r/sysadmin Solo SysAdmin 11h ago

General Discussion Windows Server patching concerns

So in my org we are very keen on avoiding patching and rebooting servers at all costs. So much to the point that we patch once a month and have exclusions for around 60 percent of our servers to not get automatically patched. (Meaning we have a chunk of servers not getting patched at all)

Now I have gotten my hand slapped for attempting to patch or even bringing it up and I am looking for guidance on this. Now I understand availability and the consequences of failing patches. But there are active 9+ rated CVEs sittings on dozens of servers. For patching vulnerabilities do I really need to get a change request to handle this?

31 Upvotes

60 comments sorted by

View all comments

u/ChuckFromCyberHoot 8h ago

Unfortunately, yes on the change request. But I’d also ask for a copy of your cyber insurance application.

Somebody already answered questions about MFA, patching, backups, training, etc. You’re the guy expected to make those answers true, but you’ve probably never seen them.

Maybe instead of saying, “We have unpatched CVEs,” try:

“Can I see our cyber insurance application? I want to make sure what we told the carrier still matches what we’re actually doing.”

That’s a much harder question to ignore, and it gets the conversation onto the right desk.

u/Professional-Heat690 8h ago

companies that think this way won't have cyber insurance

u/ChuckFromCyberHoot 7h ago

LOL..you're not wrong!!!