if they are just learning how to run a network or are former PHBs turned Network Administrators, then the security will be weak. Like the lawfirm I used to work for, someone ran a password cracker, and I noticed the database on a shared drive full of passwords, and apparently nobody seemed to care that it existed or that someone has a list of password from most of the user accounts, including administrators. They also didn't seem concerned with applying the latest patches and kept SP4 on the NT 4.0 Servers when SP6.1 was out. They used a Linux server for a firewall, but I think someone else set it up for them. I'd give out their address and domain name, but I don't want someone to hack them and then point a finger back at my post listing the address to go at.