TechKnowSurge
VideoSecurityFree

Hardening - Updates

New hardware often ships with outdated firmware due to the time elapsed between manufacturing and deployment, making it essential to apply patches and updates before putting any device into production.

Complete this video to capture a CTF flag worth 1 point.

About this video

Hardware devices rarely arrive with current firmware. The time between manufacturing and end-user deployment typically involves factory staging, overseas shipping, warehouse storage, and retail distribution — a chain that can stretch across many months. During that same period, vendors continue releasing firmware updates to fix bugs, close security vulnerabilities, and improve performance, meaning the version shipped with the device is almost always outdated by the time it is unboxed. This applies to a wide range of equipment, including network switches, routers, firewalls, and any device running an embedded operating system or application stack. The risk is not theoretical — unpatched firmware may contain known, publicly disclosed vulnerabilities that attackers can exploit the moment a device is connected to a network. Treating the initial update as a non-negotiable step in the provisioning process is a foundational principle of secure deployment. Establishing a consistent pre-deployment patching workflow helps organizations avoid introducing unnecessary risk at the moment new infrastructure comes online. Checking vendor release notes, downloading the latest stable firmware, and verifying the integrity of update files before applying them are standard practices that should be built into any hardware onboarding procedure, regardless of device type or vendor.

What you'll learn

What's covered

Patching New Equipment

Key terms

Firmware
Permanent software embedded in a device's non-volatile memory that controls its hardware functions and low-level operations; it bridges the hardware and any higher-level software.
Patch Management
The process of acquiring, testing, and installing software updates to fix vulnerabilities and improve functionality.
Vulnerability
A weakness in a system, application, or process that can be exploited by a threat actor.
Attack Surface
The total set of points in a system where an unauthorized user can attempt to enter or extract data.
Baseline
A documented set of minimum security standards or performance metrics used as a reference point.

Topics

Network Hardening Firmware Updates Patch Management Network Security Device Configuration Vulnerability Remediation

Transcript

When we get a new piece of equipment, one of the first things we're going to want to do is update it. We're going to want to patch whatever software is running on it. So if it has an operating system or firmware, or perhaps certain applications that are on it, we're going to want to make sure those are patched and updated.

The Delay Between Manufacture and Deployment

There's usually quite a delay between the point in time something is manufactured and the time you're actually deploying it. Let's use an example of a switch. Maybe you are buying a switch, and that switch has some sort of firmware that's installed on it. Number one is, when things are on the factory and they're deploying these, that probably doesn't have the latest firmware. This firmware could be cycling up quite quickly, and they're not going to change out that firmware on those switches right away. They're going to probably ship with old firmware on it.

And then when they ship it, it might be coming from overseas. So then it gets put on some sort of shipping cargo ship and gets sent overseas, and then maybe some sort of train gets sent to a warehouse. There could actually be multiple warehouses between this process. And then it gets shipped by truck to the actual store, and then you're going to the store and you're purchasing it.

Now, this isn't the flow of all different products that you're buying, but a lot of products are. This is a general flow of that.

Update It First

Now, from the point in time where this firmware was created to when you actually purchase this and are installing it, there's a lot of changes to that firmware. And so the first thing we have to do is update it. So whatever piece of equipment that you're purchasing, one of the first things you need to do is make sure it's patched and updated.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →