← All articles

Updates… Not That Complicated?

A Monday morning call: every file is encrypted. The cause? An update that never happened. Here's how to avoid that call.

A company calls us on a Monday morning. Every file is encrypted, backup copies included. The general manager can't understand it: his computers run automatic updates, exactly as they should. The problem is that IT security doesn't stop at Windows Update.

What we think of, and what we forget

When people hear "vulnerability," most think of Windows Update right away, that tool running quietly in the background to install security patches and new features. On an Android phone or an iPhone, it's the same story: apps update themselves almost without you noticing. Manufacturers do their part. They fix the security holes discovered in their products, usually fairly quickly once an issue becomes public.

The catch is that Windows, macOS, Linux, and mobile apps are only part of what actually runs inside a small or medium business. There are many aspects to IT security, and vulnerability management is one that stays largely invisible unless you follow technology news closely. The result: plenty of significant flaws slip past unnoticed, until the day they become a very concrete problem.

An example that makes the point

A well-known case: a D-Link storage device affected by cr1pt0r, a piece of malware that encrypts pretty much any vulnerable device connected to the internet. A company using this device reached out to us after the fact. The general manager was adamant: all their computers run automatic updates. He couldn't understand why his files, and even his backup copies, had suddenly turned up encrypted.

The answer comes down to one thing: the storage device itself wasn't covered by that update policy. Nobody thought about it, because it doesn't look like a computer in the usual sense. That's exactly the kind of blind spot that turns an otherwise well-managed business into an easy target.

Updates, sure, but which ones?

It's great to have automatic updates configured on your workstations. But what about the rest of the IT environment? Are the servers up to date? What about firmware versions? Is the router covered? The switches? The firewall? These are often the devices you set up once, forget about, and that keep running unmonitored for years.

You also need to ask about end of life for your technology products. Every manufacturer eventually stops releasing patches for a given model. From that point on, any newly discovered vulnerability stays open, with no official fix coming. Is there an upgrade or replacement plan in place for that equipment before it reaches that point?

When a device simply can't be updated

In some cases, like the company hit by cr1pt0r, the device in question simply can no longer be patched. When that happens, the goal isn't zero risk, that's not realistic, it's knowing that risk exists and reducing it as much as possible. In practice, that might mean keeping backup copies outside the vulnerable device rather than on the same network, or simply replacing the device before it becomes an entry point.

An overall view, not just checked boxes

What matters is having a full picture of your IT environment and managing it as a coherent whole, not as a collection of independent devices you're hoping will update themselves. It bears repeating: security is like a chain. It's never stronger than its weakest link, and that weakest link isn't always the computer you keep a close eye on.

At MMO Techno, we look at your entire solution, from workstations to the network equipment that tends to get forgotten, to bring a holistic approach to vulnerability management rather than a list of half-checked boxes.

An IT project or a question?

Talk to an MMO Techno expert. We'll give you a clear, fast answer.

Contact us