IT Cyber Security For Our Financial Services Client

Managed Print Provider

Since January 2020, Windows 7 Operating System is not supported by Microsoft anymore. This means any PCs still running the software no longer receive security updates, software updates, or technical support for any issues.

Many small businesses are not aware of the potential impact and implications of not running the latest software releases. Their approach? “If it ain’t broke, don’t fix it”. Unfortunately, this mindset will cause systems to be compromised at some point as there is no further maintenance available to protect their operating system from cyber attacks if they still use Windows 7.

On the upside, this Windows 7 end of life status has incentivised some of Espria’s clients to undertake a review of their IT systems. 

Our client’s issue : an IT system vulnerable to threats

One of our clients has used the cessation of the Windows 7 platform to look at their complete IT infrastructure and ensure that it is as secure and reliable as it can be.

The team here at Espria performed an audit of their IT systems.

Several areas in need of improvement were identified, including:

    • Multiple anti-virus products being used throughout the organisation but also on some machines!
    • Different versions of Microsoft Office being utilised, including Windows 2007, and desktops running multiple Windows Operating Systems
    • Windows Updates not being applied to all machines
    • Large levels of spams received on a daily basis
    • Many web browsers in use
    • Administrative rights granted to users on their desktops
    • Simple passwords used and shared amongst all users
    • Remote user laptops only secured by simple passwords
    • All users provided with remote access to the server, whether it was actually required by the business or not

Laughing people

Our solutions : new processes

Whilst the above was not causing any problems from an operational perspective, clearly this is not best practice as to how IT systems should be maintained.

Through the introduction of new processes and a small investment in hardware and software products, we were able to address each of these concerns within a short space of time with minimal disruption to the userbase:

  1. Whilst the above was not causing any problems from an operational perspective, clearly this was not best IT practice.

    Through the introduction of new processes and a small investment in hardware and software products, we were able to address each of these concerns within a short space of time with minimal disruption to users:

    1. We introduced a modern, anti-virus solution with central management, update services and reporting.
    1. We migrated all users to Office 365, ensuring that the same version of the Office product was used and automatic updates were carried out.
    1. We standardised Windows 10 operating system across all machines, performing in-place upgrades where possible or machine replacements where hardware was not suited to the new environment.
    1. We configured Windows 10 to perform updates automatically in the background to ensure that all users are on the latest security release.
    2. With the migration to Office 365, this has automatically provided a level of spam protection : only required emails are allowed to go through.
    1. We agreed with the business that only 2 Web Browsers should be used and removed non-supported products. We configured automated updates to ensure that the latest product versions are always present.
    1. We removed administrator rights from all users to ensure that their desktop environment cannot change so that no additional software can be installed.
    1. We introduce complex passwords to ensure a minimum level of characters, as well as password change enforcement every 30 days.
    1. We enabled encryption services on remote laptops prior to Windows starting so that the data cannot be accessed without an initial key being entered to allow the machine to start.
    1. We reviewed all remote user access to ensure it was restricted to only those that need it. In addition, a secure Firewall with VPN Services was installed so that remote users have to authenticate against the Firewall before they are given access to the network.

If your business is not up to date with IT security, your systems are at risk of being compromised.
So it’s imperative you remain a step ahead with your cyber security.

Dene, our Expert

The Results

These steps have led to an improved IT offering for the business’ customers while ensuring the company is better protected against cyber attacks.

We will continue to review the installation every 6 months to ensure that the levels of protection and policies used remain adequate.

Reveal areas that need proactive, defensive or collaborative resource

One of our experts will review your current data risk, examine current governance and security controls.

Rectangle111

What’s in this article

    We’re experts in building sustainable IT infrastructure that can scale to your businesses needs.

