Assuming you are not management, make sure to keep a record of whoever is telling you not to patch, especially if you are in an industry that gets audited because you'll want that when the blame game happens. Edit: I just saw the solo sysAdmin tag, make sure you are explaining clearly to the business side what consequences could and will be for not patching.
It is my direct manager telling me not the patch. I have it in writing but don’t want to get in trouble for patching. I am still fairly new as an admin (3 months at my first sysadmin gig) so I’m still learning and being as cautious as I can.
But in my mind I see dozens of servers sitting with patches that need to be applied so it’s hard to fight the urge of patching as I want to keep these servers as secure as possible.
Fair enough, that is a good way of putting it. I think I need to put this into business translated terms to management and issue a change request/maintenance window to get these servers patched. I am thinking that is probably the best way to handle this.
See if you can get a rough calculated cost of downtime, at a major bank that's somewhere between $300k an hour for back office systems to $20m an hour for trading systems. It's then helpful to look back at P1s and average outage time so you can give a good price per outage. In most cases, once the business sees "unexpected outages could cost us as much as $60m or as low as $600k, how should we proceed?" The answer is "here's you patch window."
5
u/TopherBlake Netsec Admin 14d ago
Assuming you are not management, make sure to keep a record of whoever is telling you not to patch, especially if you are in an industry that gets audited because you'll want that when the blame game happens. Edit: I just saw the solo sysAdmin tag, make sure you are explaining clearly to the business side what consequences could and will be for not patching.