By Paul Rollman, Founder, NJ Cyber Security Solutions
Ask most small business owners who’s responsible for keeping devices updated, and you’ll get a pause, then something like “IT handles that” or “I think it updates automatically.” That answer usually isn’t wrong — until it is, on the one laptop or the one piece of practice-management software that quietly stopped patching itself months ago.
Device Maintenance Month is a good time to fix that gap for good. Not with another reminder to “keep your software updated,” but with an actual, written policy: who owns updates, what needs to be covered, how often it happens, and how you’ll know it’s working. This guide walks through building one, even if your business has no dedicated IT department.
The cost of skipping this isn’t abstract. The Federal Trade Commission (FTC) points to unpatched software as one of the basic security gaps small businesses are expected to close, and cyber insurance carriers increasingly ask about patch management practices directly during underwriting. A simple policy is often the difference between a clean answer on that questionnaire and a scramble to prove you’re doing something you assumed was already happening.
Table of Contents
- Why “Someone Should Update That” Isn’t a Policy
- Step 1: Assign Ownership
- Step 2: Inventory What Actually Needs Updating
- Step 3: Set a Realistic Cadence
- Step 4: Don’t Forget Employee-Owned and Remote Devices
- Step 5: Document It and Review It Twice a Year
- Tools That Make This Easier
- What This Looks Like in Practice
- FAQ
Why “Someone Should Update That” Isn’t a Policy
Most small businesses already know updates matter. Where the system breaks down isn’t awareness — it’s ownership. When update responsibility is informal (“whoever notices the pop-up”), a few predictable things happen: office workstations get patched because someone sees the notification, while the server in the closet, the point-of-sale terminal, or the industry-specific software nobody opens every day quietly falls behind.
The Cybersecurity and Infrastructure Security Agency (CISA) consistently identifies unpatched, known vulnerabilities as one of the most common ways attackers gain initial access to a network — not exotic zero-day exploits, but gaps that a routine update would have closed. A written maintenance policy closes that gap by making updates a scheduled task with a name attached to it, rather than a hope.
Step 1: Assign Ownership
Every device and every piece of software needs exactly one person (or one managed IT provider) responsible for confirming it’s current. For a five-person office, that might be the office manager checking a simple list once a month. For a larger practice, it might be split between an internal point of contact and an outsourced IT partner.
What matters is that the responsibility is explicit and written down — not implied. If ownership is unclear, write it into each employee’s role, or bring in a managed IT services partner who takes on that responsibility as part of ongoing support.
Step 2: Inventory What Actually Needs Updating
Most businesses think first of laptops and desktops. A complete inventory covers more ground than that, and this is where the policy earns its keep. Depending on your industry, your update list likely includes:
- Operating systems on every laptop, desktop, and server
- Network hardware — routers, firewalls, and Wi-Fi access points
- Mobile devices that touch business email or client data
- Line-of-business software — the applications your team actually works in every day
That last category is the one businesses most often miss, and it deserves special attention. A medical office running electronic health records (EHR) software, a law firm running case-management software, an accounting firm running tax or bookkeeping platforms, or a construction company running estimating or project-management software — all of these applications need their own update cycle, separate from the operating system. IT teams and generalist providers frequently patch Windows diligently while the specialized software your business actually depends on goes untouched for months, simply because it isn’t part of the standard update routine.
Callout Tip: Make a single list — even a simple spreadsheet — of every device and every piece of software your business relies on, along with who’s responsible for updating each one. If something isn’t on the list, it won’t get checked.
Step 3: Set a Realistic Cadence
Not everything needs to be checked with the same frequency. A workable, low-effort cadence for most small businesses looks like this:
- Weekly: Confirm operating system updates have installed on all workstations (many can be set to install automatically overnight).
- Monthly: Check line-of-business software, mobile devices, and any equipment that doesn’t auto-update.
- Quarterly: Review network hardware firmware and confirm nothing has quietly reached end-of-life.
Microsoft’s monthly “Patch Tuesday” release schedule is a useful anchor point for the weekly and monthly checks, since it gives your team a predictable date to expect and apply operating system and browser updates.
