EXPERT RESPONSE
I think a lot of new administrators or, at least, administrators opening doors in new environments, overlook the importance of patch management and Windows Update management from the beginning. You can harden Windows systems against unknown threats, but you also need to keep the items you're guarding completely up to date against the potential vulnerabilities inherent in software.
There are two demons here: In smaller companies, the small number of systems means that it's easy to forget to update; but in larger companies, the need for an automated patch management and deployment system can shift patching down the priority list.
There is always something more glamorous to do than visit Windows Update, but after your basic network security is covered, there's little that is more important.
|