Microsoft 365CIO BriefingsRetrospectives

CIO Brief: The Hidden Cost of Keeping Exchange On-Prem

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from March 2021, written in 2026 with the benefit of hindsight.

The short version: In 2021, attackers exploited flaws in Microsoft Exchange email servers that companies ran themselves, compromising tens of thousands of organizations within days. Companies whose email ran in Microsoft's cloud weren't affected by those flaws.

The hidden cost of on-premises email

Running your own email servers means patching them — fast — every time a critical flaw appears. Between 2021 and 2022, there were three major waves of Exchange Server attacks. Each required emergency patching, hunting for intruders, and sometimes rebuilding servers.

The business impact

  • Data theft from email.
  • Ransomware launched from compromised servers.
  • Staff time for emergency patching and investigation, often over nights and weekends.
  • Hidden exposure from "leftover" hybrid servers kept after moving to the cloud.

Questions to ask your team

  • Do we still run any Exchange servers, including "hybrid" or management servers?
  • How quickly were they patched during the last emergency?
  • What would it take to retire them?

What good looks like

Email in Exchange Online, the last on-premises Exchange server retired where Microsoft supports it, and any remaining servers patched quickly, isolated from the internet and monitored.

The decision

If you still run Exchange servers, ask for a cost-benefit comparison of retiring them. Include staff time spent on emergency patches — it often settles the question.

proxylogon impactProxyLogon2021

More on this story