Building societies have always occupied a distinct place in UK financial services. Member-owned, community-rooted, and answerable to the people who save and borrow with them rather than to shareholders. That model is a genuine strength. It also means that when member data is exposed, the damage lands squarely on the relationship the society is built on.
The way societies operate has changed. Hybrid working, satellite branches, outsourced service providers and community outreach have all extended the working environment well beyond head office. What has not changed is that the networks staff connect from in those settings are largely outside IT’s control.
That gap has a name the uncontrolled network edge. Loxada exists to close it.
This was once a niche concern. It is not any more, and the shift is measurable.
Exploitation of edge-device and VPN vulnerabilities rose from 3% to 22% of vulnerability-related breaches in a single year, roughly an eightfold increase, according to the Verizon 2025 Data Breach Investigations Report. The reason is straightforward: as the corporate perimeter has become better defended, attackers have moved to the part of the estate that nobody manages, and automation has made scanning for it cheap.
Societies are an attractive target for the same reasons they are trusted. They hold rich member data, they are often leaner on in-house security than the large banks, and their reputation is disproportionately valuable relative to their size.
The uncontrolled network edge is anywhere a staff member reaches society systems from outside the core IT environment. For a building society that typically means:
In each case the device may be well protected while the network beneath it is unknown. An encrypted-connectivity client protects traffic in transit. It does not tell you whether the router carrying that traffic was last patched three years ago, or what else is sitting on the same network.
UK regulators are responding to these risks. The FCA, PRA and guidance from the National Cyber Security Centre (NCSC) all emphasise the need for:
The Digital Operational Resilience Act (DORA) and NIS2 Directive, though EU-led, set further expectations for operational resilience that UK firms may choose to align with as a matter of best practice.
Loxada replaces the unmanaged router at the point of connection with a **Loxada secure router**, pre-configured and centrally managed, and routes traffic through Loxada’s secure connectivity layer, an encrypted connection from the device out to the internet. Your people stop depending on the local network being sound.
Each Loxada secure router:
There is no local configuration and nothing for the user to manage. The device is plugged in and it works.
Loxada suits organisations that do not want to run complex infrastructure across dozens of sites:
No specialist installation. Devices arrive ready to use.
Central management. Firmware and configuration are handled centrally, not locally.
Proportionate. It works the same way for five users as for five hundred.
Complementary. It sits alongside your existing remote access, endpoint and identity tooling rather than replacing any of it.
Deployment is fully auditable, with monthly security reports and device-status visibility, so you can evidence which devices are deployed, connected and on current firmware.
UK regulators have moved from asking whether firms have a plan to asking them to evidence one. For dual-regulated societies, that means showing you can keep your important business services running through severe but plausible disruption, and that you understand what every one of them depends on. A compromised home or branch network that lets an attacker intercept traffic or move sideways is exactly the kind of scenario the FCA and PRA framework has in mind, and it is hard to argue you have accounted for it if the edge has never been brought under management.
Dependency mapping is where this bites hardest. Firms are expected to map the technology and third parties behind each important business service, and domestic routers chosen by staff and maintained by nobody are an unmapped dependency that cannot honestly go on the map. Loxada replaces them with a single documented provider that can, giving the individual accountable under the Senior Managers and Certification Regime something concrete to point to rather than a policy asking people to keep their home broadband patched. NCSC guidance on firmware integrity, network separation and secure remote access points the same way.
Loxada supports these expectations at one specific layer; networks your staff use that are outside your control. It is a preventive control providing deployment coverage and configuration assurance, not monitoring, threat detection or incident containment, and those obligations sit elsewhere in your programme.