Updates
& patches
No security measure delivers as much for as little effort as this one — and none is so consistently postponed. Every "remind me later" leaves documented, publicly known holes open in your devices. Good news: the entire problem can be automated away in one evening. Here is why it is more urgent than you think, and exactly which checkboxes to find.
The most important measure — by a margin
Every update you postpone is a list of known, documented holes in your device — published openly, readable by anyone. Vulnerabilities are catalogued as CVEs in databases like NIST NVD, and the moment a fix ships, attackers know exactly what it repairs. Tools that scan the whole internet for unpatched systems do the rest.
Industry reports such as Mandiant M-Trends and the Verizon DBIR have in recent years identified exploited vulnerabilities as the initial vector in up to a third to 38% of examined breaches — on par with stolen credentials. The difference: the password problem took a whole episode to solve. This problem is solved with a checkbox: automatic updates on.
The race: zero-days and the patch window
A zero-day is a vulnerability exploited before the vendor has shipped a fix. Google's threat analysis has shown that the time from disclosure to active exploitation has shrunk dramatically — in modern measurements, a majority of new vulnerabilities are exploited within days to a week of becoming known. Meanwhile, patch statistics show roughly half of all systems still unpatched nearly two months after the fix is released.
That's the whole race in one paragraph: the attacker acts in days, the average user in months. Automatic updates move you from the slow group to the fast one — without you doing anything at all.
Automate everything — device by device
The goal: you should never have to think about updates again. Go through the list once, tick the boxes, done.
- Windows: Settings → Windows Update → enable automatic updates and "Get the latest updates as soon as they're available". (Microsoft's guide)
- macOS: System Settings → General → Software Update → turn on everything under Automatic updates, especially "Install Security Responses". (Apple's guide)
- iPhone/iPad: Settings → General → Software Update → Automatic Updates on, including "Security Responses & System Files".
- Android: updates run via Settings → System → Software update, plus Play Store → automatic app updates. (Google's guide)
- Your browser: updates itself — but only if you restart it occasionally. If you see "update pending" in the corner: restart now, not next week.
- Your router: log in to the admin interface and enable automatic firmware updates if available. If the feature is missing and the router is many years old — more on that in episode 10.
- Everything else: apps, NAS boxes, smart gadgets, payment terminals. Rule of thumb: if it has power and a connection, it has updates.
Windows 10 is done — what to do now
Windows 10 reached the end of its support in October 2025. Computers that stay on Windows 10 receive no security updates — every newly discovered vulnerability stays open forever. Such a machine becomes progressively more dangerous to use for banking, email and shopping.
- Can the machine run Windows 11? Upgrade — it's free and the easy path.
- Doesn't meet the requirements? Microsoft's ESU programme (Extended Security Updates) buys limited time, but it's a band-aid — not a solution.
- Older but healthy hardware? A modern Linux (e.g. Ubuntu or Mint) keeps many "too old" computers living safely for years.
- Whatever you choose: don't use an unsupported computer for anything involving money or logins.
Five objections — and the answers
- "Updates break things." It happens — rarely, and usually fixed within days. Weigh it against the alternative: known security holes standing open for months. For your personal computer, the update wins every time.
- "I don't have time right now." That's why we automate. Devices now update overnight without disturbing you. "Later" has a tendency to mean "never".
- "My device is too old for new versions." Then it's too old to be safe. A device without security updates is a growing hole in your home — replace it or disconnect it (episode 13 covers the IoT variant of this problem).
- "I don't do anything important on it." The episode 1 lesson: your device is valuable as a resource even if its contents aren't. Unpatched devices become botnet members.
- "I'll wait until they've fixed the bugs in the update." For big feature updates, a few days can be reasonable — but security updates always go in immediately. They are the fix.
Sources
Want to dig deeper? These are the sources behind this episode.
- CISA — Known Exploited Vulnerabilities Catalog — vulnerabilities proven to be actively exploited.
- NIST — National Vulnerability Database — the CVE catalogue.
- Mandiant/Google — M-Trends — annual report on intrusion vectors.
- Google Threat Intelligence — zero-day analyses — time from vulnerability to exploitation.
- Verizon — Data Breach Investigations Report — vulnerability exploitation as an intrusion vector.
- Microsoft — Windows 10 end of support — what EOL means and the options.
- Microsoft — Update Windows — settings guide.
- Apple — Keep macOS up to date automatically — settings guide.
- Google — Update Android — settings guide.
- CERT-SE — cert.se — Swedish alerts when serious vulnerabilities are exploited.
- ENISA — Threat Landscape — vulnerability exploitation in the EU threat picture.
Episode 6 — Antivirus & malware
Viruses, ransomware, spyware and trojans — and what protection you actually need.