Security builder & leader

4 Reasons Why Computer Users Dread Installing Security Updates

Users avoid updates because they require too many clicks, downloads are heavy, finalizing requires reboots, and mechanisms fail for non-privileged users. Google Chrome and Windows Update show better design. Enterprise IT should assume users won't patch timely and use centralized management tools.

68% of computer users prefer to have dental surgery rather than install security updates on their laptops or desktops. OK, I made that up, but my point is that updating software is time-consuming and annoying, which is probably why many people don’t bother to install security patches. Software vendors need to make the update process as easy as possible; at the same time, corporate IT teams need to plan their security architecture with the assumptions that end-users won’t manually install patches in a timely manner.

Security update mechanisms often have the following weaknesses from the perspective of the user’s experience:

For examples of well-designed security update mechanisms, see:

My hope is that software vendors can devote some R&D and user interface design efforts to make it less painful to install security updates. In the mean time, IT departments should recognize that most end-users will not install client-side updates in a timely manner. Enterprise IT should use Enterprise Management Systems (EMS), such as Group Policy and WSUS to push out updates in a centralized manner. Personal users should use tools such as Secunia to validate that the necessary updates are installed.

Related:

About the Author

Lenny Zeltser is a cybersecurity executive with deep technical roots, product management experience, and a business mindset. As CISO at Axonius, he leads the security and IT program, focusing on trust and growth. He is also a Faculty Fellow at SANS Institute and the creator of REMnux, a popular Linux toolkit for malware analysis. Lenny shares his perspectives on security leadership and technology at zeltser.com.

Learn more →