Virtual Patching
Shield vulnerable applications with WAF or IPS rules while the underlying patch is being prepared and tested.

Shield vulnerable systems while the permanent fix is planned
Sometimes a critical system cannot be patched immediately - a legacy application, a supplier release cycle, a change freeze. Virtual patching wraps protective controls around the system so exploitation is blocked while the real fix is scheduled safely.
- Reduces exposure during unavoidable patching delays
- Protects legacy or business-critical systems that cannot be touched
- Buys you time to remediate without rushing changes
- Vulnerable systems tracked with a compensating control
- Temporary protections documented and time-bound
- A permanent fix is still on the roadmap
What actually happens when a critical system cannot be patched immediately?
Ask us to review options for shielding vulnerable systems.
Understanding virtual patching
Sometimes you can't patch immediately - a critical line-of-business app needs vendor sign-off, a server has a tight maintenance window, or the fix breaks something else. Virtual patching uses web application firewalls and IPS rules to block the exploit path at the network or application edge while the real patch is on its way. It buys time without leaving you exposed.
- Cyber Essentials & Cyber Essentials Plus
- ISO 27001:2022 Annex A controls
- NCSC 10 Steps to Cyber Security
- CIS Critical Security Controls v8
What we deploy and run
The concrete controls Telappliant configures, manages and reports on.

Virtual Patching as run by a UK SOC and engineering team.
WAF rules tuned to your applications, not generic templates.
IPS signatures on the perimeter firewall for high-CVSS network vulnerabilities.
Cloudflare or vendor WAF deployment for public-facing sites.
Rapid rule deployment when a new critical CVE is published.
Logging and alerting on blocked exploit attempts.
Decommission of the virtual patch once the real patch is live.
Why Telappliant
What you get with us that you don't get with the alternatives.
Delivered by a UK SOC and engineering team - no offshored ticketing.
Vendor-agnostic. We pick the right tool for your estate, then run it for you.
Mapped to Cyber Essentials, ISO 27001 and the NCSC 10 Steps from day one.
Fixed monthly price - no surprise hourly bills when something goes wrong.
The outcomes for your business
What changes for your team, your auditors and your insurer.
Close zero-day and N-day windows that would otherwise leave you exposed.
Keep critical business apps online while patching is scheduled.
Reduce the blast radius of any one unpatched system.
Demonstrate active risk treatment to auditors and insurers.
Measured outcomes, not promises
3000+ UK organisations served and 100000+ end users supported.
< 60 minute average response on security incidents.
4000+ tickets resolved every month with measurable first-time-fix rates.
Vendor-fluent, not vendor-locked
We pick the right tool for your estate, then run it for you.
Trademarks are the property of their respective owners. We have no affiliation unless stated on our partners page.
Use cases
How this capability fits at different scales.
Protect a public-facing portal with managed WAF rules from day one.
Mitigate critical CVEs across regional offices while patching is staged.
Bridge change-control windows on regulated apps without sitting unpatched.
How this applies to organisations like yours
Recent situations we've worked through with UK businesses - find the one closest to yours.
Situation. SCADA and legacy Windows machines can't be patched without vendor sign-off that takes months.
Outcome. IPS rules virtually patch the exposed CVEs at the network layer until the vendor approves the real fix.
Situation. EPOS terminals running an end-of-life OS the supplier refuses to update.
Outcome. Virtual patching plus network segmentation contains the risk and satisfies the PCI assessor's compensating control.
Situation. Project management server can't be taken down during the build phase for a Microsoft patch.
Outcome. WAF and IPS shield the known CVE for 30 days until the planned change window.
Situation. Medical imaging workstation tied to FDA-approved software that breaks if patched.
Outcome. Virtual patches at the firewall and host level keep the device usable and compliant.
Common questions
Related fundamentals & services
Microsoft 365 Security Hardening
Most SMEs already pay for the controls that cover virtual patching. We help you turn Microsoft 365 Business Premium into a real security baseline - the front door into the wider Cyber Fundamentals portfolio.
Explore Microsoft 365 hardeningTalk to us about virtual patching
A 30-minute call to scope what good looks like in your estate.
Talk to a UK technology partner who's done this for 20 years
Book a practical, no-pressure consultation. We'll review your current setup, show where AI communications, cloud telephony or managed IT could improve customer experience and reduce admin - and tell you straight if you don't need us.
- UK-based people, real account management
- Honest recommendations - even if it's not us
- Practical AI where it adds value, not hype
