# Security updates: why you should install them, and when to do it

URL : https://skillrung.com/en/guides/cybersecurity/security-updates
Topic: Cybersecurity · Updated on 2026-09-11

## In brief

A security update fixes a flaw that attackers already know about. Until it is installed, your device stays open to an automated attack that targets no one in particular. Install it within a few days, switch on automatic installation wherever possible, and do not forget the phone, the router or your business software. A device that no longer receives updates needs replacing.

## What is a security update?

Software is millions of lines written by humans: it contains mistakes. Some of those mistakes open a door: this is called a **security flaw**, or *vulnerability*. A **security update**, sometimes called a *fix* or a *patch*, is the piece of code that closes that door again.

An update is not the same thing as a new version that changes the look or adds features. The two often arrive together, which explains the exercise's poor reputation: people remember the menu that moved, not the flaw that was closed.

## Key points

- A security update closes a door that attackers have already spotted.
- The flaw becomes public the day the patch is released: the delay matters.
- Update the phone, the router, the printer and the business software too.
- Switch on automatic installation wherever it exists.
- An update is never installed from a pop-up window.
- A device with no update available must be replaced or isolated.

## Why do they need installing quickly?

Counter-intuitive, but decisive: **releasing a patch makes the flaw public**. The vendor describes what it is fixing, and that description tells anyone who can read it where the door was and how to open it. From that moment, two races start at once: yours, to install, and the attackers', to exploit the machines not yet patched.

Hence a misconception to discard: "I am too small to interest anyone". These attacks do not choose their victims. Programs scan the Internet continuously, try the flaw on everything that responds, and settle wherever it works. A three-person practice, a village council and a listed multinational are exactly as visible to an automated program.

## What needs updating?

The computer springs to mind. The rest gets forgotten, and it is often the rest that serves as the way in.

- **The operating system** of your computers, phones and tablets, work and personal alike as soon as they access work.
- **The browser and its extensions.** An extension abandoned by its author, or even sold on, is an open door onto everything you browse.
- **Everyday software**: office suite, document reader, video-conferencing tool, email client.
- **Business software**: management, accounting, point of sale, patient records, scheduling. These updates often come through the vendor and sometimes require an intervention.
- **The router and the modem.** Rarely updated, often permanently exposed.
- **The office's connected devices**: network printer, storage server, camera, time clock, sensor, alarm system. They have an operating system, so they have flaws.
- **Your website** and its plugins, if it runs on a publishing tool you administer yourself.

Patches are taken **only** from the source: the update function built into the device or the software, the official app store, or the vendor's official site. Never a link received by message.

## When should you install them without stopping work?

The real obstacle is not security, it is the restart at the wrong moment. It can be worked around.

1. **Switch on automatic installation** for the operating system, the browser and the phones. It is the setting that does the most work for you.
2. **Choose the time window.** Most systems let you set the hours during which they will interrupt nothing: consultations, service, the counter, class.
3. **Book a short, regular slot** for what cannot be automated: business software, router, printer, network storage. Half an hour a month, a fixed day, a named person.
4. **Handle separately the patches flagged as urgent** by the vendor or reported by the authorities: those get installed the same day, even if it means postponing something else.
5. **Actually restart.** Many patches only take effect after a restart. A computer put to sleep every evening for six months has installed nothing.

One precaution for the tools that run the business: back up before a major update of your business software, and avoid touching it the day before a deadline. An update can break an integration: that is an argument for scheduling it, not for avoiding it. The method is described in our guide [Backing up your work data: what, where and how often](/guides/cybersecurite/sauvegarder-ses-donnees-professionnelles).

## How do you recognise a fake update?

It is a classic trap: a window pops up while you browse, announces that your video player or your browser is out of date, and offers a file to download. The file installs malware.

Three markers are enough:

- **A real update does not announce itself from a web page.** It appears in the settings of the system or the software, not in the middle of an article.
- **Urgency and fear are signs of fraud**, not technical signals. A vendor does not write "your device is infected, click immediately".
- **When in doubt, close everything** and go and check for yourself in the device's settings. If an update really exists, you will find it there.

The same reflex applies to messages announcing an update to install urgently: you do not click, you check at the source. These mechanisms are practised in real situations in the course [Phishing: simulator, wire transfer fraud and deepfakes](/formations/cybersecurite/phishing-avance-simulateur).

## What about when the device no longer receives updates?

Every piece of hardware and software has an **end of support**: a date after which the vendor fixes nothing more. The device keeps working, which makes the situation deceptive. It does not become faulty: it becomes permanently vulnerable, and every flaw discovered afterwards will stay open.

