Illustration of servers and timely security patching

Security bulletin (practical edition): When vendors and agencies warn that collaboration or server software is under active exploitation, the businesses that get hurt are usually not “unlucky”—they are unpatched, under-monitored, or both.

Track high-impact advisories via CISA Cybersecurity Advisories and apply vendor guidance quickly for internet-facing systems.

What small businesses should do within 48–72 hours of a critical advisory

  • Inventory whether you run the affected product (on-prem SharePoint, Exchange, VPN appliances, etc.)
  • Apply vendor patches or official mitigations during a controlled window
  • Confirm backups completed successfully before major changes
  • Watch logs for unusual admin sign-ins and web shells if internet-facing
  • If you outsource IT, demand a written status: patched / mitigated / not applicable

Do not wait for “we’ll get to it next quarter”

Internet-facing servers are scanned constantly. Attackers automate exploitation once proof-of-concept code circulates. Internal-only systems still matter—ransomware crews love lateral movement from one forgotten box.

A simple monthly patch rhythm

  • Workstations: automatic updates + monthly compliance check
  • Servers: staged patches with a rollback plan
  • Firewalls/VPN: firmware within vendor-supported versions
  • Microsoft 365 / Google Workspace: track admin center message center items
  • Document exceptions with an owner and expiry date

Where to watch


If you are not sure what is internet-facing or unpatched in your environment, that is a managed services conversation—not a weekend project. Fully managed IT · Contact SabatAge · (845) 475-8468.

Subscribe

SabatAge blog—IT news, tips, and stories for Hudson Valley businesses