Ask most organizations when they last updated their computers and they can tell you. Ask when they last updated the firmware on their firewall, switches and wireless access points, and the answer is often a long pause. These devices sit in a closet, work quietly, and are easy to forget until something breaks.
That quiet is the risk. Network devices sit at the edge of your environment and carry all your traffic. Vendors regularly release firmware to fix security vulnerabilities and bugs, and attackers actively look for devices that have not been updated. Firewalls and remote access gateways in particular have been frequent targets. Updating them takes planning, because a mistake can take down a facility, but not updating carries its own cost.
Understanding the reasons helps address them.
Fear of downtime. Updates may require a reboot, which interrupts service.
Nobody owns it. Network gear falls between IT staff, vendors and facilities.
No inventory. If you do not know what you have, you cannot know what is outdated.
It works. Devices without visible problems seldom attract attention.
Complexity. Some updates must be done in a certain order or can change behavior.
List every firewall, router, switch, wireless controller and access point. For each, record make, model, serial number, current firmware version, location and support status. Check whether the vendor still supports the model. End-of-life devices no longer receive security fixes, and replacing them belongs in your budget plan.
Not every device carries the same risk.
Internet-facing devices first. Firewalls, VPN gateways and anything reachable from outside deserve the fastest attention, especially when a vendor publishes a critical security fix.
Core switches and wireless controllers next, since they affect many users.
Edge switches and access points can be updated in groups on a regular schedule.
Subscribe to your vendors' security notifications, and watch CISA advisories for vulnerabilities affecting equipment you use.
Look for security fixes, known issues and required upgrade paths. Some devices cannot jump directly from an old version to the newest one.
Export and store the current configuration before any change, in a location you can reach if the device is down. Knowing you can restore quickly makes everything less stressful.
Pick a time when disruption is least harmful. In healthcare, that requires thought. Nurse call, phones, door access, cameras and resident Wi-Fi may all depend on the network. Notify department heads ahead of time and give them a number to call if something looks wrong.
If you have identical devices, update a less critical one first, or a spare, and watch for problems. For multi-site organizations, update one location before the rest.
Know how you will return to the previous version or configuration if something fails, and how long that takes. Keep console access or an out-of-band method available, since you may not be able to reach a device over the network if it fails to start.
Confirm the backup and rollback plan.
Apply the update following the vendor's instructions.
Verify the device returns to service and that traffic is flowing.
Test key systems: internet access, remote access, wireless, phones and clinical applications.
Monitor for several hours or days for unusual behavior.
Record the new version in your inventory.
For redundant firewalls, update one at a time so service continues on the other, following vendor guidance.
One-time heroics are not a strategy. Set a recurring schedule:
Monthly: review vendor security notices and check for critical fixes.
Quarterly: update access points and switches in planned groups.
As needed: emergency patching for critical vulnerabilities on exposed devices, usually within days rather than months.
Annually: review the inventory for end-of-support devices and plan replacements.
Firmware is only one part of device hygiene. Change default passwords, disable management access from the internet, restrict administrative interfaces to a management network, use multi-factor authentication where supported, and keep backups of configurations. Disable services you do not use.
If your network is complex, uses specialized medical or building systems, or has no one clearly responsible for it, outside help can lower both risk and stress.
UnityCare IT manages firmware updates as part of regular network maintenance for healthcare and senior-living organizations, handling inventory, scheduling, testing and rollback planning so updates happen without surprises.
Wi-Fi, switching, firewalls and internet that hold up across a whole facility.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172