AI training for Copilot, Claude and OpenAI. Book your slot now +61 3 4803 4915Client PortalRemote Support
Belton IT Nexus
Belton · Run / Protect / Improve / BuildView all services ›
Belton · Knowledge, not gatekeepingResource library ›
Belton IT Nexus · Est. 2004 · Newmarket, AucklandAbout us ›
Home/ Insights/ What we found on a Windows fleet

What we found on a Windows fleet.

We ran a security sweep across a large estate of Windows machines. Nothing we found was exotic. That is exactly the point, and it is why this is worth reading.

Jason AgnewFounder & CEO
Aug 2026Cyber Security
6 minRead

There is a version of cyber security that gets all the attention. Sophisticated adversaries, novel techniques, the kind of thing that makes the news. It is genuinely interesting and it is almost never what happens to a Australian business.

What happens to a Australian business is that something ordinary was left switched on for years, and somebody found it.

We recently ran a security sweep across a large fleet of Windows machines. Not a penetration test, nothing clever. Just a systematic look at what each machine actually had enabled, compared against what it should have. I want to share the shape of what came back, because none of it will surprise anyone technical, and all of it is the sort of thing a business owner never gets told.

Legacy protocols nobody meant to leave on

The single largest category of finding was old file-sharing protocols still enabled on machines that have no need for them. This is technology from the 1980s, formally deprecated years ago, with well-documented weaknesses that have been used in some of the most damaging attacks of the last decade.

It was not enabled deliberately. It was enabled because a printer needed it in 2015, or because a machine was built from an image that had it on, or because it came across in an upgrade and nobody thought to look. Once it is on, nothing ever reminds you it is there. It causes no errors and breaks nothing, right up until it is the way in.

Turning it off is usually straightforward. Knowing it is on is the hard part, and that requires somebody to go and look, machine by machine, which is not a thing that happens by accident.

Machines past their end of life

A meaningful number of devices were running versions of Windows that no longer receive security updates. Every one of them worked perfectly. That is the trap. A machine past end of life does not slow down, does not warn the person using it, and does not stop doing its job. It simply stops receiving fixes, while the list of publicly known ways to attack it keeps growing.

These are rarely anyone's main computer. They are the machine in the workshop that drives a piece of equipment, the terminal at reception, the old server that runs one application nobody wants to touch. Each has a good reason for still being there, and collectively they are the softest part of the estate.

I wrote about this at the time Windows 10 support ended, and the pattern has held: the risk is not the machines people think about, it is the ones they have stopped thinking about.

Weak policy where it matters most

The finding I liked least was on the servers that run the virtual machines. Several were not joined to the central directory, which means their local accounts are managed individually rather than centrally, and several had no minimum password length enforced at all.

Think about what that means in practice. The host that runs a dozen virtual servers, holding the systems the business depends on, protected by a local password with no enforced standard, on an account that is not covered by the central policy anyone would point to if you asked how the business handles passwords.

Nobody decided this. It is what happens when infrastructure is stood up quickly under pressure, works correctly, and is never revisited because it never causes a problem.

The dangerous configuration is never the one that breaks. It is the one that has worked flawlessly for six years while quietly being wrong.

Why this keeps happening

None of these findings required skill to discover. They required someone to systematically look, which is a different and much rarer thing.

Day-to-day IT is demand-driven. Something breaks, someone reports it, it gets fixed. That model handles everything visible and, by construction, handles nothing invisible. An old protocol quietly enabled generates no ticket. A machine past end of life generates no ticket, right up until it generates a very large one.

The second reason is that the answer is unglamorous. There is no product to buy here. It is a list, worked through methodically, mostly consisting of switching off things that should not be on. It is easier to sell and easier to approve a new security tool than a fortnight of somebody carefully turning things off, even though the second one usually reduces more risk.

What to do with this

You do not need a fleet sweep to start. You need three answers, in writing, from whoever looks after your IT.

Which machines in the business are running software that no longer receives security updates, and what is the plan and date for each. Are legacy file-sharing protocols enabled anywhere, and if so where and why. And do the servers and hypervisors that run the business fall under the same account and password policy as everyone else, or do they have local accounts that sit outside it.

Three questions, and the quality of the answers tells you a great deal. Clear, specific answers with dates mean somebody is genuinely looking. Vague answers are not a scandal, they are just an accurate picture of a demand-driven model, and they tell you where to start.

The honest summary

The most useful security work I know of is rarely the most interesting. It is a methodical inventory of what is actually running, compared against what should be, with someone accountable for closing the gap. It does not photograph well and it does not make anyone feel like they are in a thriller. It is what stops the boring attack that was always the most likely one.

If nobody has done that exercise on your estate, our security assessment is exactly that, and we will give you the list whether or not you do anything else with us. You can also read how we handle this on an ongoing basis as part of managed IT.

Jason Agnew
Jason Agnew Founder & CEO, Belton IT Nexus. Twenty-two years building specialist IT and security for Australian business.

Get the list for
your estate.

A 90-minute discovery and security session. We look at what is actually running, what is past end of life, and what should have been switched off years ago. Then we hand you the list.

And relax

Getting started is the easy part.

Onboarding without drama

We do the switch: your current provider, the migration, the handover, all of it. Most teams barely notice the cutover happened.

Everything looked after

On the right plan, compliance, reporting and budgets are handled inside the partnership. You run the business; we run the IT underneath it.

Your QBR writes itself

Quarterly business reviews are generated automatically from your live environment: spend, posture, recommendations and roadmap, ready for the board, reviewed with your account manager.

The honest bit: the full looked-after experience comes with the right plan. We charge fairly for what we take on, and when costs step up it's because you are taking on more, always moving in the right direction.

Sovereign by design

New Zealand owned and operated.

Sovereign data centres across New Zealand and Australia, with your data kept onshore wherever it's required. Our team understands New Zealand, and our leaders have built, scaled and secured businesses right across the New Zealand landscape.

Sovereign data centres · New Zealand & Australia
  • Auckland
  • Christchurch
  • Sydney
  • Melbourne
  • Brisbane
  • Perth
International data-centre operations
  • Singapore
  • Germany
  • Netherlands
  • USA

Servers available in minutes, not days.

Explore data centres & hosting →
Partners & platforms
Microsoft Solutions Partner, Modern Work Microsoft Solutions Partner, Security
Fortinet Partner Veeam Partner Lenovo Partner HP Partner SentinelOne Partner Microsoft Azure Microsoft Copilot Claude
Book your free discovery & security session