3.S, Secure Internet Facing Devices, adds: "Prioritize keeping software current with timely patches and updates."

On Update Day you're only looking. A firmware update can restart the network, so schedule it instead of starting it mid-morning.

  • IT host manages it: ask for the current firmware version and the last update date.
  • ISP supplied it: ask the ISP who updates it, and whether they will replace it once the manufacturer stops supporting it.
  • You manage it: sign in to the admin page, note the firmware version, and compare it with the maker's support site.

Step 6: Note anything past end of life (2 minutes)

Some software no longer gets security updates. CISA's patches page says: "CISA recommends that users and administrators retire all EOL products." EOL means end of life. Windows 10 is the one to watch, since Microsoft's Install Windows Updates page says "After October 14, 2025, Microsoft will no longer provide free software updates from Windows Update, technical assistance, or security fixes for Windows 10." Microsoft's page on the Windows 10 Extended Security Updates (ESU) program describes ESU as "a paid program" that lets organizations keep receiving security updates after support ends. List any PC, router, or app in that state, and ask your IT host for a replacement plan and date.

Printable Update Day log

Copy or print this table. One row per item, each month. Leave blanks as unknown. Don't guess.

#ItemCheckPass looks likeVersion / last updateKEV match (CVE)Who fixes, by whenDate / initials
1KEV catalogLast 30 days, your vendorsNo match, or each match has an owner
2Windows PCsUpdate history on each PCLatest quality update, restarted
3Microsoft 365 AppsFile > AccountCurrent for its channel, or host report
4BrowsersEach About pageUp to date
5Router / firewallAdmin page or host answerFirmware version and date known
6VPN / remote access / NASVendor portal or host answerVersion and date known
7End-of-life itemsYour listNone, or each has a replacement date

Update Day date: YYYY-MM-DD · Checked by: · Next Update Day:

Save it as update-day-YYYY-MM-DD in the same folder as your MFA and backup logs.

If something is behind

That's normal, and it's what the log is for. Don't troubleshoot during the 30 minutes. Send it to your IT host as a ticket instead.

FindingWhat to ask for
A KEV entry matches something you use"Is CVE-____ fixed on our equipment? Send the date."
Office shows no Update Now buttonA version report for every PC
Router firmware date unknownCurrent version, last update date, and who owns updates
Windows 10 or another end-of-life itemA replacement plan with a date

Question 4 on the IT-host renewal card asks the same thing at renewal: what's the patch cadence, and how do you see that it happened?

Related guides


Educational content only — not legal, insurance, or compliance advice.

Need help implementing this in Houston?

Houston Secure IT can walk through MFA, backups, and a practical baseline with you.

713-364-8666 — Houston Secure IT / shop line