A common recommendation to mitigate against cyberattacks is to regularly patch software.
People making these recommendations often downplay the difficulty of patching for certain organizations or systems.
People complaining about the difficulty of patching are often overestimating the difficulty of patching.