All professional firms
Why software updates matter more than they used to
· PS ProTech · 2 min read
The update prompt appears, and you click "remind me tomorrow." Everyone does. It's also one of the main ways firms get breached.
What an update is for
Software has flaws. When one is found that could let an attacker in, the maker releases a fix, and that fix is the update. Until you install it, your computer still has the flaw, and now the flaw is public knowledge.
That's the uncomfortable part. Announcing a fix also tells attackers where to look. They study the update, work out what it repaired, and go looking for computers that haven't installed it yet.
Why it's getting worse
Verizon's 2026 breach report found that exploiting unpatched software now accounts for 31% of the ways attackers first get in, a 55% jump on the year before. The same report found the typical time to fully fix a critical flaw had grown to 43 days (Verizon 2026 summary).
Put those together: attackers are moving faster, and organizations are fixing things more slowly. AI helps attackers find and use these flaws at a speed that used to take skilled people weeks.
It isn't only Windows
The operating system is the part most firms do keep current. The gaps are elsewhere.
- Web browsers, which are attacked constantly.
- PDF readers and office software.
- Remote access tools and anything that connects the office to the internet.
- Routers and firewalls, which almost nobody updates.
- Line-of-business software. Tax, accounting and practice management packages.
- Phones and tablets that hold work email.
Software that can't be updated
Every product reaches a point where its maker stops releasing fixes. From then on, each new flaw stays open permanently. Old operating systems and old versions of specialist software are the usual cases.
If you run something like this, it needs replacing or isolating from the rest of your network. Insurers ask about it directly, as we cover in what cyber insurers ask.
What a small firm should do
Take it out of people's hands. Updates that rely on staff clicking "install" won't happen reliably. They should be applied automatically, outside working hours, with someone checking that they succeeded.
Cover everything. Applications as well as the operating system.
Know what you have. You can't update a computer you've forgotten about. Keep an inventory.
Restart. Many updates don't take effect until the computer restarts. A laptop that has only been closed for a month hasn't installed anything.
Get a report. You should be able to see, at any time, which machines are up to date.
This is routine work, and it's a good example of what a firm shouldn't have to think about. We keep every computer updated, including the applications on it, as part of device monitoring and patching, which is in every plan. It's item six on our security checklist.
