It has a built-in firewall (not microsoft) that prevents all connections except to the web server (which currently has no known exploits) and the remote control. The website only allows access by specific IPs, and the remote uses an AES-secured completely custom protocol. All of the Microsoft networking stuff that normally is the source of many remote exploits, doesn’t even exist on the OS image. Leif & LA guys (and now Omnia a bit) have been working on optimizing the XP Embedded (a special ultra-small version of Windows made for doing hardware devices) in these boxes for the better part of a decade as well.
In other words, it’s locked down pretty dang tight. 😉 But yeah, have your IT guy call Omnia so they can address any concerns your IT guy has without having to RTFM, and probably get some info that’s not in the manual too.