How to Build an Emergency Patching Process for Internet-Facing Servers
Retrospective: this article looks back at events from August 2021, written in 2026 with the benefit of hindsight.
When a critical vulnerability is exploited in the wild, normal monthly patching is too slow. Here is how to build an emergency patching process for internet-facing servers.
Step 1: Know what is internet-facing
Maintain an inventory of systems exposed to the internet: email servers, VPNs, web servers, remote access gateways, file transfer appliances. Use external attack surface tools (such as Microsoft Defender External Attack Surface Management) or regular external scans to confirm it.
Step 2: Define triggers
Emergency patching applies when a vulnerability is:
- Listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, or
- Rated critical with public exploit code, and
- Present on an internet-facing system.
Step 3: Set the SLA
Common targets: mitigation within 24–48 hours, patch within 72 hours. If you can't patch, apply vendor mitigations or take the system offline.
Step 4: Pre-approve the process
Agree in advance with leadership and change management that emergency patches can bypass normal change windows with notification. Waiting for a weekly change board defeats the purpose.
Step 5: Run the playbook
- Confirm exposure and version.
- Apply vendor mitigation immediately if available.
- Snapshot or back up.
- Patch and verify the version.
- Hunt for compromise indicators published by the vendor or CISA.
Step 6: Communicate
Notify leadership of status and residual risk daily until closed.
Step 7: Review
After each event, measure time to mitigate and time to patch. Improve the slowest step.
- ProxyShell (Aug 2021): Exchange Server Exploited Again Incident Teardowns
- Detecting Exchange Server RCE: Defender XDR and Sentinel Hunting Queries Detection & Response
- CIO Brief: Repeated Exchange Zero-Days — A Signal to Move to the Cloud CIO Briefings