Updates and maintenance
Why Remind me later is the biggest risk on your computer

Most computers that get breached are not breached through some clever new flaw. They are breached through a fix that already existed, had already been downloaded, and was waiting for a restart that never came.

Updated 24 July 2026 · by Oshri Pinhas, XIT · 9 min read
Updates and maintenance: the cost of Remind me later | XIT

The short answer

Up to date and patched are not the same thing. A security update that has been downloaded or detected but not installed leaves the known vulnerability open until the machine restarts, and unpatched machines are the most common ransomware entry point. The XIT agent reports every 15 minutes how many updates are pending: one pending update already raises a warning, 10 or more is treated as critical, and a machine with no update installed for over 60 days is flagged as a patch gap. Restarts are offered and scheduled with the customer, never forced remotely. From $5/month per computer.

What does up to date actually mean?

An update has three states and only one of them protects you. No update available, and the machine is genuinely patched. Update detected or downloaded but not installed. Update installed, but only taking effect after a restart.

The last two states carry exactly the same risk: the known vulnerability stays open until the machine restarts. That is not theoretical. Unpatched machines are the most common ransomware entry point, because when a vendor publishes a fix it also publishes, indirectly, a description of what was broken. Attackers read the same document. The window between the day a patch ships and the day it goes live on your machine is their opportunity.

The XIT agent counts, every 15 minutes, every update the operating system reports as not installed. It does not stop at software: it searches driver updates too, and tags each pending update by kind — security, driver, feature or general. That classification matters later, when someone has to decide what goes in today and what can wait for a quieter afternoon.

Why is one pending update already a warning?

The threshold is not set at some vague notion of too many. One pending update raises a warning. Ten or more is marked critical. The logic is simple: there is no such thing as a security patch that is only slightly pending. Either the fix is live on the machine or it is not, and while it is not, the hole is open.

The threshold of 10 tells a different story. A machine with ten pending updates did not miss one patch. It has not been restarted, or someone has been dismissing the same prompt for weeks, or the update process is failing quietly. That is a pattern rather than an incident, which is why it is treated as a fault and not a reminder.

In the monthly report this appears in plain language under the maintenance and updates section: either no pending updates, or the number pending with a note that they include security fixes. No tool names, no raw log output. The same principle runs through all of continuous monitoring: a number, what it means, and a recommendation.

What happens on a machine that has not been patched in 60 days?

Alongside the pending count, XIT measures the age of the last installed patch — days since any Windows update was actually installed. More than 60 days raises its own separate warning. That distinction matters more than it looks: a machine can report zero pending updates simply because its update search has been stuck for two months.

Here XIT does something that is not the industry norm: it does not invent a list of vulnerabilities. No agent genuinely knows which specific flaw is exposed on your machine without a complete inventory of every application and version on it. Rather than attaching impressive-looking vulnerability identifiers to a guess, XIT reports the gap that actually exists: how long the machine has gone unpatched and how many updates are waiting. A machine patched within the last month with fewer than 10 updates pending is not reported as a finding at all.

Why does the fault come back after you reinstall the software?

There is a category of fault that behaves confusingly. An application keeps crashing, you uninstall and reinstall it, it behaves for a day, then it crashes again. That happens when the problem was never in the application at all, but in the operating-system files it depends on. A system file damaged by an unclean shutdown, a disk that filled up mid-update or failing hardware stays damaged after a reinstall, because nothing in that reinstall touched it.

That is why these checks exist as actions a technician can run remotely, and why they appear in the customer report under names a non-technical reader can follow:

These are also the first step in crash analysis, because a corrupted system file and a recurring blue screen are very often the same story told twice.

Drivers in error, and the fault that appeared right after an update

A driver is the translation layer between the operating system and a piece of hardware. When one is in an error state, an entire component stops working — the printer disappears, the network card will not connect, the microphone is silent on the call. Users almost never describe this as a driver problem. They say the computer started behaving strangely.

The agent pulls the list of devices the operating system itself has flagged as faulty, with the component name and its class, and every one raises a warning. This is one of the clearest cases where an automated check saves an hour of guessing, because it names the component instead of the symptom.

The other side of this is just as important and less comfortable to say: a driver update is itself a common cause of a brand-new fault. A new printer or graphics driver can break something that worked yesterday. That is exactly why updates are classified by category and can be installed as security only, drivers only, or everything. For a small business that separation is worth real money: security patches go in immediately, and the printer driver goes in separately, when somebody is around to check that the printer still prints.

Windows licensing and certificates about to expire

Two quiet things that can cost a full working day with no advance warning.

Licensing state. The agent reads the operating system's own licence status and distinguishes between activated, unlicensed, grace period and notification state. Anything other than activated raises a warning, because that is where the restrictions and the full-screen prompts begin. On second-hand machines and machines that have had a hardware upgrade this is far more common than people expect, and it tends to surface on exactly the day something is due.

Digital certificates. The agent scans the machine's certificate store and reports anything expiring within 30 days, including how many days are left. Thirty days or fewer raises a warning; seven days or fewer is critical; and if a certificate has already expired, the alert says how many days ago. Certificates get that attention because an expired certificate never announces itself. A service simply stops working, a site starts showing visitors a security warning, and nobody thinks to look there first. Thirty days of notice is enough to renew without a crisis. The rest of the protective checks are covered on the security check page.

What happens on a machine that has not restarted in a month?

