PatchAudit keeps small businesses - 1 to 200 or more devices - patched automatically across Windows, macOS, and Linux, and actively protected around the clock if you need it. No IT hire, no MSP retainer. Just a monthly record you can hand straight to your insurer, your board, or your own peace of mind.
If you're running a business with a handful of computers up to a couple of hundred, you almost certainly don't have - and don't need - a full-time IT team. But three things still have to happen: every device needs to stay patched, something needs to be watching for actual threats, and you need to be able to prove both when someone asks.
And someone is asking. Cyber insurance renewals increasingly ask directly whether you have endpoint detection and response (EDR) deployed and a documented patch management process. The Australian Cyber Security Centre's Essential Eight lists patching applications and patching operating systems among its eight baseline strategies. None of that requires an in-house IT department - it requires a system that runs on its own and can show its work.
average self-reported cost of a cyber incident for an Australian medium-sized business (up 55%).
For small business this number is $56,600 (up 14%)
record-breaking vulnerabilities (CVEs) addressed in the July 2026 Microsoft Patch Tuesday alone, with over 400 targeting Windows components. Manual patching can no longer keep up.
surge in Remote Code Execution (RCE) vulnerabilities in 2025. Attackers are exploiting vulnerabilities faster than organizations relying on legacy patching workflows can remediate them.
Patching genuinely is a sequence - enroll, assess, deploy, verify, report - and each step depends on the one before it. Here's the order it runs in, every day.
A lightweight agent is deployed remotely to every device - Windows, Mac, or Linux - in minutes. No site visit, no downtime.
Every enrolled device is scanned around the clock for missing OS and application updates, including known, actively exploited vulnerabilities.
Patches roll out in maintenance windows built around your business hours. Critical, actively-exploited vulnerabilities can go out same-day.
Every patch is confirmed installed and functioning after deployment - not just marked as sent.
A plain-English record each month: what was patched, what's pending and why, and your overall compliance rate.
Operating systems:
Applications:
An honest look at how small-medium businesses (1–250 devices) handle patching and protection today.
| Doing it in-house | PatchAudit Core | PatchAudit Shield | Full-service MSP | |
|---|---|---|---|---|
| Monthly cost | Often $0 in software cost - but real, unbilled staff time | One flat fee per device | One flat fee per device - includes Core | Bundled retainer, usually priced well above patching + protection alone |
| What's covered | Whatever there's time for | OS + application patching, start to finish | Everything in Core, plus 24/7 endpoint monitoring & response | Everything - patching, help desk, procurement, and more |
| Who owns a missed patch or threat | You | Us, under a response SLA (patching) | Us, under a response SLA (patching + threat response) | Your provider, per their contract |
| Insurance / compliance evidence | You assemble it yourself, if you remember to | Monthly patch compliance report | Monthly patch + protection report | Varies by provider |
| Time to get running | As long as it takes internally | Days | Days | Often weeks of onboarding |
| Typical contract | N/A | Month-to-month | Month-to-month | Usually annual |
| Best fit | Businesses with real in-house time to spare | Businesses that just need patching handled | Businesses that also want active threat monitoring - often for insurance or compliance reasons | Businesses that want IT fully outsourced, end to end |
One number for patching alone, one for patching plus 24/7 protection. No quote form required.
Patch management for OS + apps, across Windows, macOS & Linux.
| 1–9 devices | $15.00 / device / mo |
| 10–49 devices | $12.50 / device / mo |
| 50+ devices | $10.00 / device / mo |
Everything in Core, plus 24/7 endpoint detection & response, powered by Malwarebytes ThreatDown.
| 1–9 devices | $30.00 / device / mo |
| 10–49 devices | $25.00 / device / mo |
| 50+ devices | $20.00 / device / mo |
Indicative pricing shown above. Your exact rate is confirmed after a short scope call - device mix (workstation vs. server) and support tier can move the number slightly.
Some patch management platforms give away a generous free tier if you're the one configuring policies, watching dashboards daily, and troubleshooting failures. That's a fine option if someone on your team has the spare hours for it. PatchAudit is for the businesses that don't - we own the whole process end to end and put a response time in writing.
Core keeps every device patched automatically. Shield does that and adds 24/7 endpoint detection and response - a security analyst is watching for active threats around the clock, not just missing updates. Most businesses start with Core and add Shield when insurance, compliance, or peace of mind calls for it.
It can. Many carriers now ask directly whether you have EDR deployed and a documented patch management process - Shield plus Core's monthly reports cover both. We're not brokers and can't guarantee approval or premium, but we'll give you and your broker the documentation to make the case.
Patches are staged and tested before wide rollout, and deployed inside scheduled maintenance windows rather than the moment they're released. If something still needs rolling back, that's on us to resolve - not a ticket you have to chase.
Yes. Devices connect over the internet from anywhere - no VPN or office network required. If a laptop is offline when a patch ships, it's applied the moment it reconnects.
Yes - a server counts as a device like any other endpoint, and is priced the same way.
The service is month-to-month. Cancel with 30 days' notice - no multi-year lock-in.
No - PatchAudit handles patching only. If you already have internal IT or an MSP, we plug in alongside them and take one specific, ongoing task off their plate.
We'll come back with a real quote and a couple of clarifying questions - no obligation.
Book a 15-minute call - we'll ask about your device mix and current patching process, and tell you honestly whether PatchAudit is a good fit.
hello@patchaudit.com