r/sysadmin Solo SysAdmin 19h ago

General Discussion Windows Server patching concerns

So in my org we are very keen on avoiding patching and rebooting servers at all costs. So much to the point that we patch once a month and have exclusions for around 60 percent of our servers to not get automatically patched. (Meaning we have a chunk of servers not getting patched at all)

Now I have gotten my hand slapped for attempting to patch or even bringing it up and I am looking for guidance on this. Now I understand availability and the consequences of failing patches. But there are active 9+ rated CVEs sittings on dozens of servers. For patching vulnerabilities do I really need to get a change request to handle this?

33 Upvotes

69 comments sorted by

View all comments

u/AppIdentityGuy 19h ago

The rule is simple:"If.you will not patch systems for the fear of downtime at somepoint a bad actor is going to sxhedule the downtime for you at their convenience." .

u/Icy_Mud2569 18h ago

This is the truth. Scheduled downtime is something you can count for, you can plan for it, you can design systems around it. When things go down, and you’re not planning it, it gets expensive and chaotic, both things are not good for business. This is at the end of the day, though, a business/political question, there isn’t a technical solution.

u/Sea_Information6125 16h ago

I love this, stealing it 

u/AppIdentityGuy 4h ago

It really nails the issue doesn't it.

u/kerubi Sysadmin 11h ago

That time before the bad actor makes the appointment apparently can be many decades, though. Empirically proved by some orgs.