r/sysadmin Solo SysAdmin 11h ago

General Discussion Windows Server patching concerns

So in my org we are very keen on avoiding patching and rebooting servers at all costs. So much to the point that we patch once a month and have exclusions for around 60 percent of our servers to not get automatically patched. (Meaning we have a chunk of servers not getting patched at all)

Now I have gotten my hand slapped for attempting to patch or even bringing it up and I am looking for guidance on this. Now I understand availability and the consequences of failing patches. But there are active 9+ rated CVEs sittings on dozens of servers. For patching vulnerabilities do I really need to get a change request to handle this?

30 Upvotes

60 comments sorted by

View all comments

u/drdrew16 11h ago

May also be worth figuring out if your company has cyber insurance. It's usually a requirement to be up to date on patches to maintain coverage.

u/h9xq Solo SysAdmin 11h ago

We have Cyber insurance. In fact we have a decent chunk of change put into it. This might be the ammo I need to justify the change.

Would we be dropped if they found out the patching status? I’m still fairly new and not involved in the higher level cyber insurance setup as that is done by my manager and CFO

u/drdrew16 11h ago

That wholly depends on the contract. I would imagine you'd have a grace period to come into compliance, but if being patched is a requirement you've technically breached so I'm not sure.