A vulnerability is a defect in a program that can be exploited to do something the program should not allow. As long as nobody knows about it, the risk is theoretical. The moment a fix is published, the situation reverses: the defect becomes public knowledge, and anyone who has not installed the fix is more exposed than before.
It is a counter-intuitive dynamic, and it is the reason this post exists. It does not describe a generic risk: it describes what concretely stays open on an unpatched device, across the three aspects by which the security of any information is measured.
It expands on the recommendation keeping your software up to date.
The factor that decides everything: time
Before the impacts, the variable that governs them.
| Moment | Who knows about the defect | Level of exposure |
|---|---|---|
| Defect not yet discovered | Almost nobody | Low in practice |
| Defect discovered, fix in preparation | Whoever found it | Medium |
| Fix published, not installed | Anyone who reads the publication | The highest of all |
| Fix installed | Irrelevant: the defect is closed | None for that defect |
The third row is the point. Publishing a fix is also a description of the defect: it says where it was and what it allowed. From that moment, unpatched devices are findable and predictable.
It follows that the useful question is not “does my device have vulnerabilities?” — it does, like every device — but “how much time passes between the fix and its installation?”
1. Confidentiality: what becomes readable
Confidentiality is the guarantee that information stays accessible only to those entitled to it.
A practical example
A defect in the browser allows a web page to read data that should stay isolated from the page itself — the contents of other tabs, local files, session information.
What the incident looks like
The sensitive point is that nothing has to be installed: opening a page is enough. And the page can be a legitimate one, if it carries compromised third-party content.
The scale depends on where the defect sits:
- in the browser: browsing data, open sessions, displayed content;
- in the operating system: potentially everything the device holds;
- in a single application: that application’s data, which can still be a great deal;
- in the router: the unprotected traffic of every connected device.
What to watch for
Almost nothing, and that is this scenario’s main characteristic. A defect exploited to read changes nothing and slows nothing down.
What to do
Automatic updates on the browser before anything else: it is the program that every day runs content coming from sources you do not control.
2. Integrity: what can be altered
Integrity is the guarantee that data, and the way the system works, stay as they should be.
A practical example
A defect allows a program to be installed without authorisation being requested, or a protected setting to be changed.
What the incident looks like
Here the impact runs deeper, because it touches the device and not only the data: unwanted software installing itself, a security setting turned off, a certificate added that allows traffic to be observed.
There is a knock-on effect worth isolating: a device compromised at this level weakens every other protection. A password vault, a second factor and data encryption only work if the system hosting them is intact.
What to watch for
- applications that appeared without your involvement;
- changed security settings;
- unusual browser behaviour: different start pages, new extensions;
- authorisation requests you did not start.
What to do
Check the installed applications and extensions periodically. If something does not add up, an update alone is not enough: what was added has to be removed.
3. Availability: when it stops working
Availability is the guarantee of being able to use your own data and tools when you need them.
A practical example
A defect allows a device to be made unusable, or files to be encrypted so they cannot be read.
What the incident looks like
It is the most visible and most brutal impact. It is worth being precise: most of these episodes do not come from sophisticated techniques, but from known and uncorrected defects — often months or years old.
For anyone working with their own devices, the effect is that the work stops. And recovery depends entirely on a copy of the data existing.
What to watch for
- sudden, generalised slowdowns;
- files that no longer open;
- a device restarting on its own or not completing startup.
What to do
Automatic updates, and a copy of your data that is not permanently connected to the device.
| Aspect | What stays exposed | What the scale depends on |
|---|---|---|
| Confidentiality | Data readable with no visible trace | Where the defect sits: browser, system, app, router |
| Integrity | Unauthorised installations and changes | The level of privilege the defect allows |
| Availability | Device or data unusable | Whether a copy exists |
Where the defects that count sit
Not all software weighs the same. Exposure depends on how reachable from outside a program is.
| Component | Exposure | Why |
|---|---|---|
| Browser and extensions | Very high | It runs content from uncontrolled sources every day |
| Operating system | High | A defect here carries the widest privilege |
| Router and network devices | High and neglected | Always on, reachable, almost never updated |
| Messaging and mail apps | High | They receive content from anybody |
| Apps installed but unused | Medium, and invisible | They remain updatable and remain exposed |
| Accessory devices | Medium | Cameras, printers, smart TVs: connected and forgotten |
| Offline software | Low | Exposed only through the files you open |
The most useful rows are the third and the fifth: the router and the apps you do not use are the two points almost nobody considers, and they are also the ones that stay unpatched the longest.
