Not Updating Software? You Are Risking More Than You Think

Martynas Siautilas

Martynas Siautilas

Continuous software updating is one of the most critical steps in safeguarding your business against cyberattacks. Research indicates that approximately 60% of successful cyberattacks occurred due to legacy, unpatched systems, which presented easy targets for hackers.

Not Updating Software? You Are Risking More Than You Think

Skipping Updates Can Have Serious and Irreversible Consequences

Today, cybersecurity is one of the key factors driving organizational stability, and reliably functioning information systems are an essential prerequisite for operational efficiency. Nevertheless, outdated software remains one of the most common security vulnerabilities. Although deploying updates directly mitigates the risk of known vulnerabilities being exploited, statistics show that a significant portion of cyber incidents still stem from delayed patching [1, 2, 3, 4, 5].

The software lifecycle relies on continuous adaptation—expanding functionality, strengthening security measures, and fixing bugs. Developers dedicate significant effort to identifying vulnerabilities, which are addressed through regular patches and new software releases. These patches are targeted code or configuration modifications designed to eliminate identified flaws and reduce the likelihood of unauthorized actions. Unapplied patches create opportunities to bypass security controls, access confidential data, or execute other critical operations that compromise system integrity and availability [6, 7, 8, 9, 10, 11].

Modern cyberattack dynamics are characterized by a high level of automation. Scanning and vulnerability identification tools continuously probe publicly accessible services, and newly published flaws are integrated into attack execution chains almost immediately. VulnCheck data from the first half of 2025 reveals that out of 432 analyzed vulnerabilities, as many as 32.1% were exploited within the first 24 hours of official publication, with some cases recorded even prior to public disclosure. This rate significantly exceeds the 23.6% figure established in 2024, highlighting the accelerating pace of attack automation. Cloudflare’s analysis also confirms that the publication of technical information often immediately triggers the first exploitation attempts—one of which was recorded just 22 minutes after the details were published. Such dynamics demonstrate that automated scanning tools operate much faster than most organizations can deploy patches or update defense mechanisms, making proactive readiness, swift response, and systematic patch management critically important [12, 13, 14, 15].

By 2027, the advancement of artificial intelligence technologies is projected to further accelerate vulnerability discovery and exploitation, scaling automated attacks particularly against unpatched systems. The window between vulnerability disclosure and initial exploitation is consistently shrinking, and advanced analytical tools will intensify this dynamic even further, posing risks to both critical infrastructure and supply chains [16].

In the first half of 2025, a record number of software vulnerabilities was recorded—over 21,500 new flaws, representing an 18% increase compared to the same period in 2024 [17]. This trend underscores a growing burden on systems: the rising volume of vulnerabilities directly expands the attack surface and complicates timely patch management. Survey findings further confirm this persistent issue. A 2019 study by the Ponemon Institute found that approximately 60% of data breach incidents stemmed from unapplied patches, while a 2020 Automox analysis revealed that 58% of breaches were linked to missing system updates [18, 19]. These figures indicate that despite growing security investments, patch management remains one of the weakest links.

This issue is highlighted even more clearly by a 2024 study published by the U.S. National Bureau of Economic Research (NBER), which covered the period from 2000 to 2018 and examined more than 150,000 medium and large organizations. The analysis revealed that as many as 57% of them were using server software containing known critical vulnerabilities, despite security patches being available. The study’s authors emphasize that decisions to delay patch deployment often stem not from objective risk assessment, but rather from operational constraints, complex dependencies, service continuity requirements, and technological integration risks. Consequently, complex updates are frequently postponed, leaving infrastructure vulnerable for extended periods [20].

Delays in software update deployment are driven not only by technical or organizational barriers, but also by the psychology of user decision-making. A 2020 study by P. Rajivan and co-authors [21], based on repeated decision-making tasks, analyzed how users realistically evaluate the benefits and potential costs of updates. Participants periodically faced situations where they had to choose between immediate updates—incurring one-time costs in time or convenience—and postponement, which increased the risk of maintaining a vulnerable system. This methodology made it possible to observe how behavioral strategies form under repeated decision-making, constantly balancing short-term comfort against long-term risk.

The study’s results revealed a consistent shift toward procrastination: in the initial phase, 71% of participants chose an immediate update, but in later stages this figure dropped to 31%, while the proportion of those opting to forgo updating altogether rose to 46% at one point. The authors highlighted that this behavioral shift was not driven by objective technical risk, but reflected a subjective perception of update costs—additional time expenditure, fear of operational disruption, or uncertain potential outcomes. This indicates that users often view updates not as an investment in security, but as an inconvenience, leading to the long-term adoption of an organizationally detrimental practice: systematic delay [22, 23].

