Patch, Backup, Repeat: Why ‘It’s Working Fine’ Isn’t the Same as ‘It’s Protected’

A business can run for months without a single IT problem and still be exposed. Files are saved, email arrives, and the till takes payments. None of that confirms whether last month’s critical security update went on or whether the backup would restore if it were needed tomorrow. Both of those things are built to work without anyone noticing, which is exactly why they’re so easy to overlook. 

Why No News Doesn’t Mean Good News 

Most of daily life runs on a fair assumption. If something were wrong, you’d have noticed by now. Nothing’s crashed, and nobody’s called to complain, so everything must be fine. That holds up for a boiler or a company car. 

IT doesn’t follow the same logic. An unpatched vulnerability in Windows Server, or three-year-old firmware on a firewall, sits there whether or not anyone’s found it yet. A backup job can report success every night for a year without anyone confirming the data inside it restores properly. Both systems are designed to run in the background so nobody has to think about them, which is precisely what makes a silent failure indistinguishable from silent success. Neither one interrupts anyone’s working day. From the outside, a system with no symptoms and a system with no risk look exactly the same. 

According to the government’s Cyber Security Breaches Survey 2025/2026, 43% of UK businesses reported a cyber security breach or attack in the past 12 months, roughly 612,000 businesses. Most of them would have described their systems as working fine the week before. 

What a Working System Can Hide 

A laptop can open Outlook and save straight to SharePoint without a hitch while running three security updates behind and completely unmonitored. Nobody using it would ever know. 

Microsoft releases security fixes on a rolling monthly schedule, and a business can run for months on a machine that’s several updates behind without a single visible symptom. Everything opens, everything saves, everything looks identical to a machine that’s fully patched. The moment a fix goes out, the vulnerability it closes becomes public knowledge too, and anyone scanning for unpatched systems knows exactly what to look for. Only 34% of UK businesses have a policy to apply security updates within 14 days, according to the same survey. 

A backup can run every night, log a clean success message, and still be worthless if nobody’s tried restoring so much as a single folder from it. NCSC’s guidance on ransomware is direct on this point. Organisations should know how to restore from a backup and test that it works on a regular basis. Ransomware often targets connected backups specifically, encrypting or deleting them before it moves on to the rest of the network, which is why NCSC recommends keeping at least one copy offline and separate from the systems it protects. A green tick on a dashboard only confirms the backup job ran. 

These two problems tend to compound each other. A business running an unpatched system with an untested backup has no fallback if that vulnerability gets used against it. That combination is common because few businesses don’t have either fully in hand. 

What Real Protection Involves 

Patch cycles need evidence behind them. Someone should be able to point to a dated report showing which updates went out, when, and to which devices. That record also needs to hold up under scrutiny, whether that’s an insurer asking questions after a claim or an assessor checking Cyber Essentials compliance. 

Restores need testing on a set schedule. That means pulling a file, or ideally a full system image, back from the backup and opening it in the application it belongs to, checking the content is genuinely intact. A quarterly test is a reasonable minimum for most small businesses. Many of the businesses we support around Taunton and Barnstaple had never had this checked before we looked at their setup, and the answer is often no. 

Patch and backup status shouldn’t sit in a dashboard nobody opens. They need reviewing often enough that a problem surfaces in weeks, which is part of how we structure reporting inside our managed IT support. 

Where Cyber Security Compliance Fits In 

Cyber Essentials formalises much of what good patching and backup practice already looks like, and patch management is one of its five technical controls. The scheme’s 14-day rule for critical and high-risk updates reflects how fast a known vulnerability gets exploited once a fix is public. Only 24% of UK businesses currently have technical controls in place across all five Cyber Essentials areas, and patching is one of the areas most often found lacking during assessment. 

Many larger clients and insurers now treat Cyber Essentials as a baseline requirement before they’ll sign a contract or issue a policy, which pushes cyber security compliance well beyond a box-ticking exercise. Evidence of proper patching and backup practice increasingly needs to travel with a business into every tender and every renewal, which is part of why we build every client environment against the same baseline. 

Proof Over Assumption 

A patch that should have gone out three months ago becomes the way in. A backup nobody tested turns out not to restore when it’s needed. Both look identical to normal operation until that point. 

Most of the businesses we see with real exposure have nothing visibly wrong. They’ve just never had a reason to check. 

If you’d like that check, Integy’s free Microsoft 365 assessment benchmarks your setup against recognised standards like CIS and Cyber Essentials and gives you concrete evidence to work from.