The agent reports continuous uptime. Past 30 days of uninterrupted running, XIT raises a finding stating plainly that a restart would apply the pending updates. On laptops this happens more often than people realise, because closing the lid is not shutting down. The machine sleeps and resumes exactly where it was, including the same updates that have been waiting for a month.

Two things are true on a machine like that. Installed updates have not taken effect, and memory is never returned — software that leaks memory keeps claiming more of it the longer it runs, and XIT measures that upward trend across 60 days of snapshot history and flags it as a suspected memory leak. A restart is the cheap, immediate fix for both.

The opposite is measured too: three or more restarts inside a single week is flagged as a suspected stability or hardware problem. Both ends of the range are watched — too many restarts and too few.

Restarts are recommended and scheduled, never forced

This is a deliberate product decision rather than a technical limitation, and it is worth stating flatly: XIT will not restart your computer remotely without you choosing to. When an update is installed and waiting on a restart, a message appears on the machine saying the updates are installed and a restart is needed to complete them. It has two buttons: restart now, and remind me later. The restart only happens if the person at the keyboard presses the button.

You might reasonably ask why a page about the danger of postponing keeps a postpone button at all. Because the alternative is worse. A management tool that reboots a machine in the middle of a video call, an unsaved edit or a filing deadline becomes a tool people work around, and a system people work around protects nobody. So the approach runs the other way: state what is at stake, agree a time, and keep reminding. The prompt stops once the machine has actually restarted, and there is a minimum interval between reminders.

What does happen behind the scenes is that nothing gets forgotten. As long as updates are pending, they keep appearing in the alerts and in the monthly report. Remind me later postpones the restart, not the problem.

A maintenance routine: what, how often, and what it prevents

Preventive maintenance sounds like an IT department's phrase. In practice it is a short list, each item preventing one specific failure:

TaskHow oftenWhat it prevents
Scan for pending updatesAutomatic, every 15 minutesA machine quietly drifting to 10 pending updates
Install security updates and restartMonthly, at an agreed timeA known hole staying open — the most common ransomware entry point
System file integrity scanQuarterly, or after any crashA fault that returns even after reinstalling the software
Installation file repairOnly when the integrity scan could not repair the damageUpdates failing repeatedly with the same error
Review drivers in an error stateMonthlyPrinter, network or audio failing for no visible reason
Track expiring certificatesAutomatic, 30 days of noticeA service or site breaking on the day the certificate expires
Deliberate restartAt least monthly; a finding after 30 days of uptimeInstalled updates never taking effect, and memory never released
Verify operating-system licensingAutomatic, on every reportRestrictions and prompts appearing suddenly mid-work
Review the system event logWeekly, or when 50+ errors appear in a dayA faulty component or service that has not yet taken the machine down

Updates fail when the disk is full. Below 20% free space is a warning and below 10% is critical, and that is exactly the range where updates install themselves halfway and fail silently. If an update has failed twice in a row, check free disk space before anything else — the detail is on the hardware check page.

If you would rather someone else carried this, that is what the $10/month per computer package buys: the agent counts, measures and alerts, and a human technician decides what is urgent and agrees the restart window with you.

FAQ

Does a downloaded update already protect me?

No. An update that has been downloaded or detected but not installed, and an update that has been installed but is waiting on a restart, both leave the known vulnerability open until the machine restarts. Only after the restart is the fix live. Unpatched machines are the most common ransomware entry point.

How many pending updates count as a problem?

One. A single pending update already raises a warning in XIT, because there is no such thing as a partially pending security patch. Ten or more pending updates is marked critical and indicates a machine that has not been restarted or whose update process is failing repeatedly.

Will XIT restart my computer without asking?

No. Restarts are always recommended and scheduled with the customer and are never forced remotely. When an update is waiting on a restart, a message appears with two buttons: restart now, or remind me later. The machine only restarts if the person at the keyboard chooses it.

Why does a fault come back after I reinstall the application?

Because the problem is usually not in the application but in a damaged operating-system file it depends on, and that file stays damaged after a reinstall. The fix is a system file integrity scan, followed, if it found damage it could not repair, by an installation file repair that restores the store of clean files those repairs are copied from.

Should driver updates be installed together with security updates?

Better not. A driver update is a common cause of a new fault appearing immediately after an update. XIT classifies updates by category and can install security only, drivers only, or everything, so security patches go in straight away and a driver update goes in separately at a time when its hardware can be tested afterwards.

What is wrong with a computer that has not been shut down in a month?

Two things. Installed updates do not take effect until the restart, and memory is never released, so software that leaks memory keeps claiming more of it. XIT raises a finding once a machine has been running continuously for more than 30 days. Closing a laptop lid is not a shutdown.

How does XIT know a machine has not been patched recently?

The agent reports every 15 minutes both the number of pending updates and the number of days since the last Windows update was installed. More than 60 days without an installed update raises its own separate warning, because a machine can show zero pending updates purely because its update search is stuck.

Let the updates be handled without you having to remember

An agent that counts pending updates every 15 minutes, and a human technician who decides what is urgent and agrees the restart window with you. From $5/month per computer for monitoring, $10 with a technician.

Get in touch

Read next

⚡ POWERED BY INSTASITE
This site was built with InstaSite.ai
Build a high-quality business website with AI in 60 seconds — totally free · built-in SEO · your own domain
Build a free site →
instasite.store · Automatic AI website builder for small businesses