· Cyber Resilience · 4 min read
Known. Patched. Managed. 3 Words That Can Significantly Reduce Your Cyber Risk
Cyber security doesn't have to be complicated. Why 3 simple words Known, Patched, and Managed, form the foundation of effective cyber resilience for businesses and charities.

Cyber security is often portrayed as something highly technical - Artificial Intelligence, Zero-day vulnerabilities, Ransomware gangs, Nation state attacks.
Whilst these threats are real, most successful cyber attacks don’t begin with sophisticated hacking. They begin with organisations losing sight of the basics. If there are only 3 words your organisation remembers from this article, make them Known. Patched. Managed.
3 simple words that underpin some of the most effective cyber security advice produced by the National Cyber Security Centre and the UK Government’s Cyber Essentials scheme. Whether you’re a business, charity, or community organisation, getting these 3 things right can dramatically reduce your cyber risk.
Known
You can’t protect what you don’t know exists.
Every organisation accumulates technology, a new laptop here, a cloud application there, a website built years ago, an old administrator account no one remembers creating. Over time these become forgotten assets and forgotten assets often become forgotten vulnerabilities. Ask yourself - Do you know every:
- Laptop and desktop?
- Mobile phone?
- Email account?
- Administrator account?
- Cloud application?
- Website?
- Subdomain?
- Remote access solution?
- Third-party supplier with access to your systems?
- Software package installed across the organisation?
For many organisations, the honest answer is “probably not.” Criminals actively look for forgotten technology because nobody is maintaining it. Unknown systems increase your attack surface without anyone realising.
Practical actions
- Maintain an inventory of devices.
- Record all business software and cloud services.
- Review administrator accounts regularly.
- Remove unused systems.
- Keep ownership records for every critical asset.
Knowing what you own is the first step towards protecting it.
Patched
Criminals don’t always discover new vulnerabilities.
More often, they exploit old ones. Every month software vendors release security updates fixing weaknesses that attackers already know about. The problem isn’t usually that patches don’t exist. It’s that organisations delay installing them. Attackers continuously scan the internet looking for outdated:
- Operating systems
- Firewalls
- VPN appliances
- Microsoft 365 services
- Websites
- WordPress installations
- Plugins
- Network equipment
Many ransomware incidents begin with vulnerabilities that had already been fixed, sometimes months, or even years earlier. Every day an update is delayed is another day the opportunity remains open.
Practical actions
- Enable automatic updates wherever possible.
- Replace unsupported software.
- Prioritise internet-facing systems.
- Update WordPress themes and plugins.
- Schedule regular maintenance windows.
Patch management is one of the simplest and most effective ways to reduce cyber risk.
Managed
Cyber security is never “finished.”
Technology changes. People join. People leave. Suppliers change. Threats evolve. Without ongoing management, today’s secure environment gradually becomes tomorrow’s vulnerability. Good cyber security means continually asking questions.
- Who still has administrator access?
- Are backups actually working?
- Is Multi-Factor Authentication enabled?
- Who can access sensitive information?
- Are suppliers still trusted?
- Have staff received awareness training recently?
Good management isn’t complicated, it’s consistent.
Practical actions
- Review user accounts every month.
- Remove accounts immediately when staff leave.
- Use password managers and strong unique passwords.
- Enable Multi-Factor Authentication.
- Test backups regularly.
- Deliver phishing awareness training.
- Review cyber risks at leadership meetings.
Technical controls work best when people know what to look for, which is why practical cyber awareness training remains an important part of resilience.
Boards and senior leaders can strengthen this oversight through independent cyber resilience advisory support.
Cyber resilience isn’t created through one annual project. It’s created through continual management.
Why These Three Words Matter
Most cyber attacks don’t begin with sophisticated hacking. They begin with ordinary failures.
An old server that nobody remembered, a website plugin that hadn’t been updated, a forgotten administrator account, a reused password, an unsupported operating system.
These aren’t usually technology failures, they’re management failures. Fortunately, they’re also some of the easiest problems to fix.
Small Improvements Create Big Reductions in Risk
Many organisations assume improving cyber security requires expensive technology, often it doesn’t. The NCSC and Cyber Essentials both promote practical controls that are achievable for organisations of every size. You don’t need a dedicated security team, you don’t need a six-figure budget, you simply need consistency.
Imagine the reduction in cyber crime if every organisation ensured their technology was always:
✅ Known
✅ Patched
✅ Managed
Those 3 habits alone would remove a significant proportion of the opportunities criminals rely upon. Cyber resilience isn’t built through expensive products, it’s built through disciplined habits. Know what you own, patch what needs fixing, manage it consistently. 3 words, 1 mindset, a significantly safer organisation.
Need Support?
Whether you’re preparing for Cyber Essentials, reviewing your cyber resilience or looking to improve your organisation’s security culture, White Rock Advisory provides practical, independent cyber risk guidance backed by real-world operational experience.
