There is a version of cyber security that gets all the attention. Sophisticated adversaries, novel techniques, the kind of thing that makes the news. It is genuinely interesting and it is almost never what happens to a New Zealand business.
What happens to a New Zealand business is that something ordinary was left switched on for years, and somebody found it.
We recently ran a security sweep across a large fleet of Windows machines. Not a penetration test, nothing clever. Just a systematic look at what each machine actually had enabled, compared against what it should have. I want to share the shape of what came back, because none of it will surprise anyone technical, and all of it is the sort of thing a business owner never gets told.
Legacy protocols nobody meant to leave on
The single largest category of finding was old file-sharing protocols still enabled on machines that have no need for them. This is technology from the 1980s, formally deprecated years ago, with well-documented weaknesses that have been used in some of the most damaging attacks of the last decade.
It was not enabled deliberately. It was enabled because a printer needed it in 2015, or because a machine was built from an image that had it on, or because it came across in an upgrade and nobody thought to look. Once it is on, nothing ever reminds you it is there. It causes no errors and breaks nothing, right up until it is the way in.
Turning it off is usually straightforward. Knowing it is on is the hard part, and that requires somebody to go and look, machine by machine, which is not a thing that happens by accident.
Machines past their end of life
A meaningful number of devices were running versions of Windows that no longer receive security updates. Every one of them worked perfectly. That is the trap. A machine past end of life does not slow down, does not warn the person using it, and does not stop doing its job. It simply stops receiving fixes, while the list of publicly known ways to attack it keeps growing.
These are rarely anyone's main computer. They are the machine in the workshop that drives a piece of equipment, the terminal at reception, the old server that runs one application nobody wants to touch. Each has a good reason for still being there, and collectively they are the softest part of the estate.
I wrote about this at the time Windows 10 support ended, and the pattern has held: the risk is not the machines people think about, it is the ones they have stopped thinking about.
Weak policy where it matters most
The finding I liked least was on the servers that run the virtual machines. Several were not joined to the central directory, which means their local accounts are managed individually rather than centrally, and several had no minimum password length enforced at all.
Think about what that means in practice. The host that runs a dozen virtual servers, holding the systems the business depends on, protected by a local password with no enforced standard, on an account that is not covered by the central policy anyone would point to if you asked how the business handles passwords.
Nobody decided this. It is what happens when infrastructure is stood up quickly under pressure, works correctly, and is never revisited because it never causes a problem.
The dangerous configuration is never the one that breaks. It is the one that has worked flawlessly for six years while quietly being wrong.
Why this keeps happening
None of these findings required skill to discover. They required someone to systematically look, which is a different and much rarer thing.
Day-to-day IT is demand-driven. Something breaks, someone reports it, it gets fixed. That model handles everything visible and, by construction, handles nothing invisible. An old protocol quietly enabled generates no ticket. A machine past end of life generates no ticket, right up until it generates a very large one.
The second reason is that the answer is unglamorous. There is no product to buy here. It is a list, worked through methodically, mostly consisting of switching off things that should not be on. It is easier to sell and easier to approve a new security tool than a fortnight of somebody carefully turning things off, even though the second one usually reduces more risk.
What to do with this
You do not need a fleet sweep to start. You need three answers, in writing, from whoever looks after your IT.
Which machines in the business are running software that no longer receives security updates, and what is the plan and date for each. Are legacy file-sharing protocols enabled anywhere, and if so where and why. And do the servers and hypervisors that run the business fall under the same account and password policy as everyone else, or do they have local accounts that sit outside it.
Three questions, and the quality of the answers tells you a great deal. Clear, specific answers with dates mean somebody is genuinely looking. Vague answers are not a scandal, they are just an accurate picture of a demand-driven model, and they tell you where to start.
The honest summary
The most useful security work I know of is rarely the most interesting. It is a methodical inventory of what is actually running, compared against what should be, with someone accountable for closing the gap. It does not photograph well and it does not make anyone feel like they are in a thriller. It is what stops the boring attack that was always the most likely one.
If nobody has done that exercise on your estate, our security assessment is exactly that, and we will give you the list whether or not you do anything else with us. You can also read how we handle this on an ongoing basis as part of managed IT.
