Every business owner has heard “keep your computers updated.” Fewer have heard the second half: “but not all at once, and not the minute the update arrives.” Both halves matter. Skipped updates leave doors open for attackers. Rushed updates can take down the very systems they were meant to protect.
This article explains why updates matter, why speed alone is the wrong goal, what Microsoft’s newer “hotpatch” updates change, and how a managed patching process gets the balance right.
Why updates matter
Microsoft publishes its main Windows security updates on the second Tuesday of each month, often called “Patch Tuesday,” according to its update release cycle documentation. When an urgent problem cannot wait, it issues “out-of-band” updates in between.
Each monthly release fixes security weaknesses (vulnerabilities) that attackers could use to get into a system. Once a fix is published, the weakness becomes public knowledge, and unpatched machines become easier targets. Updates also fix bugs that cause crashes and slowdowns, and they keep Windows compatible with the software and devices you rely on.
Microsoft notes that monthly updates are cumulative: each one includes all the fixes that came before. Skipping a month does not save work; it just leaves the machine exposed for longer.
Why “install immediately” is not the answer
Updates are software, and software sometimes has mistakes. Occasionally a patch conflicts with a particular application, printer driver or hardware model. Now and then Microsoft revises or pulls an update after release, or follows it with a fix. Microsoft’s own Windows 11 release information lists six out-of-band updates for version 25H2 between January and mid-September 2026. Microsoft reserves those for issues that cannot wait, whether an urgent vulnerability or a quality problem affecting many devices. If every PC and server in your office installs a new update on day one, a bad patch hits everything at once.
Servers deserve extra care. A workstation that misbehaves after an update affects one person. A file server, database server or phone system that fails to restart affects everyone.
A real-world example: July 19, 2024
The clearest recent illustration of this risk was not a Windows update at all. On July 19, 2024, the security vendor CrowdStrike released a routine content update for its Falcon sensor on Windows. According to CrowdStrike’s own incident summary, a defect in that update caused affected Windows computers to crash. The update was pulled about 80 minutes later, but machines that had already received it needed hands-on recovery. CrowdStrike states it was not a cyberattack.
Microsoft estimated that about 8.5 million Windows devices were affected, which it described as less than one percent of all Windows machines. Even so, the disruption was felt around the world, because so many of those machines ran critical operations.
The lesson is not about one vendor. Any fast, broad rollout of any update carries this kind of risk. In its published response, CrowdStrike committed to staged (“canary”) deployments that start small and grow, and to giving customers more control over when updates arrive. Those are the same principles a well-run patching process applies to Windows updates.
What hotpatching changes, and what it does not
A “hotpatch” is a security update that takes effect without restarting the computer. According to Microsoft’s hotpatch documentation, it works on a quarterly rhythm: a normal update that needs a restart in January, April, July and October, then restart-free security updates in the two months after each. It is available for Windows 11 version 24H2 or later on devices with qualifying Microsoft licenses and cloud management. Microsoft announced that from the May 2026 security update, hotpatching is on by default for eligible devices managed through its Windows Autopatch service, unless an organization’s own policies say otherwise. On servers, Microsoft says hotpatching for Windows Server 2025 is now available at no extra cost for machines connected to its Azure Arc management service.
This is good news: fewer restarts means fewer interruptions and less time running unpatched code. But hotpatching changes how an update installs, not whether it is safe for your systems. A faulty patch applied without a restart is still faulty. So our position has not changed: hotpatching is a welcome tool inside a tested process, not a replacement for one.
How managed patching works
At FTI, our approach is simple to describe: automate updates, hold new patches briefly, test them, and deploy selectively per system. In practice, that looks like this:
- Automate. Our Kaseya platform tracks which updates each machine needs and installs them on schedule. No one has to remember, and nothing gets skipped because someone was busy.
- Hold briefly. New patches wait a short period before going out broadly. That gives time for any widespread problems to surface and for Microsoft to publish fixes or known-issue notes.
- Test. Updates go first to a small group of systems. We watch for problems with common business software and hardware before approving wider rollout.
- Deploy selectively. Workstations, servers and specialized machines get different schedules. A critical server might be patched during a planned maintenance window with a backup taken first, while ordinary workstations update overnight.
- Verify. After deployment, we confirm that updates installed and machines restarted cleanly. Anything that failed gets followed up.
When a vulnerability is being actively exploited, the hold shortens. Timely does not mean slow; it means deliberate.
What you can do
- Do not turn updates off. If an update caused trouble once, the fix is a better process, not no updates.
- Let PCs restart. Even with hotpatching, many updates only finish on restart. Logging out and restarting regularly helps; see why logging out at the end of the day matters.
- Keep good backups. A tested backup turns a bad update from a crisis into an inconvenience.
- Retire unsupported systems. A PC that no longer receives updates cannot be patched at all. If you still have Windows 10 machines, read still on Windows 10?
How FTI helps
Patch management is part of our managed IT service. We handle the monitoring, testing, scheduling and follow-up, and we pair it with on-site and cloud backup so there is a recovery path if something goes wrong. Our AI-assisted operations watch update results, alerts and help desk tickets together, so a pattern such as the same application failing on several PCs after a patch reaches an engineer quickly. People decide what to hold, roll back or release. Our 24/7 help desk is there if an update ever causes a problem at your desk.

