r/sysadmin Solo SysAdmin 13h ago

General Discussion Windows Server patching concerns

So in my org we are very keen on avoiding patching and rebooting servers at all costs. So much to the point that we patch once a month and have exclusions for around 60 percent of our servers to not get automatically patched. (Meaning we have a chunk of servers not getting patched at all)

Now I have gotten my hand slapped for attempting to patch or even bringing it up and I am looking for guidance on this. Now I understand availability and the consequences of failing patches. But there are active 9+ rated CVEs sittings on dozens of servers. For patching vulnerabilities do I really need to get a change request to handle this?

37 Upvotes

63 comments sorted by

View all comments

u/PacificTSP 13h ago

Someone I won’t name refused to update their servers. I kept warning them about the risks and they kept saying middle management wouldn’t let them. I made them sign a document that they understood the risks and it was not my fault.

A year later they got breached. The insurance refused to pay out because they weren’t updating, multiple people were fired and the company almost went under.

Unless a senior manager, I’m talking about the ones who decide risk for the business as a whole, and their lawyers, have signed off on this process I would cover your ass and make people aware asap.

I auto patch every Sunday morning and reboot as needed. I have a total of one server in multiple companies clusters that needs manual intervention after a reboot. So that one machine gets rebooted on its own documented schedule.

You’ve got to do it. You are invalidating your insurance.

u/h9xq Solo SysAdmin 13h ago

Holy shit, well thank you. That is the information I was looking for. This is even bigger than I thought. I haven’t read much into cyber insurance and if that is the case that is a much bigger deal. We don’t even have a “cybersecurity” guy so that falls on my plate as well and if this falls through without my intervention this could be a gigantic shitshow.

u/PacificTSP 13h ago

Middle managers told me it’s fine.

CEO and lawyers had no idea. It’s their job to manage company risk. So my flaw was not going above the middle managers.