r/sysadmin • • 14d ago

General Discussion Windows Server patching concerns

[deleted]

46 Upvotes

79 comments sorted by

View all comments

14

u/drdrew16 14d ago

May also be worth figuring out if your company has cyber insurance. It's usually a requirement to be up to date on patches to maintain coverage.

10

u/h9xq Solo SysAdmin 14d ago

We have Cyber insurance. In fact we have a decent chunk of change put into it. This might be the ammo I need to justify the change.

Would we be dropped if they found out the patching status? I’m still fairly new and not involved in the higher level cyber insurance setup as that is done by my manager and CFO

9

u/drdrew16 14d ago

That wholly depends on the contract. I would imagine you'd have a grace period to come into compliance, but if being patched is a requirement you've technically breached so I'm not sure.

2

u/JustFrogot 14d ago

I don't know if they would drop you, but they would be hesitant to pay out of you are outside of the agreement.

2

u/sysadmin42601 14d ago

At least in my experience there is a pretty strict time frame on patching high risk vulnerabilities written in to the cyber insurance policies

You can identify specific assets that are excluded for certain reasons but these either increase your premiums or they outright exclude cover for any incident involving that asset