4. Unpatched systems

Why is updating important?

Computer systems, servers, and applications that are not regularly updated with security patches represent a major security risk to any organisation or individual. Every system contains potential known and unknown vulnerabilities, and manufacturers regularly release security updates (called patches) that correct these known vulnerabilities. Unknown vulnerabilities or "Zero-day" vulnerabilities are security weaknesses in software or some other part of the system that an attacker has discovered, but for which there is no patch yet or is not known to the manufacturer, so attackers can exploit them before the manufacturer can fix them.

The lack of regular updates leaves the system exposed to known security vulnerabilities, making it easier for attackers to exploit them, as they use publicly available information about vulnerabilities and tools to exploit them. One of the most famous examples is the WannaCry ransomware attack, which exploited a vulnerability in the Windows operating system for which a patch had been available more than two months before the attack – but many systems simply had not been updated.

For example, a computer with a Windows operating system that is not regularly updated, especially with security patches that correct discovered vulnerabilities, can be compromised within minutes of connecting to the internet. The same applies to mobile devices, network equipment, CMS platforms (e.g., WordPress), and other components of information systems.

Security alerts about vulnerabilities in various systems can be found at the following sources:

  • National CERT
  • NIST – national (US) vulnerability database (for those who want to know more).
Accessibility

Background Colour Background Colour

Font Face Font Face

Font Size Font Size

1

Text Colour Text Colour

Font Kerning Font Kerning

Image Visibility Image Visibility

Letter Spacing Letter Spacing

0

Line Height Line Height

1.2

Link Highlight Link Highlight