Thursday May 14, 2015

Set your alarm, 14th July 2015 is a significant date. After this, Microsoft will no longer issue updates for Windows Server 2003. What does this mean? Any server still running this level of Windows will become an ever widening doorway with a red carpet rolled out for hackers and malicious software to enter your organisation's IT environment.

What happens if you do nothing? Perhaps you don't have budget or business approval for the upgrade and inherent outages? Perhaps your servers on this level of Windows are nearing end of life and you think there's no point in upgrading? The danger is that the damage from a hacking attack or computer virus attack may spread much further. What if your Windows Server 2003 hardware is just the way in for a virus, like a secret door into a well-defended castle? Would you like to take the risk of discovering the impact once it's inside the firewall?

What can you do? There is still time to put things right. Information security is a board level agenda item, and you will need to escalate if you haven't got the budget or approval to migrate off Windows Server 2003. Of course, the change will need to be carefully planned and managed, and not rushed.

If you are a head of department or a board member, ask the IT manager and/or IT director to report if any servers are still on Windows Server 2003. Ask them what applications run on them, and what's the migration plan. Indeed, also ask if there are any servers with an older operating system, and if the organisations PCs all run on a supported level of Windows.

If you've already moved forward from Windows Server 2003, then "congratulations". If you haven't, bear in mind that there is no mercy in a hacking attack or a virus. If you think you can't afford to upgrade, a virus will show no sympathy whatever the nature or size of your organisation.

It is a certainty that vulnerabilities will be found and exposed following the end of support on 14th July 2015. The arms race between hackers and software companies is run at a breathless pace, so it's important to take action before the date to maintain your organisation's information security. Don't open the door and roll out the red carpet to hackers.

distributed by