In this article
  1. Why updates fix security holes
  2. The race after a patch is published
  3. More than security
  4. How to make updating painless
  5. How long devices receive updates
  6. What "end of support" really means
  7. Frequently asked questions

Few messages are dismissed as often as “An update is available.” Yet keeping software current is one of the simplest and most effective things anyone can do to stay safe online.

Key facts

  • 20% of breaches studied in Verizon’s 2025 Data Breach Investigations Report began with attackers exploiting a software flaw.
  • 34% rise in that type of attack compared with the previous year’s report.
  • Credential abuse, such as stolen passwords, remained slightly more common at 22%.
  • Automatic updates remove most of the effort for home users.

Why updates fix security holes

All software contains mistakes. Some mistakes let an attacker run their own code, read data or take control of a device. When developers discover such a flaw, they release a fix, called a patch. Until the patch is installed, the flaw stays open.

The race after a patch is published

Once a fix is public, criminals can study it to understand the weakness and then target people who have not updated. The days after an important update are therefore a period of higher risk, not lower. Some flaws are exploited before any fix exists; these are called zero-day vulnerabilities, and they are one more reason to install fixes as soon as they appear.

The trend is clear in Verizon’s 2025 Data Breach Investigations Report, one of the largest annual studies of real incidents. Exploiting vulnerabilities was the first step in 20 percent of breaches, up 34 percent on the year before, with many attacks aimed at internet-facing equipment such as VPNs and firewalls.

How breaches startedShare of breaches
Credential abuse (stolen or guessed passwords)22%
Exploiting a software vulnerability20%
Top initial routes into organizations. Source: Verizon 2025 Data Breach Investigations Report.

The top route, stolen passwords, is best blocked with two-factor authentication. The second is best blocked by updating.

Why Two-Factor Authentication Matters for Every Account

More than security

  • Updates improve speed, battery life and compatibility with new websites and devices.
  • Older versions eventually stop receiving support at all. After that date, any new flaw stays open forever, so plan to replace devices and software that have reached end of support.

How to make updating painless

  1. Turn on automatic updates for your operating system, browser and main apps.
  2. Restart regularly. Many updates only take effect after a restart.
  3. Update routers and smart devices too. Check the manufacturer’s app or website; these are often forgotten.
  4. Only download updates from official sources. A pop-up on a website saying you must install an update is a common trick; see our guide to recognizing phishing.
  5. Remove apps you no longer use. Fewer programs means fewer things to keep updated.

For businesses: organizations often test updates before rolling them out, to avoid breaking important systems. That is sensible, but critical security fixes, especially for internet-facing equipment, should be prioritized and applied within days, not months.

How long devices receive updates

Every device eventually stops receiving security updates. Knowing the date helps you plan a replacement before you are left unprotected.

ProductUpdate support
Windows 10Free support ended on 14 October 2025; paid or enrolled Extended Security Updates run to October 2026 for home users
Google Pixel 8 and laterSeven years of Android and security updates from release
Samsung Galaxy S24 and later flagshipsSeven years of Android and security updates
Apple iPhoneNo fixed promise; recent models have typically received updates for six years or more
Check the manufacturer’s website for your exact model.

What “end of support” really means

When software reaches end of support, the developer stops releasing fixes. The software keeps working, which is why many people keep using it, but every new flaw discovered after that date stays open permanently. Attackers know this and specifically target old systems.

A simple rule: if a device or program you use for banking, email or work no longer receives security updates, plan to replace or upgrade it. For older phones and laptops that still work well, you can reduce risk by using them only for low-risk tasks.

Frequently asked questions

Should I wait a few days before installing updates?

For most people, no. The risk from attackers exploiting a known flaw is usually greater than the small risk of an update causing a problem. Businesses with critical systems may test first, but should still move quickly.

Are automatic updates safe?

Yes, when they come from the operating system or the app store. Be suspicious of update prompts that appear inside web pages or emails.

What should I do with a device that no longer gets updates?

Replace it if possible, or at least stop using it for banking, email and shopping, and never expose it directly to the internet.

Sources

  1. Verizon: 2025 Data Breach Investigations Report, news release
  2. Verizon: 2025 DBIR full report (PDF)
  3. CISA: Known Exploited Vulnerabilities catalog
  4. UK National Cyber Security Centre: Install the latest software and app updates