The Largest and Most Significant Vulnerability of the Past Decade

One of the most prominent software vulnerabilities of the past decade was the critical flaw discovered in 2021 within the open-source logging library Log4j. This library is used across thousands of different systems—from enterprise infrastructure and cloud services to mobile applications and Internet of Things (IoT) devices. The vulnerability allowed remote code execution, enabling external actors to gain control of systems or access stored data. Due to the library’s widespread integration, the vulnerability affected billions of devices worldwide and received the maximum CVSS (Common Vulnerability Scoring System) score of 10, rightfully making it one of the most significant security incidents of recent times [24, 25].

Although the library’s developers released a fix immediately, actual risk mitigation took significantly longer. Many software vendors required months to release patched versions. At the end of 2023, Cloudflare reported that Log4j remained one of the most actively exploited vulnerabilities, even though two years had passed since its discovery. This situation underscored a fundamental issue: a prompt vulnerability patch is insufficient if organizations delay deploying updates or lack effective maintenance practices. As a result, Log4j continues to serve as an example of how even a single unpatched flaw can sustain global cyber risks [26, 27, 28].

A Missed Update Cost Nearly $700 Million

One of the most widely discussed cases illustrating the consequences of unpatched software was the 2017 Equifax incident. Due to a security vulnerability in Apache Struts, hackers gained access to the personal data of nearly 148 million consumers, including names, addresses, dates of birth, Social Security numbers, and other sensitive identifiers. The vulnerability enabled remote server command execution, allowing attackers to compromise the company’s infrastructure [29].

Crucially, Apache had released a patch as early as March 2017, but Equifax failed to apply it in a timely manner. The flaw remained unpatched until late July, with remedial action initiated only after unusual network activity was detected. Investigations into the incident revealed that the failure to patch stemmed from process fragmentation, unclear boundaries of responsibility, and ineffective infrastructure inventory management. The estimated financial impact—encompassing legal proceedings, fines, compensation, and technical remediation—approached nearly $700 million [30]. This case has become one of the most frequently cited examples demonstrating how costly a single delayed patch can be.

Examples of Data Leaks Can Also Be Found in Lithuania

Cyber threats associated with unpatched software are equally relevant at the national level. On January 7, 2024, the database of „Aiva sistema” was leaked, containing contact details of approximately 260,000 users, including full names, phone numbers, and email addresses. According to experts, the breach was likely executed by exploiting an unpatched software vulnerability that granted access to the database [31].

In March 2023, the State Data Protection Inspectorate (VDAI) imposed a €6,600 fine on a public sector institution for GDPR violations. The investigation revealed that the organization was using an outdated, unpatched content management system (CMS), allowed access to the admin dashboard from external networks without two-factor authentication, and attackers exploited these vulnerabilities to exfiltrate and publish a database of 13,500 individuals on dark web platforms [32]. These examples demonstrate that outdated infrastructure poses a threat not only to businesses, but also to the public sector and individual privacy.

Updates Are a Necessity, Not an Option

Cybersecurity practice clearly demonstrates that system updating is not an optional add-on, but an essential component of infrastructure hygiene. A key challenge is that organizations often still view updates as a disruption to routine operations rather than as a strategic risk mitigation process directly linked to service reliability and business continuity.

Practical experience in e-commerce maintenance indicates that a significant proportion of online stores continue to run on software that is 2 to 5 years out of date. This situation typically originates during the initial website development phase when long-term maintenance is neglected: no budget is allocated for ongoing support, version migrations are unplanned, and the platform architecture makes updates technically complex or virtually impossible without extensive re-engineering. Faced with critical security vulnerabilities under these conditions, businesses often find it more cost-effective to build a new e-commerce website from scratch rather than attempt to overhaul an obsolete system.

This trend is corroborated by data from National Cyber Security Centre (NKSC) reports. Analyzing „.lt” domain websites that utilize content management systems, the NKSC has recorded a consistently high proportion of vulnerable websites over several years. In 2018, 52% of such websites were assessed as vulnerable due to unpatched systems and components. In 2019, this share rose to 63%, reached 56% in 2020, and was 50% in 2021. Furthermore, in 2019, 8% of websites were operating on end-of-life platforms no longer supported by developers and receiving no security patches; such websites accounted for 6.5% in 2020 and 10% in 2021 [33, 34, 35, 36]. These figures demonstrate that inadequate maintenance and lack of updates remain primary drivers of website vulnerability within the Lithuanian web space.

