Stylised illustration of a Loxada device
Securing Hybrid Work and Remote Access for UK Building Societies

Building Societies

Building societies have always occupied a distinct place in UK financial services. Member-owned, community-rooted, and answerable to the people who save and borrow with them rather than to shareholders. That model is a genuine strength. It also means that when member data is exposed, the damage lands squarely on the relationship the society is built on.

The way societies operate has changed. Hybrid working, satellite branches, outsourced service providers and community outreach have all extended the working environment well beyond head office. What has not changed is that the networks staff connect from in those settings are largely outside IT’s control.

That gap has a name the uncontrolled network edge. Loxada exists to close it.

Why This Is Getting Worse

This was once a niche concern. It is not any more, and the shift is measurable.

Exploitation of edge-device and VPN vulnerabilities rose from 3% to 22% of vulnerability-related breaches in a single year, roughly an eightfold increase, according to the Verizon 2025 Data Breach Investigations Report. The reason is straightforward: as the corporate perimeter has become better defended, attackers have moved to the part of the estate that nobody manages, and automation has made scanning for it cheap.

Societies are an attractive target for the same reasons they are trusted. They hold rich member data, they are often leaner on in-house security than the large banks, and their reputation is disproportionately valuable relative to their size.

Where the Edge Actually Is

The uncontrolled network edge is anywhere a staff member reaches society systems from outside the core IT environment. For a building society that typically means:

  • Staff working from home on ordinary domestic broadband
  • Temporary or mobile setups for community outreach and member events
  • Contractor and partner offices that sit outside your security policies
  • Branches running older networking equipment that’s not supported anymore

 

In each case the device may be well protected while the network beneath it is unknown. An encrypted-connectivity client protects traffic in transit. It does not tell you whether the router carrying that traffic was last patched three years ago, or what else is sitting on the same network.

Regulatory Expectations Are Rising

UK regulators are responding to these risks. The FCA, PRA and guidance from the National Cyber Security Centre (NCSC) all emphasise the need for:

  • Robust controls around remote access
  • Visibility over systems and assets used to access sensitive data
  • Demonstrable patching and firmware integrity
  • Support for Zero Trust models and network segmentation

The Digital Operational Resilience Act (DORA) and NIS2 Directive, though EU-led, set further expectations for operational resilience that UK firms may choose to align with as a matter of best practice.

Stylised illustration of a Loxada device

How Loxada Protects the Connection

Loxada replaces the unmanaged router at the point of connection with a **Loxada secure router**, pre-configured and centrally managed, and routes traffic through Loxada’s secure connectivity layer, an encrypted connection from the device out to the internet. Your people stop depending on the local network being sound.

Each Loxada secure router:

  • Runs Loxada’s secure firmware in place of the manufacturer’s
  • Creates a separate work network, isolated from everything else on the local connection
  • Blocks known malicious domains, dropping requests to domains on Loxada’s aggregated blocklist before they resolve
  • Updates automatically, with Loxada’s secure firmware, with no user involvement
  • Returns to a secure state after a factory reset or relocation
  • Can be revoked centrally when someone leaves or a device is lost

 

There is no local configuration and nothing for the user to manage. The device is plugged in and it works.

Built for Societies, Not Enterprises

Loxada suits organisations that do not want to run complex infrastructure across dozens of sites:

No specialist installation. Devices arrive ready to use.

Central management. Firmware and configuration are handled centrally, not locally.

Proportionate. It works the same way for five users as for five hundred.

Complementary. It sits alongside your existing remote access, endpoint and identity tooling rather than replacing any of it.

Deployment is fully auditable, with monthly security reports and device-status visibility, so you can evidence which devices are deployed, connected and on current firmware.

Supporting Operational Resilience Expectations

UK regulators have moved from asking whether firms have a plan to asking them to evidence one. For dual-regulated societies, that means showing you can keep your important business services running through severe but plausible disruption, and that you understand what every one of them depends on. A compromised home or branch network that lets an attacker intercept traffic or move sideways is exactly the kind of scenario the FCA and PRA framework has in mind, and it is hard to argue you have accounted for it if the edge has never been brought under management.

Dependency mapping is where this bites hardest. Firms are expected to map the technology and third parties behind each important business service, and domestic routers chosen by staff and maintained by nobody are an unmapped dependency that cannot honestly go on the map. Loxada replaces them with a single documented provider that can, giving the individual accountable under the Senior Managers and Certification Regime something concrete to point to rather than a policy asking people to keep their home broadband patched. NCSC guidance on firmware integrity, network separation and secure remote access points the same way.

Loxada supports these expectations at one specific layer; networks your staff use that are outside your control. It is a preventive control providing deployment coverage and configuration assurance, not monitoring, threat detection or incident containment, and those obligations sit elsewhere in your programme.

Why Building Societies Choose Loxada

  • Protects member data wherever staff are working
  • Reduces risk at the edge without adding anything for users to do
  • Deploys quickly, with no specialist installation
  • Supports FCA, PRA and NCSC expectations with a documented, auditable control
  • Scales sensibly, from a single branch to a full network

Talk to us about securing the connections your members never see, but rely on.