If staff are found using illegal software is it not still the company that is held responsible?
The CFO is ultimately responsible as an individual and is the person who would/could be prosecuted along with the company, in theory.
As people have said, if it's Vista Business (most likely) or Ultimate that the machines are currently licensed for then there's nothing illegal about it at all.
How big is the company out of interest?

)