Sources

  1. 1

    Mikalauskas, E. (2021, September 28). 95% of websites run on outdated software with known vulnerabilities. Cybernews. [viewed 2025-11-24]. Available online: https://cybernews.com/security/95-of-websites-run-on-outdated-software-with-known-vulnerabilities/

  2. 2

    OWASP Foundation. (n.d.). Outdated software. [viewed 2025-11-24]. Available online: https://owasp.org/www-project-top-10-infrastructure-security-risks/docs/2024/ISR01_2024-Outdated_Software

  3. 3

    Cybersecurity and Infrastructure Security Agency CISA. (2024, November 12). 2023 Top routinely exploited vulnerabilities. [viewed 2025-11-24]. Available online: https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-317a

  4. 4

    Cybersecurity and Infrastructure Security Agency CISA. (n.d.). Update Business Software [viewed 2025-11-24]. Available online: https://www.cisa.gov/audiences/small-and-medium-businesses/secure-your-business/update-business-software

  5. 5

    Ballejos, L. (2025, November 13). Risks of delayed patching: A guide to fix slow patching. NinjaOne. [viewed 2025-11-24]. Available online: https://www.ninjaone.com/blog/risks-of-delayed-patching/

  6. 6

    Cybersecurity and Infrastructure Security Agency CISA (2023, February 23). Understanding patches and software updates. [viewed 2025-11-24]. Available online: https://www.cisa.gov/news-events/news/understanding-patches-and-software-updates

  7. 7

    Ballejos, L. (2025, October 28). Patch vs Update: What is the Difference?. NinjaOne. [viewed 2025-11-24]. Available online: https://www.ninjaone.com/blog/patch-vs-update/

  8. 8

    Rapid. (n.d.). Patch Management: What It Is & Best Practices. Rapid7. [viewed 2025-11-24]. Available online: https://www.rapid7.com/fundamentals/patch-management/

  9. 9

    Maurice, E. (2024, September 24). Security patch management: a critical element for effective risk management? [viewed 2025-11-24]. Available online: https://blogs.oracle.com/security/security-patching

  10. 10

    IBM. (n.d.) Patch management. [viewed 2025-11-24]. Available online: https://www.ibm.com/think/topics/patch-management

  1. 11

    Anjum, M., Singhal, S., Kapur, P., Khatri, S. K., & Panwar, S. (2022). Analysis of vulnerability fixing process in the presence of incorrect patches. Journal of Systems and Software, 195, 111525. https://doi.org/10.1016/j.jss.2022.111525

  2. 12

    The Hacker News. (2025, November 13). When Attacks Come Faster Than Patches: Why 2026 Will be the Year of Machine-Speed Security. [viewed 2025-11-24]. Available online: https://thehackernews.com/2025/11/when-attacks-come-faster-than-patches.html

  3. 13

    Garrity, P. (2025, July 30). State of Exploitation – A look Into The 1H-2025 Vulnerability Exploitation & Threat Activity. VulnCheck Inc. [viewed 2025-11-24]. Available online: https://www.vulncheck.com/blog/state-of-exploitation-1h-2025

  4. 14

    Tremante, M., Zejnilovic, S., Newcomb, C. (2024, July 11). Application Security report: 2024 update. The Cloudflare Blog. Cloudflare. [viewed 2025-11-24]. Available online: https://blog.cloudflare.com/application-security-report-2024-update/

  5. 15

    National Cyber Security Centre. (n.d.). Impact of AI on cyber threat from now to 2027. NCSC.GOV.UK. [viewed 2025-11-24]. Available online: https://www.ncsc.gov.uk/report/impact-ai-cyber-threat-now-2027

  6. 16

    Khalil, M. (2025, October 8). Vulnerabilities Statistics 2025: Record CVEs, Zero-Days & Exploits. DeepStrike. [viewed 2025-11-24]. Available online: https://deepstrike.io/blog/vulnerability-statistics-2025

  7. 17

    Ponemon Institute. (2023). Ponemon vulnerability survey. ServiceNow. [viewed 2025-11-24]. Available online: https://www.servicenow.com/lpayr/ponemon-vulnerability-survey.html

  8. 18

    Automox. (2020). Automox 2020 cyber hygiene report: What you need to know now. [viewed 2025-11-24]. Available online: https://patch.automox.com/rs/923-VQX-349/images/Automox_2020_Cyber_Hygiene_Report-What_You_Need_to_Know_Now.pdf

  9. 19

    Murciano-Goroff, R., Zhuo, R., & Greenstein, S. (2024). Navigating Software Vulnerabilities: Eighteen Years of Evidence from Medium and Large U.S. Organizations. https://doi.org/10.3386/w32696

