Updates have a perception problem: they arrive when they are not wanted, they interrupt what you are doing, and sometimes they change things that were working fine.
The result is that almost everybody postpones them. “Remind me later” is an answer that, repeated often enough, becomes a decision.
The point this post tries to make concrete is a different one: an update is not a novelty, it is a repair. In most cases it closes a defect that is already known — including to anyone who might exploit it. And that is why the delay before you install it counts for more than it seems.
What this recommendation says
Recommendation R6 establishes that a device’s software should be kept up to date with the latest available version, and that where possible automatic updates should be enabled.
“Software” here means everything, not just the operating system:
- the operating system of phone, tablet and computer;
- the installed applications;
- the browser and its extensions;
- the firmware of routers and connected devices;
- the less-used programs, which are also the most forgotten.
What it is not. It is not a request to install every novelty the same day, and it is not only about new features. The part that counts is the security fixes: changes that close defects already discovered.
Why “automatic”. Not out of laziness, but because the variable deciding the protection is time. An update installed three months later left three months open. Automation removes the repeated decision, which is where the behaviour gives way.
Scope. Every personal, family or professional device that connects to a network.
Why it matters
The mechanism is less intuitive than it looks, and it is worth seeing in full.
When a defect that can be exploited is discovered in a program, whoever makes it prepares a fix and distributes it. From that moment the fix is public — and its existence reveals the defect to people who did not know about it.
An important thing follows: the period of greatest risk is not before the update, it is immediately after its release, for anyone who has not yet installed it. The defect is known, the solution exists, and unpatched devices are easy to spot.
| Benefit | Why it counts |
|---|---|
| It closes defects already known | After publication, the defect is no longer a secret to anybody |
| It shortens the window of exposure | The time between the fix and its installation is the real risk |
| It protects without requiring attention | Once automated, it works even when you are not thinking about it |
| It covers the weakest link | Often not the operating system, but a forgotten app or extension |
| It keeps the other protections working | Password vaults, encryption and the second factor depend on a healthy system |
There is also an aspect concerning every earlier recommendation: a device with uncorrected defects weakens everything else. Unique passwords, a vault, a second factor and an unlock code all assume the device they run on is trustworthy.
A concrete example
John has a tablet he uses for reading and for bookkeeping. He stopped updating it three years ago: the updates were slow and the tablet worked.
The manufacturer, meanwhile, has stopped distributing fixes for that model. It is not a fault: it is the end of support, and it happens to every device.
The tablet keeps working perfectly. But every defect discovered from that moment on stays open, and the list grows every month.
It is the most insidious scenario, because there is no signal: the device does not slow down, does not warn you, does not change behaviour. It simply stops being repaired.
When to apply it
- When setting up a new device. That is the moment when turning on the automation costs nothing.
- When the notification appears. Postponing once is reasonable; postponing out of habit is the decision that opens the window.
- On the browser, first. It is the most exposed program: it talks every day to sites you do not control.
- On the router and connected devices. They are the ones nobody ever looks at, and they stay on twenty-four hours a day.
- When a device falls out of support. A decision has to be made: limit its use, isolate it, or replace it.
- Before a trip. Better to update at home than on a network you know nothing about.
- After news of a widespread security problem. That is when the race between fix and exploitation is fastest.
How to apply it
- Turn on automatic operating system updates, on phone, tablet and computer. It is the single change with the widest effect.
- Turn on automatic application updates, from the device’s store. Many allow it but it is not always on by default.
- Allow the browser and its extensions to update automatically. The browser is by far the most exposed program.
- Schedule installation at a convenient time — at night, or while the device is charging. It removes the interruption excuse.
- Check the router at least once a year. The firmware update is done from the configuration panel; some recent models do it themselves, but that is worth verifying.
- Do a round of the forgotten devices: old tablets, smart TVs, cameras, network printers, smartwatches. They are as connected as the others.
- Check the support status. If a device no longer receives updates, the decision has to be made: replace it, or limit its use to things that do not matter.
