So at work, we had a small sandbox network for testing one of our applications. It was completely isolated from the Internet - never had a connection, ever under any circumstances. The patchlevel on the OS is WinXP SP1 era, and antivirus? LOL NO.
However, this configuration had to change due to a new feature that depends on the Internets. And we let our new sysadmin connect it up - via our psuedo-public wifi, because we want it to have a direct line to the Internet and not go through the rest of our network, just so we can be sure nothing interacts during the tests. None of us even bothered to think about patchlevel or virus protection, because it's not an issue anywhere else in the enterprise and we'd forgotten this network was in any way special and wasn't pulling automatic updates from our main network (because it's not physically connected to it). Oh. Fuckme.
The senior admin team and I just spent hella overtime de-Confickering the whole thing. The domain controllers for the domain are so bitrotted that it took me a solid FIVE HOURS to install Symantec Endpoint Protection on one of them. I still have to update and clean the secondary DC tomorrow.
Yes, the junior sysadmin bought us beer for not catching it (it WAS on the checklist for connecting any new system to the network. And he DID check it off... Because the wireless bridge he was connecting didn't NEED antivirus or patches, and he didn't think about the network behind it at all)