A firmware update is a manufacturer-issued revision to the low-level software built into a device, such as a router, printer, security camera, or laptop. It fixes bugs, improves performance, and, most importantly, patches security flaws that attackers can exploit. Applying firmware updates promptly is a basic but frequently overlooked security control.
Almost every device in your office runs on firmware, the hidden code that tells the hardware how to behave. Most people never think about it until a manufacturer pushes an update, and even then it is easy to click “remind me later” and forget. That habit is a genuine security gap. Firmware sits beneath your operating system and your antivirus, so when a flaw is found in it, the update is often the only thing standing between your business and an attacker. This guide explains what a firmware update actually is, how it differs from ordinary software, and why keeping firmware current is one of the quieter but more important parts of business security.
Firmware is the set of instructions permanently stored inside a device that tells its hardware how to operate. NIST defines it as computer programs and data stored in hardware, typically in read-only or programmable read-only memory, so that they are not changed during normal use. It is the layer that turns a circuit board into a working router, a printer, or a laptop. Without firmware, the hardware is inert. A firmware update replaces or revises that stored code with a newer version released by the manufacturer.
A useful way to picture it: if your applications are the staff working in a building and the operating system is the building manager, then firmware is the wiring, plumbing, and elevators built into the structure itself. You rarely see it, you do not interact with it directly, but everything above it depends on it working correctly. When the manufacturer finds a fault in that wiring, they issue a firmware update to fix it, and someone has to actually apply it.
The process itself is consistent across most devices:
That verification step matters more than it looks. Modern security guidance from NIST treats firmware as something that must be protected against unauthorized changes, able to detect tampering, and able to recover if it is corrupted. A legitimate firmware update, applied through the manufacturer’s official channel, is how that protection is delivered in practice.

Source: NIST Glossary: Firmware | NIST SP 800-193: Platform Firmware Resiliency Guidelines
The most common confusion is between firmware and ordinary software, with drivers adding a third layer of muddle. They are related, but they sit at different depths in a device, and knowing the difference explains why firmware updates deserve special attention.
Software is what most people mean by “apps,” the programs that run on top of an operating system: your email client, your accounting package, your browser. Firmware is far lower down, the code baked into the hardware that lets the device function at all, before any operating system is even involved. A driver sits in between, a piece of software that lets your operating system talk to a specific piece of hardware. The closer to the hardware a piece of code runs, the more powerful, and the more dangerous, a flaw in it becomes.
| Firmware | Driver | Software / Applications | |
|---|---|---|---|
| Where it lives | Inside the hardware itself | On the operating system | On top of the operating system |
| What it does | Makes the physical device work | Lets the OS control the device | Performs tasks for the user |
| Example | Router, printer, or BIOS/UEFI firmware | Printer or graphics driver | Outlook, QuickBooks, Chrome |
| If it has a flaw | Deep, often hidden, hard to remove | Can crash or expose the device | Usually contained to the app |
The practical takeaway is that all three need updating, but firmware is the one businesses forget. Operating systems and applications nag you to update; firmware on a router or camera often sits untouched for years, quietly running whatever version it shipped with, holes and all.
Source: NIST Glossary: Firmware
Firmware updates are not just about smoother performance or a new feature. A large share of them exist to fix security vulnerabilities, and the reasons those fixes matter so much come down to where firmware sits and how attackers behave.
Firmware runs below your other defenses. Your antivirus, your endpoint protection, and even your operating system all rely on the hardware underneath them behaving honestly. A vulnerability in firmware can give an attacker control at a level those tools cannot see. Malicious code planted in firmware can survive a reboot, an operating-system reinstall, and in some cases a full factory reset, because it lives in the hardware rather than on the disk you wiped.
Unpatched devices are actively hunted. Attackers run automated tools that constantly scan the internet for devices running firmware with known, published vulnerabilities. Routers, security cameras, network storage, and other connected gear are favorite targets because they are rarely updated and often forgotten. The U.S. government maintains a public catalog of vulnerabilities that are being actively exploited in the real world, and network and device flaws feature heavily on it. If a vulnerability is on that list, a firmware update to close it is urgent, not optional.
