The Cybersecurity Course · Episode 5
Read time ~8 min · No prior knowledge

Updates
& patches

No security measure delivers as much for as little effort as this one — and none is so consistently postponed. Every "remind me later" leaves documented, publicly known holes open in your devices. Good news: the entire problem can be automated away in one evening. Here is why it is more urgent than you think, and exactly which checkboxes to find.

Contents
  1. The most important measure — by a margin
  2. The race: zero-days and the patch window
  3. Automate everything — device by device
  4. Windows 10 is done — what to do now
  5. Five objections — and the answers
  6. Sources

The most important measure — by a margin

Every update you postpone is a list of known, documented holes in your device — published openly, readable by anyone. Vulnerabilities are catalogued as CVEs in databases like NIST NVD, and the moment a fix ships, attackers know exactly what it repairs. Tools that scan the whole internet for unpatched systems do the rest.

Industry reports such as Mandiant M-Trends and the Verizon DBIR have in recent years identified exploited vulnerabilities as the initial vector in up to a third to 38% of examined breaches — on par with stolen credentials. The difference: the password problem took a whole episode to solve. This problem is solved with a checkbox: automatic updates on.

The race: zero-days and the patch window

A zero-day is a vulnerability exploited before the vendor has shipped a fix. Google's threat analysis has shown that the time from disclosure to active exploitation has shrunk dramatically — in modern measurements, a majority of new vulnerabilities are exploited within days to a week of becoming known. Meanwhile, patch statistics show roughly half of all systems still unpatched nearly two months after the fix is released.

That's the whole race in one paragraph: the attacker acts in days, the average user in months. Automatic updates move you from the slow group to the fast one — without you doing anything at all.

CISA's list US agency CISA maintains a public catalogue of vulnerabilities proven to be actively exploited — Known Exploited Vulnerabilities. It grows every week. It isn't theory; it's the answer sheet.

Automate everything — device by device

The goal: you should never have to think about updates again. Go through the list once, tick the boxes, done.

  1. Windows: Settings → Windows Update → enable automatic updates and "Get the latest updates as soon as they're available". (Microsoft's guide)
  2. macOS: System Settings → General → Software Update → turn on everything under Automatic updates, especially "Install Security Responses". (Apple's guide)
  3. iPhone/iPad: Settings → General → Software Update → Automatic Updates on, including "Security Responses & System Files".
  4. Android: updates run via Settings → System → Software update, plus Play Store → automatic app updates. (Google's guide)
  5. Your browser: updates itself — but only if you restart it occasionally. If you see "update pending" in the corner: restart now, not next week.
  6. Your router: log in to the admin interface and enable automatic firmware updates if available. If the feature is missing and the router is many years old — more on that in episode 10.
  7. Everything else: apps, NAS boxes, smart gadgets, payment terminals. Rule of thumb: if it has power and a connection, it has updates.

Windows 10 is done — what to do now

Windows 10 reached the end of its support in October 2025. Computers that stay on Windows 10 receive no security updates — every newly discovered vulnerability stays open forever. Such a machine becomes progressively more dangerous to use for banking, email and shopping.

Five objections — and the answers

Next time Updates close the holes — but what catches whatever gets in anyway? Episode 6 untangles malware: viruses, ransomware, spyware and infostealers, and what antivirus protection you actually need (the answer probably costs nothing).

Sources

Want to dig deeper? These are the sources behind this episode.

  1. CISA — Known Exploited Vulnerabilities Catalog — vulnerabilities proven to be actively exploited.
  2. NIST — National Vulnerability Database — the CVE catalogue.
  3. Mandiant/Google — M-Trends — annual report on intrusion vectors.
  4. Google Threat Intelligence — zero-day analyses — time from vulnerability to exploitation.
  5. Verizon — Data Breach Investigations Report — vulnerability exploitation as an intrusion vector.
  6. Microsoft — Windows 10 end of support — what EOL means and the options.
  7. Microsoft — Update Windows — settings guide.
  8. Apple — Keep macOS up to date automatically — settings guide.
  9. Google — Update Android — settings guide.
  10. CERT-SE — cert.se — Swedish alerts when serious vulnerabilities are exploited.
  11. ENISA — Threat Landscape — vulnerability exploitation in the EU threat picture.
Next episode

Episode 6 — Antivirus & malware

Viruses, ransomware, spyware and trojans — and what protection you actually need.