Updated October 2026 to our current guidance. The original reporting date is unchanged.
In the newsletter I mentioned that the head start you used to have for installing a security fix has shrunk. Here is the fuller story, including what an owner can do about it.
Count What’s on Your Computers → See how many programs each Windows PC has, how many are current, and how many need updating. No credit card needed. The scan is on us. If you want step-by-step instructions afterward, that’s a paid report, and you’ll see the price before you decide.
In this article
Hey folks! Most businesses I talk to have an update routine. Windows patches arrive on a schedule. Someone, inside or outside the company, approves them and restarts the machines. Other programs get updated when somebody gets to them. For a long time that routine was a sensible one.
The numbers behind it have changed, and I want to show you how.
There is a public tracker called the Zero-Day Clock, built by Sergej Epp, the chief information security officer at Sysdig. It measures one gap: the time between a flaw in a piece of software being made public and the first working way to use it showing up.
That gap is your head start. It is the time you have to install the fix before anyone has a tool for the hole. By the tracker’s numbers, the head start used to run about a year. Its recent figures put it at about a day.
When I first saw that, I wanted proof it was real, so here is some from the people who caught it.
On May 11, 2026, Google’s Threat Intelligence Group reported the first known case of criminals using a break-in tool built with AI’s help. It targeted a flaw in a widely used open-source program for administering web servers, and it would have let attackers get past the two-step sign-in check once they had a valid password. Google worked with the software’s maker to fix the flaw before the planned mass campaign started.
Sources: Zero-Day Clock; Tom’s Hardware on the Zero-Day Clock; SC Media on Google’s report, May 2026.
The mechanics are worth two minutes, because they explain why this is lasting.
A fix is also a map. When a software maker ships a security fix, it shows, without meaning to, exactly what was broken. Turning that into a working break-in used to take a skilled person days or weeks. That labor was most of your head start.
AI tools do much of that labor now. Give them the fix and they can read what changed, find the weak spot, and help write working code far faster than a person working alone. The flaw did not get easier. The work of using it did.
So the head start is shorter, and it starts when the fix is published. From that day, the clock is running for every computer that has not installed it.
Here is how that plays out in an ordinary week. A fix comes out on a Tuesday. It goes into the queue for “sometime next week.” That used to be fine. With the gap measured in about a day, it means several days when the published fix is known to everyone and not installed on your machines.
Here is my opinion, after more than 35 years at this. A tidy monthly batch for everything was built for a world with a year of slack. It still makes sense for plenty of things. For programs that face the internet, or that have a published flaw being used, a month is now a long time.
There is a second part, and it is the one most owners have not heard.
Windows Update never touches third-party software.
It keeps Windows current. It does not update your PDF reader, the file compression tool, the remote-access program, the accounting package, or the specialty app your office depends on. Each has its own updater, or none. Nobody did anything wrong. That is where Windows Update’s job ends, and many routines were built around Windows.
All software has flaws. The useful question is this: when a fix comes out for a program on your computers that Windows Update does not handle, who installs it, and how soon?
It also helps to decide what goes first, because not every update is equally pressing. Programs that face the internet come first, since anyone can reach them. Next come programs with a flaw that is already being used; the U.S. Cybersecurity and Infrastructure Security Agency keeps a public list of those, and an IT provider can watch it for you. After that, the everyday programs that are a version or two behind can go into the regular routine. And any program nobody uses anymore can simply be removed, which is faster than updating it and never needs doing again.
If the honest answer is “I am not sure,” you are in good company. Most owners I ask are not sure either. You built a business. The usual reason is that everyone assumed it was somebody else’s job, and nobody has checked.
You do not need to understand a line of code. You need to know where you stand. These three moves tell you.
Get one name, in writing, for your updates. Ask who handles updates for your business, including programs Windows does not update, and how fast they act when an urgent fix comes out. A person and a time is the answer you want. “Within 24 hours of a critical fix” is a good one.
Turn on automatic updates everywhere they exist. Windows, your browsers, your phones, and the apps your team uses all day. It will not reach every business system, but it takes about ten minutes and covers a lot. Whatever automatic updates cannot reach needs a person, which brings us to number three.
Find out where you stand right now. Before you run it, guess how many programs are on one of your computers and write it down. Then run the Reveal Scan on your Windows computers and get the counts on each one: how many programs are current and how many need updating. You cannot fix a clock you cannot see. If you run it and never speak to us again, that’s a fine outcome.
If the second number is higher than you expected, that is common. You don’t have to be able to do this. We’ll do it with you.
My father fell for a phishing email. 35+ years in cybersecurity, and it still reached the person I most wanted to look after. Someone got remote access to his computer and went looking for his financial papers. My step-mother noticed something was wrong, called me, and I stopped them before they reached his bank credentials.
It is the reason I built Forward to Safety around people who check the machines, backed by good technology. I have spent 35+ years in cybersecurity. FBI InfraGard trainer. Dozens of managed clients since 1991. None has had ransomware.
Partly, and it is a good habit. Automatic updates handle Windows and many everyday apps. But the systems that run your actual business, the website tools, the remote-access setup, the server in the closet, the specialty app your office depends on, usually do not update themselves. Those need a person to watch them.
So the useful question is this: when a critical fix comes out for a system that does not update itself, who installs it, and how fast? If nobody can answer yet, that is the thing to find out first. Ask it about the programs you would least like to lose for a day, such as whatever runs scheduling, invoicing, or the machines on the shop floor. Those are usually the ones nobody has looked at in a while.
No magic here. When a serious flaw is announced, the question is whether anyone checks your computers for it that week, and whether anyone can show you the answer. Most owners have never seen that answer written down.
Once you can see which programs are current and which are not, you can decide who closes the gaps: you, your IT provider, or us.
Start with the counts. Run the Reveal Scan on your Windows computers and see how many programs on each one need updating.
Count What’s on Your Computers →
When you have your counts, you can book a 15-minute conversation with me or one of our experts about what the scan found. No pressure.
Want this kind of plain-English security news every week? Sign up for Craig’s Insider Notes at CraigPeterson.com.
#ZeroDayClock #Patching #ThirdPartySoftware #SmallBusinessSecurity #ForwardToSafety
Join the owners who get Craig's Insider Notes every week.