CIO Brief: Repeated Exchange Zero-Days — A Signal to Move to the Cloud
Retrospective: this article looks back at events from August 2021, written in 2026 with the benefit of hindsight.
The short version: In 2021, a second wave of attacks hit company-run Microsoft Exchange email servers, months after the first. Patches had been available for months. Repeated emergencies like this are a signal that running your own email servers may cost more than it's worth.
The pattern
- March 2021: ProxyLogon, tens of thousands of servers compromised.
- August 2021: ProxyShell, exploited for ransomware.
- September 2022: ProxyNotShell, another emergency.
Each wave required emergency patching, investigation and, for some organizations, rebuilding servers and notifying customers.
The business impact
- Breach and ransomware risk concentrated on a single, internet-facing system.
- Recurring unplanned work for IT teams.
- Opportunity cost of time spent maintaining a commodity service.
Questions to ask your team
- How much staff time did Exchange emergencies cost us in the past two years?
- What on-premises Exchange servers do we still run, and why?
- Can we retire them now that Microsoft supports removing the last hybrid server?
What good looks like
Email fully in Exchange Online, on-premises servers retired, and IT time redirected to higher-value work.
The decision
Ask for a plan and date to retire your remaining Exchange servers, or a clear explanation of why you can't. Repeated emergencies are expensive.
- ProxyShell (Aug 2021): Exchange Server Exploited Again Incident Teardowns
- How to Build an Emergency Patching Process for Internet-Facing Servers How-To & Hardening
- Detecting Exchange Server RCE: Defender XDR and Sentinel Hunting Queries Detection & Response