- Job title
- Finance Manager
- Organization type
- early-stage startup
- Joined
- Nov 2023
- Message
- 138
We are a 15-person hybrid design and consulting agency based in London. Everyone on the team uses a laptop; half the employees come into the office two days a week, while the rest are fully remote. We don't have a dedicated IT department, so I handle the IT tasks alongside my project manager role.
Right now, I handle security patches entirely manually. Every two to three weeks, I post a reminder in the company chat, and whenever I get the chance, I physically grab the machines one by one to check OS updates and patches for third-party software like PDF readers and browsers. This takes about 7-8 hours of my time each month, and employees usually put off the updates anyway. Last week, we had a minor scare over a vulnerability in an unpatched document viewer. At this scale, is adopting a centralized patch and vulnerability remediation tool running £4 to £7 per device a month really worth the cost and setup headache?