CIO Brief: The Hidden Cost of Keeping Exchange On-Prem
Retrospective: this article looks back at events from March 2021, written in 2026 with the benefit of hindsight.
The short version: In 2021, attackers exploited flaws in Microsoft Exchange email servers that companies ran themselves, compromising tens of thousands of organizations within days. Companies whose email ran in Microsoft's cloud weren't affected by those flaws.
The hidden cost of on-premises email
Running your own email servers means patching them — fast — every time a critical flaw appears. Between 2021 and 2022, there were three major waves of Exchange Server attacks. Each required emergency patching, hunting for intruders, and sometimes rebuilding servers.
The business impact
- Data theft from email.
- Ransomware launched from compromised servers.
- Staff time for emergency patching and investigation, often over nights and weekends.
- Hidden exposure from "leftover" hybrid servers kept after moving to the cloud.
Questions to ask your team
- Do we still run any Exchange servers, including "hybrid" or management servers?
- How quickly were they patched during the last emergency?
- What would it take to retire them?
What good looks like
Email in Exchange Online, the last on-premises Exchange server retired where Microsoft supports it, and any remaining servers patched quickly, isolated from the internet and monitored.
The decision
If you still run Exchange servers, ask for a cost-benefit comparison of retiring them. Include staff time spent on emergency patches — it often settles the question.
- ProxyLogon (Mar 2021): Exchange Server Zero-Days Exploited at Massive Scale Incident Teardowns
- How to Retire On-Premises Exchange or Harden the Hybrid Server You Must Keep How-To & Hardening
- Detecting Exchange Server Exploitation: Defender XDR and Sentinel Hunting Queries Detection & Response