HomeTrainingUpdates, devices, and backups
This is the module’s public preview page. Employees take the course in the learning environment with a test and records.Start the course →
Module 6 · 7 min

Updates, devices, and backups

Simple cyber hygiene that reduces most technical risk.

The employee keeps work devices updated and does not bypass security settings.

Threat

CERT.LV reports many compromised devices; ENISA highlights fast exploitation of vulnerabilities.

What to know

  • Updates close known vulnerabilities. Delays give attackers time.
  • A work device is not a shared family computer and is not a place for pirated software.
  • A backup matters only if it can be restored and is not available to the same attacker.
  • Public Wi-Fi is not automatically dangerous, but sensitive work should use the company’s approved secure connection.

Actions

  • Allow operating system and browser updates. Do not postpone them without a reason.
  • Do not turn off antivirus, firewall, or disk encryption just to work faster.
  • Do not connect unknown USB storage to a work device.
  • Report a lost or stolen device even if it is locked.

Workplace scenario

Postponed update

An employee postpones browser and operating-system updates for weeks because “there is no time”. Meanwhile a new vulnerability is publicly discussed.

Think before the test

  • Why do known vulnerabilities become more dangerous after publication?
  • How can updates be planned without interrupting work?
  • Which settings should employees not disable, even temporarily?

For the manager and responsible person

Employee instruction cannot replace technical inventory, patch management, and backup testing.

  • Define the maximum acceptable update delay.
  • Explain what to do if a work device is lost or stolen.
  • Regularly test whether backups can actually be restored.

Sources