All client systems monitored 24/7
Sheffield, UK  //  Est. 2006
01433 377 977

Patch Tuesday: Why We Ask You to Leave PCs On

Patch Tuesday: Why We Ask You to Leave PCs On

It is that time of the month again. Windows updates are released worldwide on the second Tuesday of every month, known in the trade as Patch Tuesday, and today is one. This is the day we ask every practice to leave their machines switched on overnight, and here is exactly why that small favour matters so much.

What Patch Tuesday actually is

Microsoft bundles up its security fixes and releases them on a fixed monthly schedule, on the second Tuesday. Every Windows PC and server on the planet, including yours, then downloads and installs them. Most of those fixes close security holes that are already known to attackers, which is precisely why the schedule is so predictable and so important.

A machine that is switched off overnight cannot download or install anything. It will try to catch up later, often at the least convenient moment, which is how you end up with a surgery PC deciding to install updates at half past eight on a Monday morning with a patient in the chair.

What we ask you to do

Two things, and neither costs you anything:

  1. Leave machines switched on overnight on Patch Tuesday. You can lock the screen and turn the monitors off, that is fine. Just leave the computers themselves running.
  2. Ideally do the same on the Wednesday evening too. That second night mops up any stragglers: machines that were busy, asleep, or halfway through when everyone left.

On our side, we start early on these mornings. If an update has caused a problem somewhere, we would much rather find it at seven o'clock and fix it before your first patient arrives than hear about it at nine. That early start is a deliberate part of how we handle patching, alongside the monitoring we run across practice networks.

But sometimes updates cause problems

They do, occasionally. We are not going to pretend otherwise, and anyone who tells you patching is completely risk-free has not been doing this very long. Now and then an update upsets a printer driver, a scanner, or a piece of practice software.

Here is the thing though: those problems are visible, understandable, and fixable. We deal with them, usually the same morning. The alternative risk, an unpatched machine sitting on your network with a known security hole in it, is invisible right up until the moment it is a catastrophe. One is an inconvenience. The other can be the end of a very bad week.

So our position is straightforward, and it has not changed in twenty years: for small dental networks it is far better to take the updates than to defer them. We wrote about the reasoning behind that in more detail in Windows updates, automatic or manual?, and we still stand behind every word.

You also cannot simply opt out. Turning Windows updates off is very unwise, and we would strongly advise against it. Deferring them indefinitely is just the slow-motion version of the same decision.

Patching may matter more than your antivirus

That sounds like a strange thing for a company that sells security software to say, so let me explain it.

Antivirus and EDR or MDR tooling are there to catch things that get in. Patching stops a whole category of attacks from having a way in at all. Most of the big, ugly, headline-making outbreaks over the years have spread through vulnerabilities that had already been patched, sometimes months earlier, on machines where nobody had applied the update.

You want both, obviously. But if you forced me to pick just one thing to get right on a practice network, I would pick "everything is patched and up to date" over any single security product. It is the cheapest, most boring and most effective control you have. It is also, incidentally, a basic expectation of Cyber Essentials and of any sensible view of your data protection duties.

We know leaving machines on is a nuisance

We genuinely do understand why practices push back on this, and the reasons are all reasonable ones:

  • Electricity costs money. True, though a modern idle PC uses very little, and this is one or two nights a month, not every night.
  • Fire safety worries. A real concern, and worth taking seriously. If your fire risk assessment or your insurer says everything goes off, that decision belongs to you, not to us. Tell us and we will work around it.
  • Isolated surgeries and set closing-down routines. Plenty of practices have a proper end of day process, and the person doing it should not have to remember which nights are different.

If any of those apply, the answer is not to skip patching. Talk to us and we will find another way: updating during quieter clinical periods, catching specific machines during the working day, or handling particular surgeries differently. What we cannot do is patch a machine that is never on when the patches arrive.

The simplest version, for most practices, is a note on the staff room wall: on the second Tuesday and Wednesday of the month, screens off, computers on.

The takeaway

Patch Tuesday is one of the few completely predictable things in IT security. The updates are coming whether we plan for them or not, so we may as well take them on our terms: overnight, when nobody is working, with us watching the next morning.

Leave the machines on tonight. That is the whole ask.

If you are not sure whether your practice machines are actually patched and up to date, or you have a surgery that always seems to miss out, get in touch and we will check. It is exactly the sort of unglamorous detail that proper IT support should be quietly getting right for you every single month.

Book your free IT health check.

We'll examine your network, tell you exactly where you stand, and what we'd fix. No commitment, no sales patter.

WhatsApp us any time on 01433 377 977or text 07488 890826