Step 4: Don’t Forget Employee-Owned and Remote Devices
If staff check business email on a personal phone, work from a personal laptop occasionally, or connect from home, those devices need to be part of the policy too — even if your business doesn’t own them. A simple, reasonable standard works well here: any personal device that accesses business email, files, or client data should have automatic updates enabled and a screen lock in place. This doesn’t need to be complicated to be effective; it just needs to be written down and communicated so nobody assumes it’s someone else’s responsibility.
Talk with a local technology partner about practical next steps if you’re not sure how to extend a maintenance policy to a mostly remote or hybrid team without creating extra work for everyone involved.
Step 5: Document It and Review It Twice a Year
A maintenance policy doesn’t need to be a long document. One page is often enough: a list of devices and software, who owns each one, how often it’s checked, and where the record is kept. What matters most is that it’s reviewed — twice a year is a reasonable minimum — so new hires, new devices, and new software get added instead of falling through the cracks.
The National Institute of Standards and Technology (NIST) recommends treating patch and configuration management as an ongoing process rather than a one-time project, precisely because business technology changes constantly. A policy that isn’t revisited becomes outdated as quickly as the software it’s meant to track.
Tools That Make This Easier
A policy is only as reliable as the process behind it, and manually checking every device by hand doesn’t scale well past a handful of computers. Remote monitoring and management (RMM) tools can apply operating system and third-party application updates automatically, flag devices that have fallen behind, and generate a simple report showing what’s current and what isn’t — turning “we think everything is updated” into something you can actually verify.
For line-of-business software that doesn’t support automatic updates, the fallback is a recurring calendar reminder tied to whoever owns that application, checked against the vendor’s release notes or support page. It’s less elegant than automation, but it’s still far more reliable than hoping someone notices.
What This Looks Like in Practice
For Ocean County businesses, the specifics vary by industry, but the shape of the policy stays the same:
- Medical and dental offices: EHR software, imaging systems, and any device touching patient data need documented update ownership — often tied directly to HIPAA security requirements.
- Law firms: Case-management and document-management platforms, plus any remote-access tools used for client work outside the office.
- Accounting firms: Tax preparation and bookkeeping software, especially during and after peak filing season when updates are easy to postpone and easy to forget.
- Construction companies: Estimating, project-management, and field-service apps used on job-site tablets and phones.
- Nonprofits: Donor-management and accounting software, often running on a mix of staff and volunteer-owned devices.
Review your current protections before a preventable issue becomes downtime — a maintenance policy is one of the simplest ways to do that, because it turns “we should probably check on that” into a scheduled, owned task.
Frequently Asked Questions
Do we really need a written policy, or is a verbal understanding enough?
A written policy matters because verbal understandings don’t survive staff turnover, busy weeks, or someone assuming a task was already handled. Even a single page prevents that kind of gap.
How long should it take to build a basic device maintenance policy?
For most small businesses, a first draft — device inventory, ownership, and a check-in schedule — can be put together in an afternoon. Refining it happens over the first few review cycles.
What if we don’t have anyone dedicated to IT?
That’s common for businesses under 100 employees. In that case, the “owner” for updates can be an office manager for day-to-day checks, paired with a managed IT provider who handles the technical patching and provides accountability.
Does line-of-business software really need separate attention from Windows updates?
Yes. Operating system updates and application updates are typically managed through completely different processes, so patching one doesn’t patch the other. Industry-specific software needs its own line in the policy.
Should the maintenance policy cover software subscriptions and cloud tools too?
Cloud-based tools generally update themselves on the vendor’s schedule, but it’s still worth listing them in your inventory along with who manages account access and settings. The update itself may be automatic, but oversight of the tool shouldn’t be.
Building Your Policy
A device maintenance policy isn’t a big project — it’s a short document that turns an assumption into an assignment. Start with the inventory, assign ownership, set a cadence that fits your team’s size, and put a review date on the calendar.
Schedule a cybersecurity or IT consultation with NJCSS to build a device maintenance policy tailored to your business, or visit our Cybersecurity Self-Assessment to see where your current update practices stand.
