IT Cyber Security For Our Financial Services Client

Managed Print Provider

Since January 2020, Windows 7 Operating System is not supported by Microsoft anymore. This means any PCs still running the software no longer receive security updates, software updates, or technical support for any issues.

Many small businesses are not aware of the potential impact and implications of not running the latest software releases. Their approach? “If it ain’t broke, don’t fix it”. Unfortunately, this mindset will cause systems to be compromised at some point as there is no further maintenance available to protect their operating system from cyber attacks if they still use Windows 7.

On the upside, this Windows 7 end of life status has incentivised some of Espria’s clients to undertake a review of their IT systems. 

Our client’s issue : an IT system vulnerable to threats

One of our clients has used the cessation of the Windows 7 platform to look at their complete IT infrastructure and ensure that it is as secure and reliable as it can be.

The team here at Espria performed an audit of their IT systems.

Several areas in need of improvement were identified, including:

    • Multiple anti-virus products being used throughout the organisation but also on some machines!
    • Different versions of Microsoft Office being utilised, including Windows 2007, and desktops running multiple Windows Operating Systems
    • Windows Updates not being applied to all machines
    • Large levels of spams received on a daily basis
    • Many web browsers in use
    • Administrative rights granted to users on their desktops
    • Simple passwords used and shared amongst all users
    • Remote user laptops only secured by simple passwords
    • All users provided with remote access to the server, whether it was actually required by the business or not

Laughing people

Our solutions : new processes

Whilst the above was not causing any problems from an operational perspective, clearly this is not best practice as to how IT systems should be maintained.

Through the introduction of new processes and a small investment in hardware and software products, we were able to address each of these concerns within a short space of time with minimal disruption to the userbase:

  1. Whilst the above was not causing any problems from an operational perspective, clearly this was not best IT practice.

    Through the introduction of new processes and a small investment in hardware and software products, we were able to address each of these concerns within a short space of time with minimal disruption to users:

    1. We introduced a modern, anti-virus solution with central management, update services and reporting.
    1. We migrated all users to Office 365, ensuring that the same version of the Office product was used and automatic updates were carried out.
    1. We standardised Windows 10 operating system across all machines, performing in-place upgrades where possible or machine replacements where hardware was not suited to the new environment.
    1. We configured Windows 10 to perform updates automatically in the background to ensure that all users are on the latest security release.
    2. With the migration to Office 365, this has automatically provided a level of spam protection : only required emails are allowed to go through.
    1. We agreed with the business that only 2 Web Browsers should be used and removed non-supported products. We configured automated updates to ensure that the latest product versions are always present.
    1. We removed administrator rights from all users to ensure that their desktop environment cannot change so that no additional software can be installed.
    1. We introduce complex passwords to ensure a minimum level of characters, as well as password change enforcement every 30 days.
    1. We enabled encryption services on remote laptops prior to Windows starting so that the data cannot be accessed without an initial key being entered to allow the machine to start.
    1. We reviewed all remote user access to ensure it was restricted to only those that need it. In addition, a secure Firewall with VPN Services was installed so that remote users have to authenticate against the Firewall before they are given access to the network.

If your business is not up to date with IT security, your systems are at risk of being compromised.
So it’s imperative you remain a step ahead with your cyber security.

Dene, our Expert

The Results

These steps have led to an improved IT offering for the business’ customers while ensuring the company is better protected against cyber attacks.

We will continue to review the installation every 6 months to ensure that the levels of protection and policies used remain adequate.

In this post

    You may be interested in

    Outgrowing your MSP; businesses need a provider that scales with their growth

    To stay competitive, business leaders must align with MSPs that deliver strategic value, drive innovation, and support to scale. Now firmly into 2025, it’s becoming clear what the year has in store for the IT landscape. For SMBs, the message is clear: business growth must be matched with smarter, more scalable managed services. The demand for cyber-resilient, cloud-first and AI-integrated solutions is no longer a forecast – it’s a reality already shaping business priorities. According to leading global technology market analyst firm Canalys’ MSP Trends 2025 report, the MSP model is transforming under growing pressure…

    Read the article

    End of windows 10 support signal urgent action needed from UK organisations as cyberattacks continue to rise

    Recent breaches at major UK retailers, combined with the approaching end of life of Windows 10, highlights a critical moment for IT resilience planning The recent wave of cyberattacks targeting major UK retailers has highlighted the growing security risks associated with organisations running outdated systems and applications and maintaining weak identity verification protocols. These incidents—particularly those involving Marks & Spencer and the Co-Op—have starkly exposed how vulnerable legacy infrastructure and insufficient access controls can be.  In both cases, attackers successfully posed as legitimate employees and manipulated IT help desks into resetting internal passwords, ultimately gaining…

    Read the article

    UK SMEs must fortify their cybersecurity against geopolitical risks, says Espria

    A recent Sky News investigation highlighted an uptick in cyberattacks tied to the Iran conflict that are targeting businesses across multiple sectors. Speaking at the NATO Summit, Prime Minister Sir Keir Starmer urged UK businesses, regardless of size or sector, to prioritise cybersecurity and ‘take immediate steps to review and strengthen their defences.’ While the warning is timely in tone, businesses are already becoming targets of politically motivated cyberattacks, emphasising the need for heightened vigilance. “As tensions spread globally, threat actors will continue to exploit digital vulnerabilities, and neutral businesses may be caught in the…

    Read the article

    Windows 10

    End of windows 10 support signal urgent action needed from UK organisations as cyberattacks continue to rise

    End of windows 10 support signal urgent action needed from UK organisations as cyberattacks continue to rise

    Read the article

    Why Businesses Should Invest in ESG: Lessons learned by Espria

    In today’s competitive landscape, Environmental, Social and Governance (ESG) performance is no longer just a “nice to have”—it is a critical business imperative. Companies that prioritise ESG are better positioned for long-term success, risk mitigation, and reputation enhancement. Today’s world demands more from companies than just financial performance. Customers want transparency. Employees want purpose. Investors want resilience. ESG helps businesses manage risk, seize new opportunities and build trust with the people who matter most. It is how you can stay competitive, stay responsible and stay relevant in a fast-changing world. A powerful case study of…

    Read the article

    The Importance of Compliance and Security: Complementary Forces in Today’s Business World

    In today’s rapidly evolving business landscape, compliance and security have become paramount. These two elements, often perceived as hurdles, are in fact complementary forces that drive business success and sustainability. Understanding their importance and how they work together can transform them from perceived blockers into enablers of growth and innovation. The Role of Compliance Compliance refers to adhering to laws, regulations, standards and ethical practices relevant to an industry. It ensures that a company operates within the legal framework and maintains its reputation. Compliance is not just about avoiding fines and legal issues; it is…

    Read the article