CIS IG1 Control 9.1: An Unsupported Application Is One the Vendor Has Stopped Defending

Ensure Use of Only Fully Supported Browsers and Email Clients

Your web browser and your email client are the two applications your people use most, and the two attackers target most, because that’s where the outside world reaches into your business. Control 9.1 asks a simple question about both: is the version you’re running still supported by the vendor? An unsupported browser or mail client isn’t just old. It’s software the vendor has stopped fixing, which means every flaw discovered from that point on stays open forever.

This is a close cousin of patching, but it’s a different decision. Patching keeps supported software current. This safeguard is about making sure the software is supported in the first place, and about not letting abandoned or unusual browsers and mail clients run where they can be exploited.

What this control actually says (in plain English)

Here’s the translation: only run browsers and email clients that the vendor still supports and updates, and retire the ones that have reached end of life.

Now the official version. Control 9.1 says you should ensure that only fully supported browsers and email clients are allowed to run in your environment, using the latest or a currently supported version.

The key word is supported. A browser that still opens fine but no longer receives updates has quietly become one of the most dangerous applications you own.

Why business leaders should care

Think about what actually flows through these two applications. Every website your team visits, every link in every email, every attachment from a client or a stranger arrives through the browser or the mail client. That makes them the busiest front door in your business, and attackers know it. When one of them is unsupported, you’re not just missing a few updates. You’re running software that the people who built it have publicly stopped defending, against adversaries who specifically look for exactly that.

This connects directly to earlier work in the series. In the spotlight on Why a Software Inventory Is More Than a Security Requirement, the whole point was knowing what you run and whether it’s still supported. This is where that inventory earns its keep, because you can’t retire an unsupported browser you didn’t know was installed. And once your browsers and mail clients are supported, keeping them current is the job of automated application patching, which I covered in Perform Automated Application Patch Management. Supported and patched are two halves of the same idea.

What “good” looks like

This is one of the more achievable safeguards, and standardizing actually makes life easier for your team, not harder. Here’s the practical path.

  • Standardize on one or two modern browsers. Pick supported, mainstream browsers and make them your standard. Fewer variants means fewer things to keep current and fewer surprises.
  • Keep them on a supported release channel. Make sure the versions in use are ones the vendor still updates, and let them stay current automatically.
  • Find and retire the stragglers. Use your software inventory to locate legacy browsers, abandoned mail clients, and anything past end of life, and remove them. Old, unsupported browsers are a common and completely avoidable exposure.
  • Block what shouldn’t run. Where you can, prevent unsupported or unapproved browsers and email clients from executing at all, so a retired application can’t quietly come back.

The audit and defensibility angle

This is a control you can demonstrate cleanly. Being able to show that your organization runs only supported browsers and email clients, and that end-of-life software is actively removed rather than tolerated, is exactly the kind of straightforward diligence auditors and insurers like to see. It signals that you manage your software deliberately instead of letting it drift, and it closes one of the easiest gaps an attacker can find.

An unsupported browser or email client is a door the vendor has stopped locking, sitting on the busiest entrance in your business. Standardizing on supported software and retiring what’s reached end of life is a low-effort, high-return decision that removes an entire category of avoidable risk. Run only what’s still defended, keep it current, and you take the two applications attackers rely on most and make them a much harder target.

Heath Gieson

Heath Gieson

Let's Connect. Make Better Technology Decisions with Forthright.

Understand your current environment and get a clear path forward. Let's connect.

who we support

Built for organizations that prioritize security, uptime, and compliance.

Z

Teams that want executive-level technology guidance and strategy for growth

Z

Operations that cannot afford disruption from unreliable or reactive IT

Z

Organizations ready to modernize operations with AI, automation, and data-driven insights

Z

Organizations handling sensitive data that need to stay secure and compliant without slowing down operations

Z

Organizations seeking outsourced IT support that strengthens their internal team or provides complete coverage when no internal team is in place

Forthright is the technology partner you should be working with

2024_CRN_MSP_500
Certified minority business
comptia-cybersecurity-trustmark