Earlier quoted context omitted.
Do you know how many versions of how many operating systems across how many different platforms and products my company uses? Hundreds of variations, maybe thousands. Only a few groups have a solid handle on regular patching, and that's because of how hyper-standardized their systems are. Even if an OS has automatic patching, you can't just immediately apply patches without going through an SDLC and QC process. And n…
> Do you know how many versions of how many operating systems across how many different platforms and products my company uses? What OSes besides Windows, macOS, Linux, Solaris, AIX, HP-UX, z/OS, mobile (Andriod, iOS)? SCADA stuff perhaps? And how many of those operating systems are targeted by worms and ransomware? I know when I used to admin Solaris and IRIX machines we were worried a lot less about attacks than th…
Now multiply that times 1,000 different combinations of versions of Windows, applications, networks, platforms, and so on.
You're not just patching "servers", anyway. You're patching bare metal machines, hypervisors, AMIs, container images, software packages, plugins, network applications, security policies. Often vendor platforms don't even have a patch available so you have to implement a custom workaround, if one exists.
One could write an entire book about this subject. Please believe me, it's not simple.