
The Renewal You Resent Is the Patch Crew You Hired
Somewhere on your network there's a device nobody has touched since the day it was installed. Unpatched network devices are how attackers actually get into small businesses now, and the licensing renewal you resent paying every year is one of the two ways that problem gets handled. The other way is hoping.
Here's the test this whole post applies, and it's worth running against every piece of hardware you own: who patches this device, and how fast do they move? Every camera, firewall, switch, and access point on your network gets exactly one of two answers. Either a vendor whose business depends on shipping the fix, or whoever at your company remembers the device exists. There is no third answer, and "the installer, probably" is the second one wearing a costume.
The math changed underneath you
The buy-it-once model made sense when vulnerabilities arrived at a pace a human could track. That era is over. Security researchers published 48,185 CVEs in 2025, publicly documented vulnerabilities, about 132 every day, up 20.6% from the year before. Nobody at a 40-person company is reading 132 vulnerability disclosures a day and cross-referencing them against the camera system. Nobody at a 400-person company is either.
Attackers noticed. Verizon's 2025 breach data shows exploitation of vulnerabilities reached 20% of the ways attackers first get in, nearly tying stolen passwords for the top spot, and the fastest-growing target grew almost eight-fold in a single year: edge devices. Firewalls, VPN appliances, the boxes that sit between your network and the internet. The same report found that even among organizations working to patch those devices, only about half the known holes got fully fixed all year, and the fixes that did land took a median of 32 days. The attackers' window is measured in days. The defenders' response is measured in months.
Why unpatched network devices are the way in
A server gets updates because someone logs into it every week. A laptop nags its owner. A camera on the warehouse ceiling and the firewall in the closet do neither: they sit there, quietly working, running the firmware they shipped with. Working and secure are different properties, and a device can hold the first one for years after losing the second.
This is not theoretical. CISA and the FBI's advisory on Akira, one of the most active ransomware operations going, says the group primarily targets small and medium businesses and gets in through VPN appliances, including by exploiting a known SonicWall vulnerability (CVE-2024-40766) on devices that hadn't been patched. As of late September 2025 they'd collected roughly $244 million in ransoms. That money came disproportionately from companies your size, and the door was disproportionately a network device nobody was watching.
The pattern repeats across vendors and years because the economics favor it. Breaking into a patched, monitored network is work. Scanning the internet for edge devices running last year's firmware is a script.
What the renewal actually buys
Now look at that licensing line item again: the Meraki renewal, the Rhombus camera subscription, whatever cloud-managed gear you run. Strip away the dashboard features and the warranty and the support line, and the core of what you're buying is this: a patch crew on retainer.
Cisco Meraki firmware upgrades, for example, are released and scheduled automatically inside a maintenance window you control, with advance email notice. When one of those 132-a-day CVEs lands in their gear, finding it, fixing it, and shipping it to your closet is their problem, on their payroll, at their speed. Cloud-managed camera platforms run the same model. Security people call this risk transference: you're paying a vendor to carry a risk you're not staffed to carry yourself. It's the same reason you buy insurance instead of self-funding your building burning down.
The trade-off, stated honestly, since there is one:
- Locally managed hardware costs less over its life and answers to no subscription. In exchange, you own the patch queue forever: tracking disclosures, testing firmware, scheduling downtime, every device, every month, for years. Done rigorously, that's real labor you're paying for anyway, just invisibly. Done the way it's usually done, it's not done.
- Cloud-managed hardware costs more, annually, visibly, and the device generally stops being useful if the license lapses. In exchange, the patch queue belongs to a vendor with an engineering department and a reputation to lose.
Neither is free. One of them just hides the bill until an incident presents it all at once, with interest.
The catch
A subscription is not absolution, so here's what it doesn't buy. A lapsed license is gear that stopped updating, so the renewal genuinely is load-bearing. Configuration is still yours: the CISA advisory notes Akira also walks in through old credentials that were never reset and VPN access with no multi-factor authentication, and no vendor patches your password habits. And a managed firewall in front of an unmanaged eight-year-old switch is a locked front door on a house with a screen-door back entrance. The test applies per device, not per network.
Skai would add that the reason this problem persists isn't technical at all: an invoice you see every year feels more expensive than a risk you never see. She's right.
The one-question audit
Walk your building, or have us do it, and put every network-connected device on a list: cameras, firewalls, switches, access points, door controllers, the DVR from the old camera system that's somehow still plugged in. For each one, write the answer to the test: who patches this, and when did they last do it? A vendor's name with a current license is a good answer. A person's name with a date is an acceptable one. A blank is your attack surface, itemized.
Most businesses that run this exercise find at least one device with no answer at all. That device is the reason the renewal is cheaper than it looks.