The clearest illustration of the stakes is the VPNFilter campaign. In 2018, the FBI and the Department of Homeland Security warned that foreign cyber actors had compromised huge numbers of home and small-office routers and network storage devices worldwide using malware that embedded itself in the devices.
VPNFilter could collect data, attack other systems on the local network, and even destroy an infected device on command. Because it lodged in the device, a simple restart was only a temporary fix. The permanent remedy the FBI recommended was to update the firmware. That is the whole argument for firmware updates in one real-world example: the flaw lived in the device, and the update was the cure.
This is the single most common and most dangerous firmware misconception. A device with a serious security vulnerability works perfectly, right up until an attacker uses it. “It is not broken” tells you nothing about whether it is safe. The old warning that updates might break something has some truth for critical equipment, which is why you test and schedule them, but it is not a reason to run known-vulnerable firmware indefinitely. The real risk is not the update; it is the months or years an unpatched device spends exposed.
Protect every device with managed cybersecurity

Attackers are also getting faster at weaponizing new flaws, which shrinks the safe window between a vulnerability being published and being exploited. The gap between “an update is available” and “we applied it” is exactly the window an attacker needs, a pattern the broader data on exploited vulnerabilities and time-to-exploit makes clear.
Source: FBI IC3 Public Service Announcement (VPNFilter) | CISA Alert: Cyber Actors Target Home and Office Routers | CISA Known Exploited Vulnerabilities Catalog
Part of what makes firmware easy to ignore is that it is everywhere and mostly invisible. When people think of updates, they picture their computers. But the firmware attack surface in a typical business is much wider, and it is dominated by the devices no one is watching.
The point is not to panic about every gadget. It is to recognize that “keeping our software updated” quietly excludes a whole category of devices that also need attention. A device you cannot see is a device you are not patching.
Source: NIST SP 800-147: BIOS Protection Guidelines | NIST SP 800-193: Platform Firmware Resiliency Guidelines
Firmware updates fail businesses not because they are hard to install, but because no one owns the job. Turning firmware from a blind spot into a managed control comes down to a repeatable routine, the same discipline NIST recommends for patching in general.
For most small and midsize businesses, the honest problem is time and visibility. No one has a full list of what runs firmware, and no one has a recurring slot to check for updates and apply them safely. That is precisely the gap a managed IT provider fills: maintaining the inventory, monitoring for critical updates, testing them, and applying them across your whole fleet so nothing quietly rots on an old, vulnerable version. It is the same principle behind sound patch management practices, extended to the hardware layer.
Keep your business devices patched and current
Get your device infrastructure professionally managed
Source: NIST SP 800-40 Rev. 4: Guide to Enterprise Patch Management Planning | CISA Known Exploited Vulnerabilities Catalog
This explainer anchors its technical claims to primary standards and government sources. The definition of firmware follows the NIST glossary (drawn from NIST SP 800-53 Rev. 5 and CNSSI 4009). The principles that firmware must be protected against unauthorized change, monitored for tampering, and able to recover follow NIST Special Publication 800-193, Platform Firmware Resiliency Guidelines, and system-firmware protection reflects NIST SP 800-147, BIOS Protection Guidelines. Update and patch-management practice follows NIST SP 800-40 Revision 4, Guide to Enterprise Patch Management Planning. The active-exploitation point references the CISA Known Exploited Vulnerabilities Catalog. The VPNFilter figures (more than 500,000 devices across 54 countries, with firmware updates as the permanent remedy) are reported by the FBI Internet Crime Complaint Center and CISA.
Primary and authoritative sources: NIST Glossary: Firmware, NIST SP 800-193, NIST SP 800-147, NIST SP 800-40 Rev. 4, CISA Known Exploited Vulnerabilities Catalog, FBI IC3 (VPNFilter), CISA VPNFilter Alert.
A human firewall is the group of employees who, through security awareness and good habits, act…
A distributed system is a collection of independent computers, called nodes, that are connected over a…
A firewall is a network security device or software that monitors incoming and outgoing traffic and…
A data center is a physical facility that houses the servers, storage, and networking equipment a…