---
title: "Patching: Payment Data Security Essential for SMBs"
description: When businesses don’t apply patches from vendors, they open themselves up to attack.
image: https://blog.pcisecuritystandards.org/hubfs/2017-Blog/smb-patching.jpg
---

[< Return to Blog Home](https://blog.pcisecuritystandards.org) [Print](https://blog.pcisecuritystandards.org/patching-payment-data-security-essential-for-smbs#)

# [Patching: Payment Data Security Essential for SMBs](https://blog.pcisecuritystandards.org/patching-payment-data-security-essential-for-smbs)

 Posted by [Laura K. Gray](https://blog.pcisecuritystandards.org/author/laura-k-gray) on 18 Oct, 2017 in [Small Business](https://blog.pcisecuritystandards.org/topic/small-business) and [Patching](https://blog.pcisecuritystandards.org/topic/patching) and [QIR](https://blog.pcisecuritystandards.org/topic/qir) and [Small Merchant Resources](https://blog.pcisecuritystandards.org/topic/small-merchant-resources) and [Cyber Security Awareness Month](https://blog.pcisecuritystandards.org/topic/cyber-security-awareness-month)

![smb-patching.jpg](https://blog.pcisecuritystandards.org/hs-fs/hubfs/2017-Blog/smb-patching.jpg?width=800&name=smb-patching.jpg "smb-patching.jpg")

<https://www.linkedin.com/shareArticle?mini=true&url=https://blog.pcisecuritystandards.org/patching-payment-data-security-essential-for-smbs>

<https://www.facebook.com/share.php?u=https://blog.pcisecuritystandards.org/patching-payment-data-security-essential-for-smbs>

<https://twitter.com/intent/tweet?original_referer=https://blog.pcisecuritystandards.org/patching-payment-data-security-essential-for-smbs&url=https://blog.pcisecuritystandards.org/patching-payment-data-security-essential-for-smbs&source=tweetbutton&text=Patching:%20Payment%20Data%20Security%20Essential%20for%20SMBs> 

[mailto:?subject=Check%20out%20this%20article&body=https://blog.pcisecuritystandards.org/patching-payment-data-security-essential-for-smbs](mailto:?subject=Check%20out%20this%20article&body=https://blog.pcisecuritystandards.org/patching-payment-data-security-essential-for-smbs)

When businesses don’t apply software patches from vendors, they open themselves up to attacks, which can lead to devastating data breaches.**

Often, software has flaws or mistakes made by programmers when they wrote the code. Hackers exploit these vulnerabilities to break into computers and systems and steal payment data.

Vendors regularly issue updates known as patches to fix software vulnerabilities. Timely application of these software patches is a payment data security essential for businesses. In order to apply patches quickly, it is critical to know how software is updated with patches and who is responsible for updating it.

To minimize the risk of being breached, businesses should find out which vendors send them patches, talk with them to make sure they receive patches, and apply patches to their systems as soon as they receive them.

The PCI SSC **[Questions to Ask Your Vendors](https://www.pcisecuritystandards.org/pdfs/Small_Merchant_Questions_to_Ask_Your_Vendors.pdf)** resource can help merchants with identifying which vendors send them patches. Vulnerability scanning tools provided by PCI **[Approved Scanning Vendors](https://www.pcisecuritystandards.org/assessors_and_solutions/approved_scanning_vendors)** can also help businesses automatically search their networks to find vulnerabilities and report when patches need to be applied. Additionally, merchants can refer to the PCI **[Qualified Integrators and Resellers list](https://www.pcisecuritystandards.org/assessors_and_solutions/qualified_integrators_and_resellers)** for companies and individuals that have been trained by PCI SSC on patching and other payment data security essentials.

[![SMB Payment Protection Resources](https://no-cache.hubspot.com/cta/default/281302/051d7996-83b7-4951-b7a7-8a5cd046427f.png)](https://cta-redirect.hubspot.com/cta/redirect/281302/051d7996-83b7-4951-b7a7-8a5cd046427f)

[![More on patching](https://no-cache.hubspot.com/cta/default/281302/6cab603a-1726-47eb-bbc6-c417a9ec2840.png)](https://cta-redirect.hubspot.com/cta/redirect/281302/6cab603a-1726-47eb-bbc6-c417a9ec2840)

### LIKE WHAT YOU READ?

Subscribe to the PCI Perspectives blog to receive insights, information and practical resources to help your organization protect payment data.

[Subscribe Here](https://training.pcisecuritystandards.org/subscribe-to-pci-perspectives-blog)

![Laura K. Gray](https://blog.pcisecuritystandards.org/hubfs/Headshots/laura-gray.jpg)

[ Laura K. Gray ](https://blog.pcisecuritystandards.org/author/laura-k-gray)

[Twitter ](https://www.twitter.com/pcissc) [Email](mailto:blog@pcisecuritystandards.org) [Website](http://www.pcisecuritystandards.org)

 The PCI Security Standards Council (PCI SSC) is a global forum that brings together payments industry stakeholders to develop and drive adoption of data security standards and resources for safe payments worldwide.

[< Return to Blog Home](https://blog.pcisecuritystandards.org) [Print](https://blog.pcisecuritystandards.org/patching-payment-data-security-essential-for-smbs#)