Banks warned on risks of using unsupported Windows Server 2003

Banks warned on risks of using unsupported Windows Server 2003

NatWest and ANZ are among the banks that are still using Windows Server 2003, despite Microsoft ending support for the operating system last month, according to security outfit Netcraft.

Extended support for Windows Server 2003 ended on July 14, 2015, meaning that Microsoft will no longer be issuing security updates, which US-Cert warns means an elevated risk of things like cyberattacks and data theft.

Yet Netcraft says that more than 600,000 web-facing computers which host millions of sites are still running the server operating system.

Natwest, ANZ, and Grupo Bancolombia are using Windows Server 2003 and Microsoft Internet Information Services 6.0 on their main sites. Hundreds of other banks "appear" to be using Windows Server 2003 while some, including ING Direct and Caisse d'Epargne, are using IIS 6.0 but do not seem to have Windows Server 2003 machines exposed directly to the internet.

Meanwhile, Netcraft warns that firms using unsupported operating systems like Windows Server 2003 in a cardholder data environment should migrate immediately or face automatic PCI compliance failure.

Comments: (1)

Melvin Haskins
Melvin Haskins - Haston International Limited - 19 August, 2015, 22:39Be the first to give this comment the thumbs up 0 likes

Why is this a surprise? It was flagged last year and nothing has changed. It is not only banks, but government institutions and many major businesses that are in the same position. The cost of upgrading is huge, because it is not just the cost of licences from Microsoft, it is also the cost of the hardware, since Windows 8.1 and Windows 10 need much bigger PCs that the banks and others have installed. Then there is the training cost to educate users. It is a critical problem, but one caused by Microsoft, not by the banks. It was Microsoft who decided to discontinue support, principally because they want to force their users to upgrade and make more money. Perhaps the banks need to schedule to move to a newer system, but not one from Microsoft.