The worst case: a device out of support
It deserves its own section because it is different from all the others.
When a manufacturer stops distributing updates for a model, the device does not break and does not warn you. It keeps working exactly as before.
One thing changes: from that moment, every defect discovered stays open for good. The list never shortens, and it grows with every later discovery.
| Supported device | Device out of support | |
|---|---|---|
| Known defects | They get closed | They stay open |
| Trend over time | The risk fluctuates and falls | The risk always grows |
| Visible signals | Update notifications | None |
| What you can do | Install | Limit its use or replace it |
The row about signals is what makes the scenario insidious: the absence of notifications gets read as “everything is fine”, when it means the opposite.
The effect on the other recommendations
One thing sets this unit apart from the earlier ones: the impacts do not stay confined to the subject of updates.
Recommendations R1–R5 build protections that assume an intact device:
- a password vault protects the store, but on a compromised system the open store is readable;
- a second factor stops whoever has the password, but not whoever controls the device the code arrives on;
- an unlock code protects physical access, not a defect that can be exploited remotely.
Updates are not one protection among others: they are the condition on which the others work. That is why this recommendation, apparently the dullest, is also one of the most structural.
The impact on the people around you
An aspect that sets this unit apart from the ones on passwords: here the starting point is not a personal account, but a device on a shared network.
- At home, computers, phones, tablets, televisions and cameras see the same network. An unpatched device can be used to reach the others.
- In a business, colleagues’ machines and shared archives sit inside the same perimeter.
- Outwards, the data of clients and suppliers held on those systems follows the fate of the system.
A consideration follows that is worth keeping in mind: a network’s level of protection is that of its least updated device, not that of its best maintained one. And the least updated device is nearly always one of those nobody thinks about — the router, the camera, the old tablet in the kitchen.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Awareness | Understanding that publishing the fix increases the exposure of anyone who has not installed it |
| Skills | Recognising where the most exposed components sit, routers and unused apps included |
| Secure Behaviour | Treating the absence of notifications on an old device as a signal, not as reassurance |
Reference level: FL2 — Beginner. This is the level at which updating stops being a nuisance and becomes a choice with a reason.
An impact you do not see: the device used to reach others
It is worth isolating, because it falls into none of the three classic categories and nearly always escapes the assessment.
A device with an uncorrected defect can be exploited not for what it holds, but for what it can do: send messages, generate traffic, serve as a stepping stone towards other systems.
In this scenario the owner suffers none of the three losses: the data stays readable only to them, nothing visible is changed, everything keeps working. The impact falls entirely on third parties.
Two practical considerations follow. The first is that the absence of visible consequences does not prove the device is intact. The second is that updating is not only a self-protective measure: it is also how you avoid becoming, unintentionally, part of somebody else’s problem.
Summary
- The risk is not having vulnerabilities — everyone has them — but the time between the fix and its installation.
- Confidentiality gives way leaving no trace: it is the quietest impact.
- Integrity opens the way to everything else, because it compromises the device and not just the data.
- Availability is the most visible impact, and it depends on a copy existing.
- A device out of support is the worst case precisely because it gives no signals.
One thing to do today. Look at your browser and check that it updates itself. It is the most exposed program you have, and in most cases two clicks are enough.
Related content
- Keeping your software up to date — the recommendation this expands on
- Consequences of outdated software — from technical impacts to concrete effects
- Signs a device is no longer supported — how to notice the repairs have stopped
- How to manage updates — the measures that reduce all three impacts
Related resources
Short reads from the Resources section, for anyone who wants to stop on a single aspect:
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



