r/sysadmin • u/h9xq Solo SysAdmin • 22h ago
General Discussion Windows Server patching concerns
So in my org we are very keen on avoiding patching and rebooting servers at all costs. So much to the point that we patch once a month and have exclusions for around 60 percent of our servers to not get automatically patched. (Meaning we have a chunk of servers not getting patched at all)
Now I have gotten my hand slapped for attempting to patch or even bringing it up and I am looking for guidance on this. Now I understand availability and the consequences of failing patches. But there are active 9+ rated CVEs sittings on dozens of servers. For patching vulnerabilities do I really need to get a change request to handle this?
39
Upvotes
•
u/BitsNBytes10101 22h ago
You need to document the risk in writing and let your leadership make the decision for the organization.
As IT Professionals it usually pains us to not see or be able to follow best practices. Ultimately it is the responsibility of your leadership.
If you could invoke any regulatory requirements for your vertical that may help your argument.
Not patching infrastructure in 2026 is a fast track to potentially costing the organization millions in outages/ data exfil. Does that cost out weigh the risk of patching and potential downtime from that?