Updates interrupt work, change familiar interfaces and occasionally introduce problems. That makes it understandable for employees and organizations to approach them carefully.
Caution is different from indefinite delay.
When updates are ignored for months or years, devices can accumulate security weaknesses, compatibility problems and unsupported software that becomes more difficult to correct safely.
The main point
Business updates should be managed, not avoided.
Vendors release updates to address security vulnerabilities, correct defects, improve reliability and maintain compatibility.
The right approach is not necessarily to install every update immediately on every device. It is to know what must be updated, test changes when the risk justifies it, deploy them within an appropriate period and verify that the work succeeded.
Separate routine and urgent updates
Not every update carries the same urgency.
Routine operating-system and application updates can usually follow a defined maintenance schedule.
Other updates may require an accelerated response, including:
- Fixes for vulnerabilities being actively exploited
- Emergency vendor security guidance
- Updates for internet-facing systems
- Remote-access or identity-system fixes
- Critical browser and email updates
- Corrections for severe operational problems
CISA maintains the Known Exploited Vulnerabilities Catalog as an authoritative list of vulnerabilities known to have been exploited. Businesses can use it as one input when deciding which issues deserve faster attention.
Someone should be responsible for reviewing vendor notices and deciding when a change must move outside the ordinary schedule.
Maintain an accurate inventory
Know which systems are in use, including:
- Operating systems
- Business applications
- Web browsers
- Mobile devices
- Network equipment
- Servers and cloud systems
- Security and remote-access tools
Where possible, record the version, owner, vendor, support status and update method.
An organization cannot reliably update technology it does not know it has.
Use a practical update process
Prioritize important systems
Identify systems that are:
- Accessible from the internet
- Used for administrator access
- Responsible for email or identity
- Required for remote work
- Essential to business operations
- Responsible for sensitive information
These systems may require more active monitoring and faster action.
Test when the impact could be significant
Test updates against critical workflows, specialized applications and representative devices.
A small organization may not need a dedicated testing laboratory. It can still begin with a limited group of devices before deploying a major update to everyone.
The goal is to avoid discovering every compatibility problem across the entire organization at once.
Schedule and communicate
Use maintenance windows when updates may require restarts or interrupt service.
Tell employees:
- What will change
- When it will happen
- Whether a restart is required
- What interruption to expect
- How to report a problem
Clear communication reduces postponement and unnecessary support requests.
Protect important data
Confirm that important data and configurations are protected before major upgrades or high-impact changes.
Critical systems should have a documented rollback or recovery plan appropriate to the risk.
Verify completion
After deployment, confirm that:
- The update installed successfully.
- Required devices restarted.
- Services returned.
- Business applications still work.
- Failed or offline devices are identified.
- Exceptions have a follow-up date.
A deployment request is not the same as a completed update.
Track exceptions
Sometimes an update must be delayed because of an application conflict, vendor dependency or operational constraint.
Document:
- The reason for the delay
- The affected systems
- Temporary protections
- The responsible owner
- The next review date
An exception without an owner or review date can easily become permanent.
End of support changes the decision
When a vendor stops supporting a product, ordinary patching is no longer a long-term answer.
The organization may need to:
- Upgrade it
- Replace it
- Isolate it temporarily
- Migrate the related process
- Retire it
Unsupported technology should not remain in normal service simply because it appears to function.
What to avoid
Avoid disabling automatic updates across the organization without replacing them with another managed process.
Do not allow employees to postpone required restarts indefinitely.
Also avoid:
- Updating critical systems without current recovery options
- Ignoring applications because the operating system is current
- Leaving failed updates unresolved
- Treating unsupported products as permanent exceptions
- Assuming a green dashboard includes every device
When to involve IT
Involve IT when updates affect:
- Servers
- Network equipment
- Business-critical applications
- Remote access
- Security tools
- A large group of employees
- Systems that cannot accept current updates
The purpose of update management is not change for its own sake. It is to keep technology supportable, secure and ready for the work the organization expects it to perform.
Need a more consistent approach to updates and device support? Book a consultation.