Vulnerability Management: A 6-Step Guide for NZ Businesses

Posted: July 31, 2023Category:

Most successful attacks don’t use zero-days. They use holes that were patched two years ago and never installed on your machines.

Vulnerability management is the boring, unglamorous discipline of keeping the doors locked. It’s 90% of security in a trench-coat — and it’s the single biggest ROI activity most NZ SMBs skip because it doesn’t feel like it does anything.

Here’s the six-step process we run for our LiveSupport clients, updated for how 2026 tools do the work.

Step 1 — Know what you actually have

You can’t patch what you don’t know about. Every device on your network, every operating system version, every piece of software installed. In 2026 this is done automatically by an RMM (remote monitoring & management) tool like NinjaOne — it keeps a live inventory of every laptop, desktop, server, and their OS & app versions.

What “good” looks like: a dashboard that shows you 100% of your fleet, updated hourly, with software inventory per device.

Step 2 — Know what’s vulnerable

The CVE (Common Vulnerabilities & Exposures) database publishes thousands of new vulnerabilities every month. Not all matter to you. The ones that matter are the ones affecting software you actually have installed.

Modern vulnerability scanners (integrated with your RMM) do this match every day. A Windows machine two patches behind on Chrome, a Mac two point releases behind on macOS, a server missing a Microsoft Exchange security update — they all appear on one list.

Step 3 — Prioritise by real risk, not CVSS score

The CVSS (Common Vulnerability Scoring System) score is a starting point, not an answer. A “critical” 9.8 on a machine that’s air-gapped in a locked cabinet is less urgent than a “medium” 6.5 on your CEO’s laptop that they use in cafés.

Real prioritisation weighs: exploitability (is there a public exploit?), exposure (is the device reachable from the internet?), and criticality (what breaks if it’s compromised?).

Step 4 — Patch, quickly & safely

Two ways patching goes wrong: too slow (attackers get in through the known hole) or too fast (a bad patch breaks a business system).

The middle path: automatic patching for low-risk devices (workstations) within 48 hours of a patch release, staged patching for higher-risk devices (servers, LOB systems) with a test group first, and same-day emergency patching when there’s active exploitation.

For our LiveSupport clients we target 95%+ patch compliance across the whole fleet — measured, not estimated.

Step 5 — Verify it actually worked

Patching a machine and re-scanning the machine are different steps. The re-scan is the proof. Without it, “we applied the patch” and “the vulnerability is closed” are two different sentences.

Modern tools re-scan automatically after patch install. Compliance drifts get flagged. Missed patches don’t stay missed.

Step 6 — Report it

Vulnerability management only becomes strategic when leadership can see the trend. Monthly reporting — patch compliance percentage, number of critical vulnerabilities open, days-since-last-restore-test — turns “we’re doing our best” into evidence for the board, the insurer, and the SMB1001 assessor.

How it ties into SMB1001 Gold

Three of the 27 SMB1001 Gold controls are direct vulnerability-management items: automatic patching on every device, managed EDR, and end-of-life OS retirement or isolation. Getting these three right is worth more than any expensive security tool. Read what SMB1001 Gold is.

Where most NZ SMBs are today

In practice we see three tiers:

  • Doing nothing formal — patching happens if the user clicks “restart later” enough times. Most vulnerable, most common in businesses without managed IT.
  • Manual patching — someone in-house or a break-fix provider patches when they remember. Better than nothing; still exposed 60-80% of the time.
  • Managed with reporting — RMM-driven, automatic, measured. Where LiveSupport clients sit — usually 95%+ compliant with monthly evidence.

Not sure where you sit?

The free 2-minute readiness check asks about your patching setup as one of its 13 questions. Take it — you’ll know within two minutes.

Or talk to us about LiveSupport — vulnerability management is included, measured, and reported every month.

Contact us today