I work for a financial institution and I've been in IT for only like a 1.5 years, so I'm still learning this stuff. We have regular IT audits and such and now that I'm the only IT guy, I got to sit with the auditor and helped him fully scan our environment with Nessus. Results came back for around 150 systems and there was something like 500 vulnerabilities, 80% of which were missing critical Windows OS patches.
I was pretty shocked because I always stay on top of monthly Windows updates. The auditor says, "well, it says there's some here from as far back as August of 2016" in a condescending tone. I was pretty pissed but just accepted it and let him finish the scan and then I got the full assessment a few weeks later, which I'm now combing through.
So, first of all, I'm wondering.... don't Windows OS updates supersede past updates? --- meaning, if I miss some critical Windows OS updates for a month or two, but then I get all the critical updates for the following months all the way up until current time, then those newer updates take the place of those missing updates, meaning I no longer have to worry about those missed patches, correct? I assume the only thing Nessus is seeing is that those individual KB's are not listed in the Windows registry, and therefore flags them as not installed, despite the fact that it doesn't matter since all updates after those have been faithfully updated.
Other than that, I was thinking, we currently don't use WSUS because when I came on my job here, they had a 3rd party patch and software management tool called DesktopCentral by ManageEngine. That's how I do updates now, and I can view all the missing updates for every system and all I see are the missing updates for this month and a few for last month (machines that were turned off for weeks).
Additionally, we used to have Kaspersky 8 AV installed which was so unbelievably fucked up... I think it was even managing our Windows updates at one time. Then when I ripped it out of our environment, I had to use their special uninstall tool in safe mode.. so God knows how that messed things up. Some of my servers and computers that used to have Kav can't even run Windows update themselves.
Anyway, I'm hoping someone here has had a similar thing happen so you can maybe give some advice... otherwise, I'll just be knee-deep in manually patching super old updates.