- Make a copy before major updates. Something rarely goes wrong, but when it does the copy is what turns a problem into an inconvenience.
The most frequent objections
“Updates break more than they fix.”
It happens, but rarely, and modern systems have introduced ways to roll back. The honest comparison is between a rare and reversible risk — a problematic update — and a frequent, non-reversible one: a known defect left open for months. A copy of your data made beforehand closes the first one too.
“My device is old but it works perfectly.”
Working and receiving repairs are two different things. A device out of support works exactly as it did the day before support ended: the only change is that, from then on, the defects discovered stay open for good.
“There is nothing important on that device.”
The point is not what it holds, it is that it sits on your network. An unpatched device can be the way in to the others, which do hold something.
“I update when I have time.”
It is the most reasonable intention and the least effective, because the right time never comes. Automation exists for exactly this: it moves the installation to a moment when you are not doing anything.
Common mistakes to avoid
- “Remind me later”, always. A single postponement is reasonable; the habit is the vulnerability.
- Updating only the operating system. Applications, browser and extensions are often the most used way in.
- Forgetting the router. It is always on, it sees all the household traffic, and almost nobody updates it.
- Confusing “it works” with “it is safe”. A device out of support works perfectly well: it simply is not repaired any more.
- Postponing for fear of losing something. The risk exists but is rare; a copy made beforehand covers it.
- Downloading updates from unofficial sources. Updates come from the system or the store, never from a link you received.
- Trusting windows announcing updates while you browse. A real update is not offered by a web page.
- Keeping applications you do not use. Every installed program is one more surface to maintain: if it is not needed, uninstall it.
How this connects to the Cyber Welfare Framework
| Pillar | How it contributes |
|---|---|
| Skills | Knowing how to configure the automation and check a device’s support status |
| Awareness | Understanding that an update is a repair, and that the delay is the risk |
| Secure Behaviour | Not postponing out of habit; including the forgotten devices in the round |
Digital maturity levels.
- FL1 — Basic. Updates get postponed; some devices have not had any for a long time.
- FL2 — Beginner. Automatic updates are on for phone and computer.
- FL3 — Autonomous. They are also on for applications, browser and extensions; the router is checked periodically.
- FL4 — Skilled. You know your devices’ support status and decide accordingly; you make a copy before major updates.
- FL5 — Expert-Guide. You help others put their own devices in order, including the ones nobody looks at.
R6 is one of the recommendations with the best ratio of effort to result: one configuration, and then it protects on its own.
How to check you are applying it correctly
- When did I install the last update on my phone and my computer?
- Does my router still receive updates, and when was the last one?
- Do I have devices connected to the network that I have not updated in more than a year?
Quick checklist
- ☐ Automatic updates on for the operating system of every device
- ☐ Automatic updates on for applications
- ☐ Browser and extensions update themselves
- ☐ The router has been checked in the last twelve months
- ☐ I know which of my devices are still supported
- ☐ I have uninstalled the applications I do not use
- ☐ I take updates only from the system or the official stores
For an overall measure of where you stand, you can take the digital resilience self-assessment.
In short
An update does not add features: in the part that counts, it closes a defect that is already known. And from the moment the fix exists, anyone who has not installed it is more exposed than before, not less.
Turning on the automation is the most effective answer because it removes the repeated decision — which is where the intention gives way to haste. The rest is a periodic round of the devices nobody looks at: routers, old tablets, cameras, printers.
Something to think about. How many devices do you have at home connected to the network — and for how many of them could you say when the last update was?
Explore this recommendation
- Impact of unpatched vulnerabilities — what stays exposed when a fix is not installed
- Consequences of outdated software — the concrete effects, from work to money
- How to manage updates — the full configuration, in order of priority
- Signs a device is no longer supported — how to notice the repairs have stopped
- How security updates work — what actually happens when you install a fix
- Attacks on known vulnerabilities — why the delay is the window
Related resources
Short reads from the Resources section, for anyone who wants to stop on a single aspect:
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



