Patch & Vulnerability Prioritisation Worksheet

Use this worksheet monthly to prioritise updates, track exceptions, and create evidence that patching is being managed—not guessed. Start with critical systems, internet-facing services, remote access tools, finance/admin devices, backups, and identity platforms.

Part A: Asset and Exposure Register

Asset / Platform Owner Type Internet-facing? Business Criticality Current Patch Status Notes
Firewall / VPNNetworkYes/NoHigh
Microsoft 365 / Google WorkspaceSaaS / IdentityYesHigh
Finance/Admin DevicesEndpointNoHigh
Backup PlatformRecoveryYes/NoHigh
Line-of-business AppApplicationYes/NoMedium/High

Part B: Prioritisation Matrix

Item Exploitability Exposure Business Impact Change Risk Priority Target Date
Low/Med/HighLow/Med/HighLow/Med/HighLow/Med/HighP1/P2/P3
Low/Med/HighLow/Med/HighLow/Med/HighLow/Med/HighP1/P2/P3
Low/Med/HighLow/Med/HighLow/Med/HighLow/Med/HighP1/P2/P3

Part C: Monthly Patch Review

Metric This Month Last Month Trend Action
Endpoint patch coverageImproving / Stable / Worse
Server patch coverageImproving / Stable / Worse
High-risk unresolved itemsImproving / Stable / Worse
Repeated patch failuresImproving / Stable / Worse
Open exceptionsImproving / Stable / Worse

Part D: Exception Register

System / App Reason for Exception Risk Accepted By Compensating Control Review Date Status
Open / Closed
Open / Closed

Part E: This Month’s Actions

Tip: Prioritise internet-facing systems and privileged-user devices before routine low-risk updates. Keep evidence short, readable, and decision-focused.

👉 Book your free consultation today
📧 hello@virtusgroup.biz
🌐 virtusgroup.co.nz
📞 0800 847 887 (VIRTUS)