Patch management is the practice of keeping software updated promptly and systematically — and it prevents more intrusions than any single security product. Attackers overwhelmingly exploit known, already-patched vulnerabilities; CISA's Known Exploited Vulnerabilities catalog exists precisely because the same handful of aging flaws gets reused year after year. The working home setup is deliberately boring: automatic updates everywhere they exist, a monthly fifteen-minute checklist for the rest, and a rule that anything announcing end-of-life support gets replaced.
Why is patching still the top defense?
Because it removes the vulnerability instead of detecting the attack on it. Intrusion chains lean on components that were fixable before the intrusion: an unpatched VPN appliance, last year's router firmware, an operating system that stopped receiving updates in 2020. Security firms' incident reporting and CISA's binding directives keep converging on the same conclusion — delays of weeks to months between patch release and installation are where intrusions live. The patches themselves are also the most-tested software most vendors ship; the fear that updates break things more often than they help is a decade out of date for major platforms.
Turn on automatic updates first
Go down this list once and never think about it again:
- Operating systems: Windows Update and macOS software updates set to install automatically, including the restart (schedule it for overnight). On phones, enable automatic OS and app updates.
- Browsers: Chrome, Edge, and Firefox update themselves by default when restarted — just close the browser fully each week.
- Password manager, antivirus, and messenger apps: auto-update in their settings.
- Router: enable automatic firmware updates if offered — this single setting closes the appliance category most people forget exists.
- Anything else with an "automatically keep updated" checkbox: check it.
What still needs the monthly checklist?
Fifteen minutes, first Saturday of the month, coffee in hand:
- Phones and tablets: Settings > Software Update — verify the version is current even with auto-updates on, since major version jumps often wait for approval.
- Computers: check for pending updates and restart anything nagging. A pending-update restart is the most common reason "automatic" updates fail silently.
- Router, modem, NAS, and printer: log into each admin page and check firmware. Every few months this shifts to "verify automatic updates are still on."
- Smart-home hubs and cameras: open their apps and run device firmware updates — these are the least-auto devices in the house and among the most attacked.
- Anything you no longer use: uninstall it. Dead software is unpatched software with your name on it.
How should a small business do this?
The same routine plus an inventory and an order of operations. Keep a one-page list of every device and its update owner. Patch in a fixed sequence — internet-facing systems first (firewall, VPN, email, remote access), then servers, then workstations — because exposed systems are where attacks enter. Windows shops can enforce this with WSUS or Intune; Mac shops with MDM; a ten-person office can honestly survive on the inventory sheet plus scheduled auto-updates. The CISA performance goal most worth copying: remediate critical internet-facing vulnerabilities within days, everything KEV-listed on the catalog's deadline, and everything else within two weeks.
When should you wait before patching?
Rarely, and briefly. Enterprises with fragile line-of-business systems may stage updates for a week of testing; homes and small offices almost never need to, and the exposure of waiting exceeds the risk of a rare bad patch. Two rules keep this honest: never delay patches for internet-facing devices, and never delay the update that CISA's KEV catalog flags as actively exploited — those two categories account for nearly all the damage. If an update genuinely breaks something, roll it back and report it to the vendor; that is a recoverable annoyance, not an argument against the habit.
What about end-of-life software?
This is the hard rule: when a vendor stops shipping security updates, the countdown starts. Windows versions past their end date, an old Android phone with no updates, a router retired by its maker — none of these can be patched into safety, and no add-on product fully substitutes. Isolate them on a guest network, keep nothing sensitive on them, and plan replacement. The cheapest security decision most households make is retiring the last unsupported device before it becomes the story of how the printer let someone in.
For more context, read How to put smart-home devices on a guest network in 20 minutes.
For more context, read dns filtering.
For more context, read zero trust security.

