Security basics
Why unpatched software is still the easiest way in
All software has bugs, and some of those bugs let an attacker do something they shouldn't: run their own code, or get past a login entirely. When a vendor finds and fixes one, they ship a security update. The moment that update is public, so is a detailed map of exactly what was broken, which means every device that hasn't installed it yet is now a known, documented target, not a theoretical one.
Most compromises don't rely on some secret, never-seen-before exploit. They rely on a vulnerability that was patched publicly weeks or months earlier, aimed at whoever hasn't updated yet, which, at any given time, is a lot of businesses. The gap isn't usually a lack of awareness; it's a patching process built around a monthly or quarterly cycle that's simply too slow for the most severe updates.
The practical fix is turning on automatic updates everywhere it's available, and having an explicit, faster process for the handful of things that can't auto-update: see our guide to the Cyber Essentials 14-day patch rule for the specific timeline. Or run the free 5-minute readiness check to see where your current process would fall short.