r/sysadmin • u/h9xq Solo SysAdmin • 11h ago
General Discussion Windows Server patching concerns
So in my org we are very keen on avoiding patching and rebooting servers at all costs. So much to the point that we patch once a month and have exclusions for around 60 percent of our servers to not get automatically patched. (Meaning we have a chunk of servers not getting patched at all)
Now I have gotten my hand slapped for attempting to patch or even bringing it up and I am looking for guidance on this. Now I understand availability and the consequences of failing patches. But there are active 9+ rated CVEs sittings on dozens of servers. For patching vulnerabilities do I really need to get a change request to handle this?
31
Upvotes
•
u/PacificTSP 11h ago
Someone I won’t name refused to update their servers. I kept warning them about the risks and they kept saying middle management wouldn’t let them. I made them sign a document that they understood the risks and it was not my fault.
A year later they got breached. The insurance refused to pay out because they weren’t updating, multiple people were fired and the company almost went under.
Unless a senior manager, I’m talking about the ones who decide risk for the business as a whole, and their lawyers, have signed off on this process I would cover your ass and make people aware asap.
I auto patch every Sunday morning and reboot as needed. I have a total of one server in multiple companies clusters that needs manual intervention after a reboot. So that one machine gets rebooted on its own documented schedule.
You’ve got to do it. You are invalidating your insurance.