We Analysed 60,000 UK Endpoints: The Hidden Cyber Risk in Your Leased Line
AMVIA's analysis of 60,000 business endpoints connected via leased line infrastructure found that organisations with dedicated internet connections frequently have weaker perimeter security than those on standard broadband — because the leased line creates a false sense of security.
Nathan Hill-Haimes
Technical Director
Why do leased lines create a false sense of security?
The risk is cultural, not technical. A dedicated, uncontended circuit feels inherently more secure than shared broadband, so some teams quietly stop hardening the controls that sit above it. The connectivity investment masks a weak security posture underneath.
That combination — high-quality connectivity with poor security controls — is a materially worse risk profile than moderate-quality connectivity with strong controls. The circuit is faultless. The firewall protecting it has not been patched in two years. The endpoints connecting through it run basic antivirus and nothing else. Buyers researching a business leased line should treat the security layer as a separate, deliberate decision, not something the circuit delivers for free.
| The leased line assumption | The reality our assessments find |
|---|---|
| "A dedicated circuit is secure by default" | Security depends on the controls above it, not the circuit |
| "Our provider maintains the firewall firmware" | Provider-installed kit is often left unpatched for years |
| "We have a firewall, so we're covered" | Rules opened for old projects are rarely closed |
| "Antivirus protects the endpoints" | Signature antivirus misses fileless and trusted-app attacks |
What did the endpoint data show?
Our findings come from data gathered across client and prospect environments over several years — roughly 60,000 UK endpoints assessed up to 2026. The patterns repeat regardless of sector or size, and they cluster around the perimeter and the endpoint rather than the circuit itself.
The most consistent findings for leased line-connected organisations include:
- Outdated firmware on network equipment — routers, switches and firewall appliances running firmware released two or more years ago, missing multiple security patches. Most common where a connectivity provider installed the kit and no one maintained it afterwards.
- Permissive firewall rulesets — rules opened for a one-off software rollout or temporary project and never closed, accumulating into a firewall that is present but barely protective.
- Missing endpoint detection and response — endpoints relying on basic antivirus with no behavioural monitoring. Signature antivirus has an acknowledged detection gap for modern malware using fileless techniques or trusted applications.
- No multi-factor authentication on remote access — VPN access protected by username and password alone. This is one of the most exploited configurations in corporate environments.
- Unmanaged devices on the network — personal or contractor laptops connecting without compliance checks, bypassing the controls that apply to managed devices.
Why does a static IP change your risk context?
A leased line typically ships with a static public IP address. Static IPs are needed for VPNs, hosted services and remote access — but they are also permanently visible on the public internet. A firewall or server behind a static IP is continuously observable to the automated scanners threat actors run around the clock.
Any service listening on that address — open ports, default management interfaces, an unpatched VPN appliance — becomes a standing attack surface. This is not an argument against leased lines. It is the reason perimeter controls must be proportionate to how permanent and how visible the connection is. The UK's National Cyber Security Centre treats internet-facing infrastructure as a primary exposure point precisely because it never goes dark.
Which configurations get exploited most often?
Three configurations account for most of the avoidable risk we find on leased line-connected networks: exposed management interfaces, unpatched VPN appliances and flat network design. Each is a free win for an attacker and a cheap fix for a defender.
Exposed management interfaces
Firewalls, switches and routers often ship with a web management interface enabled by default. When that interface is reachable from the public internet, it is a direct attack surface. Several widely used firewall and VPN products — including Fortinet, Palo Alto and Citrix products — have had critical management-interface vulnerabilities exploited at scale in the past two years. Management interfaces belong on specific internal IPs or behind a VPN, never on the open internet.
Unpatched VPN appliances
VPN appliances that are not updated regularly are consistently among the most common initial access points in ransomware attacks. The NCSC has issued multiple advisories specifically about this risk, which you can track through its cyber threat reports. Patch public-facing VPN appliances within days of a critical disclosure — not weeks. Ongoing vulnerability management is what turns "we'll get to it" into a measured patch window.
Flat network architecture
Many SME networks are flat: every device sits on one segment with no internal segregation. A single compromised endpoint then has direct access to every other device and server. Segmentation — VLANs separating user devices, servers and management traffic — sharply limits how far an attacker moves after initial access.
What should you do about it?
Treat perimeter security as a recurring operational process, not a one-time exercise. The fixes below are configuration-led and largely achievable on equipment you already own. Pair them with a leased line security review so the controls match the circuit.
- Audit firewall rules quarterly and close any rule that is no longer required.
- Enable automatic firmware updates on network equipment, or schedule monthly manual updates.
- Remove management interfaces from public internet access — restrict them to specific internal IPs or a VPN.
- Deploy EDR on every endpoint, not just traditional antivirus.
- Enforce multi-factor authentication on all VPN and remote access infrastructure.
- Implement network segmentation to limit lateral movement after a breach.
| Control | Basic antivirus | Endpoint detection and response (EDR) |
|---|---|---|
| Detection method | Known malware signatures | Continuous behavioural monitoring |
| Fileless / trusted-app attacks | Frequently missed | Detected by behaviour |
| Response to a live threat | Manual | Automatic device isolation |
| Visibility for your SOC | Minimal | Full endpoint telemetry |
These controls map directly to the Cyber Essentials technical baseline, and the government's Cyber Security Breaches Survey consistently shows that the worst outcomes hit organisations missing exactly these fundamentals.
How AMVIA closes the gap on leased line networks
AMVIA runs security assessments built specifically for leased line environments — covering perimeter configuration, endpoint posture and access control — so you get a clear picture of where your connectivity investment is exposed. One provider, security-first, Microsoft-certified: the same team that reviews your firewall rules can deploy EDR monitored by our in-house 24/7 SOC through our managed cybersecurity service and managed detection and response.
Is Your Leased Line Environment Properly Secured?
AMVIA reviews the security configuration of leased line environments for UK businesses, identifying firewall gaps, unpatched endpoints, and exposed management interfaces.
Frequently Asked Questions
A leased line gives you a dedicated connection that is not shared with other users, which removes certain network-level risks. But its static public IP is permanently visible on the internet, creating a specific attack surface. Whether the environment is safer than broadband depends almost entirely on the quality of the security controls deployed on top of the connection.
Exposed and unpatched perimeter equipment is the most commonly exploited configuration. VPN appliances, firewalls and management interfaces that are reachable from the public internet and have not been updated are consistently the primary initial access vector in attacks against leased line-connected organisations.
Firewall rules should be audited at least quarterly. Rules added for temporary purposes — a project, a third-party integration, a software rollout — are frequently left in place after the need has passed. Over time these accumulate into a permissive ruleset that no longer reflects your actual security requirements.
Not always. Most business-grade managed switches and firewalls already support VLANs for segmentation. Implementing basic segmentation — separating user devices from servers and management interfaces — is usually a configuration change rather than a hardware purchase, provided your existing equipment supports VLANs.
EDR is endpoint security software that monitors device behaviour continuously, catching threats that bypass signature-based antivirus. Instead of checking files against a database of known malware, it watches for suspicious patterns — a process encrypting files or exfiltrating data — and can isolate a compromised device automatically before damage spreads.
Related Reading
Internet Security: How to Keep Your Business Safe Online
A practical guide to internet security controls for UK businesses, from firewalls to phishing protection.
How Much Does a Leased Line Cost?
UK leased line pricing explained: what drives cost, typical monthly figures, and how to compare quotes.
Microsoft 365 Enterprise: A Practical Performance Guide
How M365 Enterprise security features address real business risk — including endpoint and identity controls.
Protect your business → Get Cybersecurity Assessment