Three ways out, in this order of preference:

1. **Replace or migrate** to a version that is still supported. It is the only complete answer.
2. **Isolate**, if the device is indispensable and cannot be replaced in the short term: take it off the Internet, put it on a separate network, restrict what it can reach. It is a stopgap, not a solution.
3. **Document** the decision: which device, what deadline, what budget, what replacement date. Written down, the subject comes back on the agenda; spoken, it disappears.

Check the end-of-support dates of your systems, phones and network equipment once a year. It is a predictable budget line, which is better than an emergency replacement after an incident.

## Who takes care of it, when there is no IT person?

In a small organisation, a task with no name attached gets done by nobody. A few written lines are enough: who checks the updates, on which day, on which devices, and who to call when something breaks. That list also serves as an inventory: it often reveals a storage server or a printer that nobody was tracking any more.

When a contractor manages your IT, the question to put to them in writing is simple: *which equipment do you update, how often, and how do you show me?* An IT support contract does not always cover the router, the phones or the business software.

## What it changes depending on your job

- **In healthcare**, patient record software and network-connected equipment are updated with the vendor, within an announced window. For a [medical secretary](/metiers/sante/secretaire-medicale), the right reflex is to know that window and to schedule a backup alongside it, rather than postponing indefinitely.
- **In a town hall**, staff workstations, network equipment and civil registry software often fall to a shared inter-municipal IT service or a contractor. A [town clerk](/metiers/collectivites-elus/secretaire-de-mairie) is well advised to have the covered scope in writing, because devices bought outside the contract almost never appear in it.
- **On building sites and in workshops**, the phone is the main tool and the most forgotten one. For a [skilled tradesperson](/metiers/industrie-btp-artisanat/artisan), switching on automatic updates on the phone is the most cost-effective step on the list.
- **In a very small business**, the question arises at purchase time: a [small business owner](/metiers/tpe-independants/dirigeant-tpe) gains by choosing equipment whose support period is announced, rather than the cheapest at the time of the invoice.

## Where to start

Take ten minutes today: switch on automatic updates on your computer and your phone, then restart them. Then take thirty minutes this week to list the devices nobody updates (router, printer, network storage, business software) and set the day of the month when someone will take care of it.

The other habits that close the most doors, unique passwords, a second factor and offline backups, are covered with cases from your own job in the course [Cybersecurity essentials: protecting your job](/formations/cybersecurite/fondamentaux-cybersecurite).

## Frequently asked questions

### Can you postpone a security update without risk?

A few hours, yes, long enough to finish a task. Several weeks, no: releasing the patch reveals that the flaw exists, and automated programs then test it on every reachable device. Postpone at most until your weekly slot, and deal with patches flagged as urgent the same day.

### Do the router and the printer need updating?

Yes. A modem, a router, a network printer or a storage server run internal software that contains flaws, and they stay switched on permanently. These devices do not always update themselves: check once a quarter in their administration interface, and change the factory password if it is still in place.

### How do you recognise a fake update alert?

A legitimate update never announces itself through a pop-up window while you browse, nor through a message asking you to download a file urgently. Close the window and check for yourself in the settings of the device or the software. If an update really exists, it is there, and it installs from there.

### What should you do with a device that no longer receives updates?

Replace it or migrate to a version that is still supported: it is the only complete answer, because flaws discovered after the end of support will never be fixed. If the device remains indispensable, isolate it from the network and the Internet in the meantime, and put its replacement in the budget with a date, not just an intention.

### Can an update break my business software?

It happens, particularly when a piece of software depends on a specific version of the operating system. The answer is not to stop updating, but to schedule: back up beforehand, avoid the day before a deadline, and ask your vendor which versions it supports. Software that forbids any update of the operating system is a risk to be dealt with.

## Sources

- Pourquoi et comment bien gérer ses mises à jour ? : Cybermalveillance.gouv.fr, 2022-03-22, https://www.cybermalveillance.gouv.fr/tous-nos-contenus/bonnes-pratiques/mises-a-jour
- Les 10 mesures essentielles pour assurer votre cybersécurité : Cybermalveillance.gouv.fr, 2026-05-07, https://www.cybermalveillance.gouv.fr/tous-nos-contenus/bonnes-pratiques/10-mesures-essentielles-assurer-securite-numerique
- Guide des bonnes pratiques de l'informatique : ANSSI, 2024-03-01, https://cyber.gouv.fr/publications/guide-des-bonnes-pratiques-de-linformatique
