@GossiTheDog No critical infrastructure should run 3rd party services that perform unsupervised automatic remote updates. The OS is irrelevant.
Also, not every server needs to have ends point protection. (For example, the kiosk displaying arrivals and departures.)
@tob @GossiTheDog Things like that should be run from a fixed read-only system image loaded over the network.
@mansr @tob @GossiTheDog ... over the network, like The Internet?
@geert @tob @GossiTheDog The local network, obviously. Bonus points if it isn't connected to the internet at all.