Why software updates are the cheapest security fix
Patches close the flaws attackers hunt for. Here is what to keep updated, how to automate it, and what to do when a device stops getting fixes.
An update prompt is easy to postpone, and that delay is exactly what attackers count on. Patches are the fixes vendors ship for flaws in their own products, and installing them is the most effective single step most people can take to protect a phone, laptop or tablet. CISA, the US cyber security agency, states this directly in its guidance on patches and software updates.
What a patch actually is
CISA defines patches as software and operating system updates that address security vulnerabilities in a program or product. Vendors also ship updates for performance bugs and new features, but the security fixes are the ones that close the door an attacker is already looking for. The UK's National Cyber Security Centre makes the same point: patches fix known flaws in products that attackers can use to compromise your devices, and new security features raise the effort needed to break in.
What needs updating
Updating the operating system is only part of the job. NCSC guidance lists the items that matter most:
- Operating system: automatic updates are usually on by default, but the setting can be switched off.
- Web browser and its extensions: browsers are complex and exposed to every site you visit, so they are a favourite target.
- Third-party apps you installed: office apps and document readers in particular, because they open files sent by other people.
- Security software: antivirus updates carry new detection signatures as well as bug fixes.
Make updates happen without thinking
Turn automatic updates on and leave them on. CISA recommends taking advantage of automatic options wherever a vendor offers them, and installing updates as soon as they arrive. NCSC suggests applying updates promptly when notified, ideally within a few days, and allowing the device the conditions it asks for, which may include power, Wi-Fi, free storage or a restart.
Download updates from the vendor itself. CISA warns that attackers have used email messages to send people to sites hosting malicious files disguised as legitimate updates, and advises against updating while connected to untrusted networks such as airports, hotels or coffee shops.
When support ends
Software that has reached end of life stops receiving security fixes, so a flaw found afterwards may never be patched. CISA advises against using unsupported end-of-life software. When replacing a device, NCSC suggests checking how long the manufacturer typically supports its products, because that decides how many years of updates you are buying. More detail sits at cisa.gov and ncsc.gov.uk.
Check occasionally that a device is still updating on its own, since automatic updates can fail quietly. If it can no longer be updated, treat it as a security problem and plan to replace it.