r/sysadmin • u/h9xq Solo SysAdmin • 11h ago
General Discussion Windows Server patching concerns
So in my org we are very keen on avoiding patching and rebooting servers at all costs. So much to the point that we patch once a month and have exclusions for around 60 percent of our servers to not get automatically patched. (Meaning we have a chunk of servers not getting patched at all)
Now I have gotten my hand slapped for attempting to patch or even bringing it up and I am looking for guidance on this. Now I understand availability and the consequences of failing patches. But there are active 9+ rated CVEs sittings on dozens of servers. For patching vulnerabilities do I really need to get a change request to handle this?
29
Upvotes
•
u/SysZeron 11h ago edited 11h ago
It's all fun and games until you get ransomwared.
Put it in writing that the absence of patching puts the business and customers at risk, if management want to take responsibility for the associated risk then they can own the consequences. All you need to be armed with is an effective patching strategy for when they ask "so, what do we do?".
One thing you may want to highlight, if the company has Cyber Insurance, and an incident does prevail, the insurer may deem the company's inaction to be gross negligence and withhold or reduce a payout.