"We patch monthly" is a cadence, not a plan. It tells you the interval and nothing else — not which systems, not who verifies the result, and not what happens when the job fails silently on a Sunday.
A plan answers the harder questions: what gets patched, in what order, with what evidence, and what you do when a patch lands badly. The interval is the easy half.
Why a single cadence fails
Monthly is a compromise between two risks that have almost nothing in common. An internet-facing VPN appliance with a known exploited vulnerability is not the same problem as an internal reporting box running a local-only service. Put both on the same calendar and the urgent one waits while the harmless one gets rebooted.
The timelines make this concrete. Once a high-profile CVE is weaponised, working exploits usually appear within 48 hours, and mass scanning starts sooner than that. That is well inside a monthly window. The vulnerability you can safely defer for two weeks is the one sitting behind a firewall with no reachable authentication surface.
So the real question is not how often you patch. It is how fast you can patch this class of system, and whether you can prove that you did.
Tier by exposure, not by calendar
Tier 1: internet-facing
Anything with a public listener — web servers, load balancers, VPN concentrators, mail gateways, exposed APIs. These patch against the clock, not the calendar. A critical vulnerability here is handled within 24 to 72 hours, out of band, with a reboot budget the business has already accepted in writing.
Tier 2: internal and service infrastructure
Databases, message queues, internal APIs, and CI runners holding deploy credentials. These matter, but the exposure window is narrower because the attacker needs a foothold first. A weekly or fortnightly window is usually defensible.
Tier 3: endpoints and long-tail hosts
Developer workstations, test boxes, and forgotten VMs. Patch monthly, but keep an inventory, because the real risk in this tier is a host nobody remembers owning or patching at all.
The loop every tier runs
The timer changes by tier. The loop does not.
- Detect. Feed a scanner and vendor advisories into an inventory that reflects reality, not the spreadsheet from last year.
- Stage. Apply the patch to a representative non-production host first, then let it bake for at least one business day.
- Apply. Roll out in waves, smallest blast radius first, inside a maintenance window the stakeholders know about.
- Verify. Confirm with the package manager and an independent scan — an agent reporting success is not proof of anything.
- Record. Log host, package, version, ticket, and timestamp. This artefact is what turns a cadence into evidence.
Plan for the patch that breaks production
Some patches break things, and pretending otherwise is how teams quietly stop patching. Every tier needs a rollback path that has been tested, not a theoretical one: package caches kept on the host, a snapshot taken immediately before the window, and a written rule for who can call a rollback without convening a meeting. If a patch requires a restart, schedule it and tell people — a surprise reboot during peak traffic is how an incident starts.
A patch policy nobody can audit is a mood, not a control.
How Weeltec runs this
On our server management engagements, every host is tagged by exposure tier in configuration management, and patching is driven from that tag rather than a manual list someone maintains by hand. Out-of-band critical patching is wired into the same alerting as production incidents, and the monthly report is generated from logs rather than memory. When an auditor asks you to show every host and its last patch date, the answer should be a query, not a project.
The rule
Pick your cadence, then write down what happens before, during, and after each window. Tier the systems by exposure. Test the rollback. Keep the evidence.
Monthly is fine as a default. It is not a plan until it has an owner, a tier, and a log line behind it.
Weeltec runs servers and infrastructure for teams that can't afford surprise outages. If your patch process lives in someone's head, get a quote and we'll put it in writing.