Understand your environment
A short conversation about your device count, operating systems, current patching process, maintenance windows and what you're trying to achieve.
PatchAudit keeps small businesses patched automatically across Windows, macOS and Linux, and actively protected around the clock if you need it. No extra IT headcount. No broad managed-services contract. Just a monthly record you can hand straight to your insurer, your board, or your own peace of mind.
If you're running a business with a handful of computers up to a couple of hundred, you almost certainly don't have - and don't need - a full-time IT team. But three things still have to happen: every device needs to stay patched, something needs to be watching for actual threats, and you need to be able to prove both when someone asks.
And someone is asking. Cyber insurance renewals increasingly ask directly whether you have endpoint detection and response (EDR) deployed and a documented patch management process. The Australian Cyber Security Centre's Essential Eight lists patching applications and patching operating systems among its eight baseline strategies. None of that requires an in-house IT department - it requires a system that runs on its own and can show its work.
average self-reported cost of a cyber incident for an Australian medium-sized business (up 55%).
For small business this number is $56,600 (up 14%)
record-breaking vulnerabilities (CVEs) addressed in the July 2026 Microsoft Patch Tuesday alone, with over 400 targeting Windows components. The volume illustrates why manual patching becomes difficult to manage consistently.
surge in Remote Code Execution (RCE) vulnerabilities in 2025. Attackers are exploiting vulnerabilities faster than organizations relying on legacy patching workflows can remediate them.
Patching genuinely is a sequence - enroll, assess, deploy, verify, report - and each step depends on the one before it. Here's the order it runs in, every day.
A lightweight agent is deployed remotely to every device - Windows, Mac, or Linux - in minutes. No site visit, no downtime.
Every enrolled device is scanned around the clock for missing OS and application updates, including known, actively exploited vulnerabilities.
Patches roll out in maintenance windows built around your business hours. Critical, actively-exploited vulnerabilities can go out same-day.
Every patch is confirmed installed and functioning after deployment - not just marked as sent.
A plain-English record each month: what was patched, what's pending and why, and your overall compliance rate.
Operating systems:
Applications:
An honest look at how small-medium businesses (1–250 devices) handle patching and protection today.
| Feature | Doing it in-house | PatchAudit Core | PatchAudit Shield | Full-service MSP |
|---|---|---|---|---|
| Monthly cost | Often $0 in software cost - but real, unbilled staff time | One flat fee per device | One flat fee per device - includes Core | Bundled retainer, usually priced well above patching + protection alone |
| What's covered | Whatever there's time for | OS + application patching, start to finish | Everything in Core, plus 24/7 endpoint monitoring & response | Everything - patching, help desk, procurement, and more |
| Who manages failures and exceptions | Your team | PatchAudit — patch failures and exceptions investigated and managed | PatchAudit + MDR — patch exceptions and security alerts managed | Your provider, according to their service scope |
| Insurance / compliance evidence | You assemble it yourself, if you remember to | Monthly patch compliance report | Monthly patch + protection report | Varies by provider |
| Time to get running | As long as it takes internally | Days | Days | Often weeks of onboarding |
| Typical contract | N/A | Month-to-month | Month-to-month | Usually annual |
| Best fit | Businesses with real in-house time to spare | Businesses that just need patching handled | Businesses that also want active threat monitoring - often for insurance or compliance reasons | Businesses that want IT fully outsourced, end to end |
One number for patching alone, one for patching plus 24/7 protection. No quote form required.
Patch management for OS + apps, across Windows, macOS & Linux.
| 1–9 devices | $15.00 / device / mo |
|---|---|
| 10–49 devices | $12.50 / device / mo |
| 50+ devices | $10.00 / device / mo |
Everything in Core, plus 24/7 endpoint detection & response, powered by Malwarebytes ThreatDown.
| 1–9 devices | $30.00 / device / mo |
|---|---|
| 10–49 devices | $25.00 / device / mo |
| 50+ devices | $20.00 / device / mo |
Prices shown are in AUD per month and exclude GST. A short scope call confirms device count, supported operating systems and onboarding requirements before service begins.
Deployment timing remains subject to vendor patch availability, agreed maintenance policies and approved exceptions.
Getting started doesn't mean replacing your existing IT environment. We agree the scope, prove the configuration on a small group of devices, then roll out from there.
A short conversation about your device count, operating systems, current patching process, maintenance windows and what you're trying to achieve.
We enrol a small group of representative endpoints into the Action1 patch-management platform, configure the policies and maintenance windows, and verify that everything behaves as expected.
Once the configuration is agreed, the remaining supported endpoints are enrolled remotely. No site visit and no replacement of your existing IT systems.
From there, PatchAudit runs the service — continuously assessing endpoints, deploying updates, investigating exceptions and giving you a clear monthly record of the result.
Some patch management platforms give away a generous free tier if you're the one configuring policies, watching dashboards daily, and troubleshooting failures. That's a fine option if someone on your team has the spare hours for it. PatchAudit is for the businesses that don't - we own the whole process end to end and put a response time in writing.
You can. Action1 is an excellent platform and businesses with the time and expertise to configure, monitor and operate it directly may not need PatchAudit.
PatchAudit is for organisations that want the outcome without adding another system for someone internally to manage. We configure the environment, maintain patch policies, monitor deployments, investigate failures and exceptions, verify compliance and provide the monthly reporting.
Action1 provides the platform. PatchAudit provides the managed service.
Core is for businesses that want patching handled continuously across their supported endpoints, with verification and monthly compliance reporting.
Shield includes everything in Core and adds 24/7 endpoint detection and response, with security alerts monitored and investigated around the clock.
Choose Core when patch management is the priority. Choose Shield when you also want active threat monitoring and response.
It can. Cyber insurers commonly ask about endpoint detection and response and whether the business has a documented patch-management process.
PatchAudit provides evidence of the patching and endpoint-protection controls we manage, which you can provide to your insurer or broker. We aren't insurance brokers and can't guarantee coverage, acceptance or a particular premium.
Patch deployments use maintenance windows and staged rollout policies where appropriate to reduce the risk of problematic updates.
If a managed patch causes an issue, PatchAudit investigates the deployment and coordinates rollback or remediation within the scope of the service.
Yes. Devices connect over the internet from anywhere — no VPN or office network required. If a laptop is offline when a patch is scheduled, it is handled when the device reconnects.
Yes — servers can be managed alongside workstations and laptops, subject to supported operating systems and the agreed maintenance policy.
The service is month-to-month. Cancel with 30 days' notice — no multi-year lock-in.
No. PatchAudit is a focused patching and endpoint-protection service rather than a general-purpose IT provider.
If you already have internal IT or an MSP, we're designed to operate alongside them and take ownership of this specific part of the environment.
Give us a rough idea of your device count and what you need help with. We'll come back with any clarifying questions and tell you whether PatchAudit is a good fit.
Book a 15-minute call. We'll ask about your device mix, current patching process and what you're trying to achieve — and tell you directly whether PatchAudit is a good fit.