SonicWall’s UK public-sector team began shipping a bundled email attachment quarantine and sandbox licence to district councils still running on-premises Microsoft Exchange after LGSS Digital circulated proxy-log alerts showing MRSProxy-style POST spikes across several East Anglia authorities, giving IT leads a single SKU for Capture Advanced Threat Protection without renegotiating perimeter firewalls separately.
What broke in council mail stacks
LGSS Digital, which supports multiple Norfolk and Suffolk councils, told members in a September coordination note that legacy Exchange 2019 hosts exposed to the internet logged unusual attachment staging through OWA and ActiveSync paths while HTTP.sys-registered proxy services lacked consistent Extended Protection for Authentication. The note did not claim successful data theft; it flagged repeated external attempts to park macro-enabled documents in quarantine folders that older SonicWall firmware treated as “clean” after static scanning.
Council security officers said hybrid migrations stalled because planning systems and committee PDF workflows still depend on on-prem journaling rules Microsoft 365 alone cannot replicate without costly third-party archivers. That leaves Exchange in the blast radius for commodity phishing even when frontline staff use cloud mailboxes.
What SonicWall is bundling
The UK bundle pairs existing TZ-series appliances with Capture ATP cloud sandboxing and a dedicated “council Exchange” policy template: attachments over configurable size thresholds route to SonicWall’s cloud detonation before delivery to internal mailboxes, while failed messages sit in a quarantine portal councillors access through SSO. SonicWall confirmed the SKU to InfoHandle but declined per-council pricing; LGSS said pilot authorities pay through existing framework call-off rates rather than new capital bids.
Templates include pre-built rules for .iso, .html, and OneNote-style containers that NCSC’s weekly threat reports flagged in Q3 commodity campaigns. Quarantine retention defaults to 14 days—long enough for incident responders to pull samples without filling council storage arrays.
Who is liable and who regulates
Councils remain data controllers under UK GDPR; ICO breach reporting duties apply if malicious attachments reach caseworkers handling housing or social-care records. NCSC’s “Board Toolkit” for local government recommends sandboxing for authorities that cannot retire Exchange before extended support ends. SonicWall’s bundle does not replace patching: Microsoft’s support matrix still requires cumulative updates on Exchange 2019; councils without ESU on 2016 are warned they may have no vendor fix path after October 2026.
Insurers covering public-sector cyber policies increasingly ask whether attachment controls sit inline or only at endpoint antivirus—a gap the quarantine bundle is marketed to close. LGSS said it shared the SonicWall offer with members only after legal review confirmed framework compliance.
Confirmed versus unverified
SonicWall and LGSS confirmed the bundle exists and that at least four councils activated pilots. InfoHandle could not verify exploit success in the East Anglia logs because member names were redacted. Microsoft’s public tracker lists related proxy-path CVEs as patched in August 2026 cumulative updates; independent researchers nonetheless published relay proof-of-concepts that assume misconfigured EPA.
What is knowable: councils delaying cloud migration keep internet-facing Exchange; attachment quarantine reduces but does not eliminate relay and credential-stuffing risks on other paths.
What IT teams must do
Pilot councils should enable EPA on every Exchange virtual directory, apply August cumulative updates, and route inbound SMTP through the sandbox policy before replicating journaling rules. LGSS asked members to file attestation forms by month-end listing whether quarantine portals integrate with existing SIEM feeds—many small authorities still rely on weekly CSV exports.
Staff training remains mandatory: quarantine consoles fail if users release macro invoices because a supplier “looks familiar.” SonicWall includes phishing simulation credits in the bundle; uptake is optional but NCSC-aligned.
Migration horizon
LGSS Digital’s long-range plan still targets full Microsoft 365 for committee services by 2028. Until then, the SonicWall bundle is an admission that legacy Exchange will persist in parish and district networks—attachment quarantine is the compensating control auditors expect when ministers demand digital-by-default services without funding complete mail replatforming in one budget cycle.
NCSC alignment
NCSC’s weekly threat bulletin for local government explicitly recommends sandbox detonation for macro-bearing attachments when Exchange remains on-prem. SonicWall’s template imports those file-type lists quarterly; councils that skip updates inherit stale rules. LGSS asked members to subscribe to NCSC feeds through existing PSN-connected mail relays so policy changes propagate without manual spreadsheet edits.








