O cliente
Our client is an American multinational with a global presence and operations in dozens of countries.
Its IT team operates on a worldwide scale and is responsible for an estate of thousands of Linux and Windows servers, spread across plants and offices in several time zones.
O desafio
In an operation of this size, patching is not an initiative: it is routine vulnerability management, with deadlines set by security policy and checked in audits. Around 70% of the estate ran Windows, and Microsoft releases its security fixes on the second Tuesday of every month, the well-known Patch Tuesday. In practice, this imposes a monthly cycle that waits for no one: fix published, clock ticking and hundreds of servers to update, starting with the critical ones.
Patches can only be applied outside business hours, in maintenance windows. And here the size of the operation took its toll: each server had a role and served a region of the world, so every window had to be negotiated with the leaders of the affected region, respecting the local time zone. Windows were short and hard to schedule, and when one overran, the impact directly affected the business.
To keep up, each window mobilized around 10 professionals on overtime, deep into the night and often on weekends. The step by step was manual: check the server, back it up, stop the applications, update, reboot, validate and bring the services back, machine by machine. And where a manual step is repeated hundreds of times, there is human error: updates failed over configuration details, rework became routine and every late night carried the risk of yet another overrun window.
A solução
Integrity-UX, a long-standing business partner of the client, was chosen to design and implement the automation of the patching process end to end, covering both worlds of the estate: Windows and Linux.
The design paired the right tool with each role: Altiris handling the Windows estate, which made up most of the environment, Ansible orchestrating patch application on the Linux servers, Red Hat Satellite managing the package life cycle and everything integrated with ServiceNow. An approved change now triggers the automation, and every step that used to be manual became a flow: collecting server information, checking disk space, system backup and image, controlled application shutdown, operating system update, reboot, post-update assessment and restarting services in the right order. When something goes off script, the automation itself opens an incident in ServiceNow, with logging and alerts for the team to follow.

Main challenges
- A heterogeneous estate, with thousands of Linux and Windows servers in several countries;
- Short, non-negotiable maintenance windows, defined by the business operation;
- Critical applications with their own shutdown and restart sequence, such as databases, ERP and printing services;
- Integrating the automation into the change and incident flow already in place in ServiceNow.
Main gains
- The team mobilized per window dropped from around 10 professionals to 2, who now monitor the execution instead of working server by server, with a direct reduction in overtime costs;
- Human failures disappeared from the windows: what used to depend on typing and memory became an automated, tested and repeatable flow;
- Each window got shorter;
- Window overruns ended: what used to run late because of delays or errors simply stopped happening.
From process design to final documentation and knowledge transfer, the project was carried out in phases, with joint validations with the client and delivery within the agreed milestones. Integrity-UX further strengthened a partnership built over the years, with bilingual service and global coverage. Patching in this environment is no longer an event that demands mobilization; it has become routine: predictable, auditable and quiet.



