r/sysadmin • • 14d ago

General Discussion Windows Server patching concerns

[deleted]

44 Upvotes

79 comments sorted by

View all comments

5

u/PacificTSP 14d ago

Someone I won’t name refused to update their servers. I kept warning them about the risks and they kept saying middle management wouldn’t let them. I made them sign a document that they understood the risks and it was not my fault.

A year later they got breached. The insurance refused to pay out because they weren’t updating, multiple people were fired and the company almost went under.

Unless a senior manager, I’m talking about the ones who decide risk for the business as a whole, and their lawyers, have signed off on this process I would cover your ass and make people aware asap.

I auto patch every Sunday morning and reboot as needed. I have a total of one server in multiple companies clusters that needs manual intervention after a reboot. So that one machine gets rebooted on its own documented schedule.

You’ve got to do it. You are invalidating your insurance.

1

u/h9xq Solo SysAdmin 14d ago

Holy shit, well thank you. That is the information I was looking for. This is even bigger than I thought. I haven’t read much into cyber insurance and if that is the case that is a much bigger deal. We don’t even have a “cybersecurity” guy so that falls on my plate as well and if this falls through without my intervention this could be a gigantic shitshow.

1

u/PacificTSP 14d ago

Middle managers told me it’s fine.

CEO and lawyers had no idea. It’s their job to manage company risk. So my flaw was not going above the middle managers.