I can hear the screams from here. “Of course you should patch!”.
Well, yes, I think we’re all in agreement that patching servers is a worthwhile exercise, certainly in the wake of Wannacry and Petya.
But for me, the debate generates as many questions as it does answers.
Over the weeks, I’ve had numerous responses to my opinions on patching;
“Everyone should be patching”
“Don’t you think all businesses need to patch their servers?”
“Are you saying it’s ok to not patch servers?”
“Eh, you must be patching your servers no matter who or what you are!”
Let me try and address some of the fundamental questions with regards to patching, as I see them.
What Should I Patch?
The simplistic answer would be ‘everything’. In reality, that may be entirely unrealistic. Servers, endpoints, firewalls, routers, switches, applications, the list is almost endless. As a business, you need to define what is most important to you. The answer can’t simply be ‘everything’.
For instance, perhaps you have a limited security or IT support team and you have defined that your patching capability only stretches to servers concerned with personal data.
That’s a risk you have to accept. Perhaps your business has accepted that service uptime is more valuable to the business than patching a whole server estate every week at cost £X.
I’m aware of companies that patch their Windows servers religiously once a week on Patch Tuesday. I’m also aware of companies that simply don’t patch very much at all (and I don’t just mean companies who were victims of some of the latest attacks).
Is It Ok Not To Patch?
Here’s where I am sure I will ruffle a few feathers. As a rule of thumb, patching should absolutely be in your security strategy. I think we can all agree on that. But the specifics of how you go about doing it and what you prioritise, define what and how you patch at any given time (and your patching policy is only ever a point-in-time and often not adhered to anyway).
Of course there are occasions when it’s ok to not patch. It’s ok to not do a thousand things in your business if you have differing levels of risk, budget, expertise and time. It depends on what it is you have chosen not to patch and why.
Say for example you have 10,000 Windows servers in your DC. Your capability only allows you to patch those servers for high criticality security vulnerabilities on an ad-hoc or infrequent basis. It means you will be making tough decisions not to patch other things.
Asking whether it’s ok to not patch servers is the same as asking whether it’s ok to not have endpoint protection, or next-gen firewalls, or network intrusion capability, or phishing protection, or hundreds of other things that would doubtless improve your security capability and posture (and reduce risk, there’s that ‘R’ word again!).
As I type this, my reminder to update the latest patches for my laptop has popped up. I clicked “remind me again tomorrow”, because I’m busy writing this. So I just made the call at this exact moment that it’s ok not to patch. See where I’m going with this?
There Is No Right Answer
My fundamental issue with many things in security is that there is no right answer. Merely stating “you must patch” is far too simplistic and does nothing to address a myriad of potential problems, risks or priorities.
You should patch what you define as important, as often as you deem it to be necessary, aligned to the business you work for and the risks that business faces.
Patching has never been the ‘holy grail’ for me, as I’ve stated publicly on numerous occasions. If you have layered security, built around a strategy addressing specific business-risk, patching can be an important addition to that. But it is only that; an addition.
Frankly, as security professionals, we should be challenging the more old-school ways of thinking and defining new ways of dealing with old problems.
So, to patch or not to patch? It’s over to you!






