How ThirdPatch Closed The Patching Gap the MSP Industry Overlooked

Photo Courtesy of ThirdPatch

Jeremy Oaks spent years watching operating systems get patched on schedule while everything else on the same endpoint quietly rotted. Browsers, communication tools, and utility software sat exposed for weeks, sometimes months, while the industry’s attention stayed fixed on the operating system layer. That narrow blind spot, invisible to most vendors, became the starting point for ThirdPatch, the platform Oaks built after managing 10,000 endpoints as an RMM administrator.

ThirdPatch has secured a 2026 Global Recognition Award, with judges naming the third-party patch management platform Startup Of The Year for closing a security gap that has persisted across the managed service provider industry for years. The distinction recognizes a company that identified a narrow, overlooked problem and built dedicated infrastructure to solve it, treating third-party patching as a standalone discipline rather than a secondary feature bolted onto broader software. Judges evaluated ThirdPatch alongside a wide field of applicants, and the platform stood out because its design closely matched a documented, persistent industry need.

Researchers at the FIRST.org project predict that published CVEs will approach 59,000 in 2026, with some estimates reaching 70,000 to 100,000 once AI-assisted vulnerability discovery is factored in. A separate analysis of Verizon’s 2025 breach dataset found that only 26 percent of critical vulnerabilities listed in CISA’s Known Exploited Vulnerabilities catalog were fully remediated, down from 38 percent the prior year, while the median time to patch rose from 32 days to 43 days. Those figures describe an environment where operating systems are patched with reasonable consistency, while the browsers, communication tools, and utility software running on the same machines are frequently left exposed for weeks or months.

Building A Discipline Around A Narrow Problem

Oaks built ThirdPatch around a distinction that had largely gone unaddressed in the managed service provider trade: operating system patching had mature tooling, while third-party application patching lacked it. His approach treated that gap as a discipline worth building infrastructure around, rather than a feature to attach to an existing remote monitoring and management tool. The system works with any RMM and integrates with ConnectWise Automate, CIPP, Atera, NinjaOne, JumpCloud, and any other tool that can run PowerShell, so providers are not required to abandon existing infrastructure to close the gap.

That flexibility carries weight because providers frequently switch RMM platforms or operate mixed environments across client accounts, a reality that shapes purchasing decisions across the trade. Oaks drew on his own experience running patch programs across multiple client environments simultaneously, which shaped the platform’s architecture from the outset. “Operating systems get patched because the tooling for that has existed for years, but everything else on the endpoint tends to fall through the cracks,” Oaks said.

“We built ThirdPatch because that gap was the source of most of the exploitable risk we were seeing, not the operating system itself, and closing it required a platform built specifically for that purpose rather than adapted from something broader,” Oaks said. That remark points to the reasoning behind the company’s narrow focus, since Oaks chose to build a dedicated tool rather than expand an existing one. The decision to specialize rather than generalize became the foundation for the rest of the platform’s design.

Automation Designed Around Real-World Exceptions

ThirdPatch’s package-based structure allows managed service providers to nest automation the way interlocking blocks snap together, so an entire stack of client-specific applications and base tools can be deployed or updated with a single command rather than dozens of separate actions. The platform’s library of more than 10,000 available software packages, paired with templates for building custom applications, helps technicians standardize remediation across accounts with widely different needs. Flat-rate pricing removes the per-app and per-endpoint charges that typically make comprehensive third-party update management cost-prohibitive at scale.

Set-it-and-forget-it automation only holds up if it can accommodate exceptions, and Oaks designed the package framework with that tension in mind from the outset rather than as an afterthought added after early adopters reported problems. Custom application support extends that logic further, since any application with silent-install parameters can be packaged and deployed centrally while versioning and reporting remain fully intact throughout the process. This approach reflects Oaks’s own experience with the operational friction that unreliable agents and disconnected portals create for technicians managing accounts at scale.

“Most of the providers we surveyed during development told us the same thing, since they wanted updated programs without an unreliable agent or another portal to log into,” Oaks said. That feedback shaped the Pro version of the platform, which installs with a single PowerShell command and can optionally discover and patch existing applications on a system. The result is a tool built from direct conversations with the technicians who would eventually rely on it every day.

A Problem The Industry Could See But Had Not Solved

“The panel noted that ThirdPatch’s product precisely matched a problem the MSP industry had openly struggled to solve for years,” said Alex Sterling, spokesperson for Global Recognition Awards, adding that the panel’s assessment centered on how directly the platform’s design responded to a documented operational problem. “ThirdPatch didn’t try to be everything to everyone, since it picked the hardest, most overlooked piece of the patching puzzle and built a workable solution around it, and that kind of focus is exactly what this award is meant to recognize,” Sterling said. It is also noted that the recognition places ThirdPatch among a small group of companies whose growth stems less from market timing than from solving a problem their own trade could see clearly but had not yet addressed.

ThirdPatch’s growth reflects a pattern in the managed service provider software market, where large opportunities often sit in the gaps left by general-purpose tools that address only part of a provider’s technical burden. Third-party patching was treated as a secondary concern for years, even as it became one of the largest sources of exploitable risk on managed endpoints across the industry. Oaks built his company around closing that specific gap rather than expanding into unrelated services, a choice that required as much discipline as it did engineering.

The platform’s RMM-neutral, package-based approach gives Oaks room to grow alongside whatever tools providers choose to run, regardless of how the broader RMM market shifts in the years ahead. What began as an observation from inside a single provider’s operations, watching 10,000 endpoints go unpatched in the places that mattered most, has become the basis for a company built to close that exact gap. The award recognizes a specific and durable piece of engineering. Still, the more lasting measure of Oaks’s work may be the discipline he brought to a problem the industry had long known about and rarely addressed head-on.

Tags

Experienced News Reporter with a demonstrated history of working in the broadcast media industry. Skilled in News Writing, Editing, Journalism, Creative Writing, and English.