Dabish Digital
Security

Five mistakes teams make with software updates

The gap between knowing this and actually doing it is where most teams lose ground. These are the ones we run into repeatedly when we audit software updates.

The cheapest security work is the boring kind done on a schedule. If two people in the business would answer this differently, that gap is the actual problem.

Where it usually goes wrong

  • Treating it as a launch task rather than an ongoing one
  • Assuming someone else already owns it
  • Most breaches exploit a fix that already existed
  • Schedule updates rather than reacting to incidents
  • Never checking whether the fix actually worked

Staging first prevents the update becoming the outage. Getting it slightly wrong is survivable. Ignoring it entirely is not. If two people in the business would answer this differently, that gap is the actual problem.

Where to go from here

The short version

The realistic threat for most small businesses is automated and opportunistic, not targeted. Three things worth confirming about software updates before you move on:

  • Someone can say what the current setup is without going to look
  • Schedule updates rather than reacting to incidents — and you know whether that is true here
  • There is a way to tell whether the last change to this helped

Pick the one that would hurt most if it failed, and start there.