Vulnerability risks of not upgrading an instance at the expected time?

YenGar
Mega Sage

Hello all, 


I am looking for some guidance/advice or lessons learned when being in the need to postpone a required upgrade. We are currently in the Vancouver release and are required to upgrade to at least the latest Washington release to stay current with the versioning. We've requested an extension before when upgrading to Utah due to resource constraints and now we are in the middle of an org shift and major project that also puts us in a jam to upgrade our instances in time. Our security team wants us to assess the vulnerabilities and risks of requesting an extension and the potential of being exposed to external attacks.

 

I know that ServiceNow will not patch an instance that has been deemed unsupported so of course, that's not ideal, but I'd like to hear from others who have been in this situation. What were things you prepared for during your extension period? How did you handle risks to the instance? Did ServiceNow provide anything during the extension period? Is there really a possibility of the instances being breached? 

 

I'd appreciate any of you sharing your experience and suggestions! 

Thank you!

Yen

0 REPLIES 0