What to Do When You Can’t Patch Windows Server 2003 — Legacy Systems Strategy
Every CISO has one. A legacy server on end-of-life software that a critical process depends on. The vendor won’t support it. The app won’t migrate. The cost feels too high — until ransomware decides for you.
Layered Mitigation When You Can’t Patch
At a major South African statutory public entity, we found scores of production servers on unsupported platforms. We couldn’t patch them traditionally. Instead, we built layered mitigation:
- Network segmentation to isolate legacy systems
- Host-based intrusion detection for those specific OS versions
- Application whitelisting to block unauthorised execution
- Formal risk acceptance with compensating controls documented
We patched 512 of 643 production servers. For the rest, we bought time for a proper upgrade programme. 45/45 test servers patched, 100% CAB-approved.
“Legacy doesn’t mean hopeless. It means you need a deliberate strategy — not wishful thinking.”
Part of the Secure & Patched series. View the full campaign.