This is a Hyper-V hypervisor host on a private VLAN three layers behind the internet and two layers behind the users locked in a room with no console access other than via an ILO card on yet another VLAN.
There has only been one KB which infers a security problem and that has had alternative mitigation put in place.
Not rebooting your server doesn't imply incompetence or disregard to security.
Only ones that affect the network surface footprint, so none here as it's on a private VLAN.
I assume that "private VLAN" means it isn't exposed to potential external attack.
Patching servers is just good practice. As is designing a system that can handle rebooting individual servers without user-facing downtime.
b) They won't download anything wrong. There's no route to the internet for this machine.
c) They won't visit any web sites. There's no browser on the machine. This is a core profile windows server installation.
Don't assume that we don't know what we're doing. We have 500ish Windows Server machines floating around.
It's good that you've managed to perfect the hiring process to the point you have zero risk of internal fraud or malice.
Nowhere!
What does that have to do with security updates and reboots?
Nothing!