Aaron Engelsrud

@aaronengelsrud.com

Oracle Ace Alum with 20+ years in IT Management 🖥️ An author & educator dedicated to the fusion of higher ed and IT. Leading at Strategic Education Inc., illuminating the tech world, one lecture at a time.

The Dangerous CVE Usually Needs a Login Unauthenticated vulnerabilities get the headlines and the emergency change windows. The ones that quietly reach critical data often need only a low-privileged account and a user willing to click. Model the interior, not just the perimeter.

Measure Patching in Dates, Not Intentions "We're current within a quarter" is a feeling. Release date, triage date, test apply, production apply—four columns for your last four security releases—is a number. Most teams have never written the table.

The Cheapest Roadmap Intelligence You'll Buy All Year Conference registration costs less than one week of guessing at Oracle's timelines. Roadmap sessions are where release dates that affect your next budget cycle actually get answered—and early pricing deadlines pass quietly.

Advisories Are Revised After You Read Them The July Critical Patch Update has been revised twice since it was published. Patching once against a document that keeps changing isn't a completed task—it's a subscription you have to keep reading.

Knowing Your Release Isn't Knowing Your Patch Level "We're on 8.61" is not an answer to a CVE question. Both fresh PeopleTools vulnerabilities this quarter were release-specific and patch-specific, and only one of those two numbers is usually written down anywhere.

Oracle's Security Calendar Changed and Yours Probably Didn't Critical Security Patch Updates now land monthly, not quarterly—one ships today. If your change calendar still shows four security windows a year, you've built a 30-day lag into every critical fix.

Automation Is a Security Feature Automated builds, automated patching, automated deployments, and automated testing reduce human error. Consistency is one of the strongest security controls you can implement.

PeopleSoft Upgrades Are Getting Easier Selective adoption changed the conversation. Modern PeopleSoft upgrades aren't necessarily multi-year projects anymore. The process is finally catching up to the promise.

The Best Time to Test Disaster Recovery Is Before You Need It Backups are comforting. Restores are confidence. If you haven't tested your recovery process recently, you don't actually know your recovery time objective.

Least Privilege Works in ERP Too Most security incidents don't require hackers. They require excessive permissions. Regular role reviews remain one of the highest-value security activities in PeopleSoft.

Your Internet Gateway Deserves Attention PIA, WebLogic, Integration Broker, Elasticsearch, and Process Scheduler all create attack surfaces. Security isn't a firewall anymore—it's layered architecture.

Security Starts with PeopleTools Many critical security improvements don't arrive in application images—they arrive in PeopleTools. Staying current isn't just about features; it's about protecting your environment.

Quarterly Patching Beats Five-Year Projects Would you rather perform four predictable maintenance events a year or one massive upgrade every five years? Modern PeopleSoft favors incremental change over big-bang projects.

Every PUM You Skip Becomes Technical Debt Skipping updates saves time today but creates larger upgrade projects tomorrow. The organizations with the easiest upgrades are usually the ones upgrading continuously.

When you stop trying to control outcomes and start focusing on removing obstacles, things shift pretty quickly. You realize most teams don't actually need more direction. They just need fewer things getting in their way.

PeopleSoft is less about the technology and more about the history inside it. Every customization tells a story. Every integration solved a problem at some point. You're not just managing a system, you're inheriting decisions.

I noticed something about myself not too long ago… I was cutting people off in conversation more than I realized. Not intentionally, but enough to shape the conversation. People would get to a point, pause for half a second, and I'd jump in.

At some point in every IT career, you realize: The system everyone complains about… is also the system no one wants to be responsible for replacing. That's when you know it’s mission-critical.

Cloud didn't eliminate operational problems. It just changed where they live. You trade hardware issues for configuration issues. You trade capacity planning for cost management. The work doesn't go away. It just evolves.

Up to now, the team has been building momentum with automation, IaC, and observability. Now comes the real challenge: letting go of control. Chapter 5 opens with a DBA pushing back on managed databases. And honestly, it's a fair reaction.

One of the best things a leader can say is: “I don’t know, what do you think?” Not as a deflection, but as an invitation. You'd be surprised how often your team already has the answer.