GCHQ warns against Windows 7 for email, banking
.png)
Windows 7 should not be used for sensitive tasks, such as banking or email, after the decade-old software hits end of life tomorrow (14/1/2020), the British government's security service has warned.
The National Cyber Security Centre (NCSC), the public-facing arm of GCHQ, issued the warning ahead of Microsoft ending extended support for the ten-year-old operating system on 14 January, meaning Windows 7 will no longer get any security updates and that flaws will go unpatched and left open for hackers. Businesses will still be able able to pay to get security updates for the next three years.
"The NCSC would encourage people to upgrade devices currently running Windows 7, allowing them to continue receiving software updates which help protect their devices," an NCSC spokesperson told The Telegraph.
"We would urge those using the software after the deadline to replace unsupported devices as soon as possible, to move sensitive data to a supported device and not to use them for tasks like accessing bank and other sensitive accounts," the spokesperson added. "They should also consider accessing email from a different device."
The NCSC noted that criminals started targeting Windows XP immediately after extended support ended in 2015, though Microsoft has issued a handful of emergency patches for serious vulnerabilities despite officially ending support.
As of the end of 2019, Windows 7 was still used on 27% of desktops and laptops globally, according to Net Applications' Market Share, while 55% were on the most recent version, Windows 10. Indeed, a tiny slice, just over 2%, remain on Windows XP.
That includes consumer devices around the world, but Kaspersky warned last year that as many as half of small businesses still use older operating systems, such as Windows 7, despite the significant security risk. That's partially down to cost and dependence on apps unsupported on newer systems, but also down to habit, the security firm said. This is despite a number of high-profile attacks such as WannaCry, which targeted Windows 7 machines.
For those who prefer to plan ahead, Microsoft has already announced that it will end support for Windows 10 in 2025.

Latest Jobs
-
- 6 month contract Operational Cyber Security - SIEM, Vulnerability, Cyber Essentials + London, Inside IR35
- City of London
- Depending on experience
-
6 month contract inside IR35 Operational Cyber Security London c50% of the role is day to day operations / administration / liaising with 3rd party monitoring suppliers. More though investigations, getting ready for cyber essentials plus. Following up on vulnerability management. 20-30% active monitoring of alerts, tooling etc. 10% reporting / light oversight of junior Experience with Microsoft defender / Azure, Splunk, Tenable Experience in maintaining Cyber Essentials Plus is a big bonus. Knowledge across ISO27001, NIST GDPR required. Inside ir35 need someone in their London (city) office 2-3 days a week.
-
- CONTRACT Fluent French AND English Cyber Security Project manager - 12 month
- United Kingdom
- Dependent on experience
-
Fluent French / English Contactor cyber Security Project Manager needed. Experience in migrating technical cyber services from one physical region to another. Experience with Crowdstrike, Tanium, Palo Alto and or Zscaler ideal or comparable solutions. Language fluency in French AND English is essential. 12 month contract. Looking to start June. Day rate dependent on Experience. Apply today for more details
-
- GRC Security Contractor - Achieve SOC2 Type 1 Compliance - 6 month
- London
- Dependent on experience
-
GRC security practitioner needed to ensure a financial service business to achieve SOC 2 type 1. Experience managing the end to end process is key, you will be the key individual to deliver this within a 6 month deadline. Experience of SOC 2 type 1 / type 2. The gathering of evidence, baseline of 27001, ukdpa, GDPR NIST etc. Looking to interview ASAP.
-
- Contact 12 month- Security Operations- Crowdstrike Falcon Insight EDR / Analyst.
- United Kingdom
- Dependent on experience
-
Security Operations engineer / Analyst with Crowdstrike Falcon Insight EDR experience for a 12 month contract. Experienced Contractor with Crowdstrike Falcon Insight: Endpoint detection and Response (EDR) experience needed - 12 month rolling project. Implementation, configuration and Analyst experience needed with Crowdstrike Falcon Insight: (EDR) Migration project- relocating capability internationally. technically implementing, configuration of that that migration and then transition to BAU role monitoring. DCL Search exclusive associate Project.