# Banking Client Enforces Endpoint Security Policies

A contractor working remotely for a banking client accessed client systems via Azure Virtual Desktop using a personal laptop instead of the approved company device, violating strict client and employer security policies. This breach highlights the critical importance of adhering to endpoint security controls in regulated financial environments to prevent contractual violations and potential disciplinary actions.

- Banking clients enforce stringent endpoint device policies to protect sensitive data and comply with regulatory standards.
- Contractors must use only authorized devices as specified by client and employer policies to avoid security breaches and contractual risks.
- Procurement professionals should ensure contract terms clearly define device usage requirements and compliance expectations for contractors.
- Organizations supporting financial sector clients may need to enhance training and monitoring to prevent unauthorized device access and maintain compliance.

**Jurisdictions:** federal
**Industries:** Information Technology
**Topics:** Cybersecurity
**Published:** September 22, 2026

### Government Entities
- National Institute of Standards and Technology (NIST)
- National Cyber Security Centre (NCSC)

### Key Quotes
> The client is a bank. Bank will likely have strict requirements on the endpoint controls. It sounds like OP could be accruing failure to meet employer policy, failure to meet client policy, and causing employer to breach contractual terms with client.
> — Commenter

### Sources
- [How fucked I am?](https://www.reddit.com/r/cybersecurity/comments/1wn5g5y/how_fucked_i_am) - reddit-cybersecurity