  10. 20

    Rajivan, P., Aharonov-Majar, E., & Gonzalez, C. (2020). Update now or later? Effects of experience, cost, and risk preference on update decisions. Journal of Cybersecurity, 6(1). https://doi.org/10.1093/cybsec/tyaa002

  11. 21

    Fitzgerald, J. (2024, August 13). Why Companies shouldn’t delay Software Updates—Even after CrowdStrike’s flaw. Harvard Business School. [viewed 2025-11-24]. Available online: https://www.library.hbs.edu/working-knowledge/why-companies-shouldnt-delay-software-updates-even-after-crowdstrikes-flaw

  12. 22

    Carnegie Mellon University. (2025, April 30). The consequences of not updating software. [viewed 2025-11-24]. Available online: https://www.cmu.edu/iso/news/2025/the-dangers-of-not-updating-software.html

  13. 23

    Bing, C., Satter, R., & Menn, J. (2021, December 13). Widely used software with key vulnerability sends cyber defenders scrambling. Reuters. [viewed 2025-11-24]. Available online: https://www.reuters.com/technology/widely-used-software-with-key-vulnerability-sends-cyber-defenders-scrambling-2021-12-13/

  14. 24

    National Cyber Security Centre under the Ministry of National Defence. (2021, December 13). Critical security vulnerability in popular Log4j library. [viewed 2025-11-24]. Available online: https://www.nksc.lt/naujienos/kritine_spraga_populiarioje_log4j_bibliotekoje.html

  15. 25

    Belson, D. (2023, December 12). Cloudflare 2023 Year in Review. The Cloudflare Blog. Cloudflare. [viewed 2025-11-24]. Available online: https://blog.cloudflare.com/radar-2023-year-in-review/

  16. 26

    Veracode. (2023, December 7). State of Log4j vulnerabilities: How much did Log4Shell change? [viewed 2025-11-24]. Available online: https://www.veracode.com/blog/research/state-log4j-vulnerabilities-how-much-did-log4shell-change

  17. 27

    Poireault, K. (2024, May 7). RSAC: Log4J still among top exploited vulnerabilities, CaTo finds. Infosecurity Magazine. [viewed 2025-11-24]. Available online: https://www.infosecurity-magazine.com/news/log4j-top-exploited-vulnerabilities/

  18. 28

    Electronic Privacy Information Center. (2017). Equifax data breach overview. [viewed 2025-11-24]. Available online: https://archive.epic.org/privacy/data-breach/equifax/

  19. 29

    BBC News. (2019, July 22). UK government’s response to the technology crisis. [viewed 2025-11-24]. Available online: https://www.bbc.com/news/technology-49070596

  20. 30

    UAB DELFI. (2024, January 11). Reports on another large-scale hacker attack in Lithuania: data of 260,000 users leaked. [viewed 2025-11-24]. Available online: https://www.delfi.lt/login/progresas/kibernetinis-saugumas/informuoja-apie-dar-viena-didelio-masto-programisiu-ataka-lietuvoje-nutekinti-260-tukst-vartotoju-duomenys-95593475

  21. 31

    Ministry of National Defence of the Republic of Lithuania. (2023). National Cyber Security Status Report 2023, ISBN ISSN 2783-7009, [viewed 2025-05-29]. Available online: https://www.nksc.lt/doc/Nacionaline-kibernetinio-saugumo-ataskaita-2023.pdf

  22. 32

    National Cyber Security Centre under the Ministry of National Defence (NKSC). (2018). National Cyber Security Status Report 2018 [viewed 2025-05-29]. Available online: https://www.nksc.lt/doc/NKSC_ataskaita_2018.pdf

  23. 33

    Ministry of National Defence of the Republic of Lithuania. (2019). National Cyber Security Status Report 2019, [viewed 2025-05-29]. Available online: https://www.nksc.lt/doc/Nacionalinio_kibernetinio_saugumo_bukles_ataskaita_2019.pdf

  24. 34

    Ministry of National Defence of the Republic of Lithuania. (2020). National Cyber Security Status Report 2020, ISBN 978-609-412-214-9, [viewed 2025-05-29]. Available online: https://kam.lt/wp-content/uploads/2022/02/nacionalinio_kibernetinio_saugumo_bukles_ataskaita_2020.pdf

  25. 35

    Ministry of National Defence of the Republic of Lithuania. (2021). National Cyber Security Status Report 2021, ISSN 2783-7017 [viewed 2025-05-29]. Available online: https://www.nksc.lt/doc/Nacionaline-kibernetinio-saugumo-ataskaita-2021.pdf