    You may be interested in

    The Hidden Costs of Printing: How Managed Print Services Reduce Business Waste

    Introduction For many organisations, printing is viewed as a routine operational expense. Printers are purchased, toner is replaced when needed, and documents continue to flow through the business without much scrutiny. However, the true cost of printing extends far beyond paper and ink. Unmanaged print environments often create hidden expenses through inefficient device usage, excessive energy consumption, IT support demands, security risks, and employee downtime. These costs can accumulate significantly over time, impacting productivity and profitability. This is particularly relevant as businesses seek to optimise operations, reduce waste, and improve sustainability while controlling expenditure. Whether…

    Read the article

    Can Your Business Actually Recover? The Operational Resilience Question Most SMEs Cannot Answer

    Operational resilience is not a technology problem. It is a business problem. And until boards and leadership teams own it, no amount of IT investment will be enough. The Gap Between Confidence and Reality Most organisations believe they are more resilient than they are. The backups are running. The antivirus is licensed. The IT team knows what they are doing. That confidence, in our experience, rarely survives first contact with an actual incident. The question is not whether your systems are protected. The question is whether your business can keep delivering its most important services…

    Read the article

    Integration of Sophos and Microsoft for enhanced threat intelligence

    Why the Sophos–Microsoft Partnership Matters – Especially for Education, Financial Services and Legal Organisations

    For most organisations today, Microsoft is the foundation of how you operate and on top of this there is also a requirement for regulatory compliance and operational resilience. Whether it’s Microsoft 365 for collaboration, Teams for communication, or Azure for infrastructure, these platforms sit at the heart of day-to-day business. But for sectors like Education, Financial Services, and Legal, that reliance comes with heightened risk, and responsibility. These organisations are not only prime targets for cyber attackers, they are also subject to strict regulatory, data protection and governance obligations. That’s why the partnership between Sophos…

    Read the article

    Checklist marked passed next to cracked cyber shield over network, illustrating compliance vs cyber resilience.

    Why Cyber Resilience Can’t Be Audited Once a Year: Lessons from the UK Cyber Action Plan

    Moving from box‑ticking compliance to real‑world cyber readiness  Written by Richard Puckey  Cyber security has a confidence problem  For years, many organisations have taken comfort in annual cyber audits, certifications and compliance checklists. Pass the audit, tick the box and move on. On paper, everything looks secure.  The problem? Cyber threats don’t operate on an annual cycle.  The UK’s Cyber Action Plan is a clear signal that this approach is no longer enough. It challenges businesses to rethink cyber security not as a periodic compliance exercise, but as a living, breathing capability and culture that must stand up…

    Read the article

    A person sitting in a comfortable, modern living space while speaking on the phone, representing a tenant reaching out to a housing association’s customer service team. The environment conveys everyday life and the importance of accessible, responsive communication.

    How Housing Associations Can Transform Tenant Experience with Modern OmniChannel CX

    Written by Russell Hallam, CX Consultant at Espria In today’s housing landscape, tenants expect fast, seamless and personal interactions, no matter which channel they use. Phone, digital, web chat, video, email, messaging: it all needs to feel connected, consistent and effortless. But for many teams, the reality is different. Disconnected systems slow down responses, important information is buried across platforms and frontline staff shoulder the burden of manual processes.  At Espria, we’ve helped housing associations modernise their customer experience with cloud-enabled omnichannel solutions designed for efficiency, visibility and compliance. Here’s what that looks like in action. 1. RealTime CRM Integration: Context at the Exact Moment You Need It  When a tenant calls,…

    Read the article

    Silhouette pointing to a digital padlock, indicating cyber security

    Elevating Human Risk Management: A Boardroom Must for Cyber Resilience in 2026

    Written by Richard Puckey As organisations move through 2026, cybersecurity has firmly established itself as a core business risk. Regulatory scrutiny is increasing, threat actors are more capable than ever and the operational and reputational impact of cyber incidents continues to escalate. In response, businesses have invested heavily in security technology such as advanced detection platforms, zero trust architectures, AI-driven analytics and automated response capabilities. These controls are considered essential and non-negotiable. However, are they sufficient? The reality facing security leaders today is clear, the majority of material cyber incidents still involve a human decision…

    Read the article