A BOT

Securing your business network: guest Wi-Fi, segments and safe remote access

IT Security4 min read

Technician with a tablet in the server room

When we look at a network for the first time, it often looks like this: the provider’s router, a switch behind it, and everything plugged into that switch. The accounting PCs, the server, the printers, the cameras, the app-controlled coffee machine and the Wi-Fi that visitors use too. Every device can see every other device.

As long as nothing happens, nobody notices. But if an attacker gets in through a single device, say an outdated camera or a guest’s laptop, the whole network is open to them.

Split the network into zones

The most effective measure is segmentation. The network is divided into separate zones, called VLANs, and the firewall decides who may talk to whom. For a typical SME, four zones are usually enough:

  • Office for staff workstations.
  • Servers for file storage, ERP and databases. Only the services that are really needed can be reached from the workstations.
  • Devices for printers, cameras, phones and anything else with a plug and an IP address. These devices rarely get updates, so they should be able to reach as little as possible.
  • Guests with internet access but no access at all to the company network.

It sounds like a lot of work, but with a current firewall and a managed switch it’s usually done in a day.

Don’t forget the Wi-Fi

A guest Wi-Fi with its own password that changes regularly is standard equipment today. The company Wi-Fi should ideally use WPA3, or at least WPA2 with a long key. Better still is sign-in with each person’s own credentials, so nobody has to change the Wi-Fi password for everyone when someone leaves.

Remote access only via VPN

A common mistake: at some point a port was opened in the firewall for working from home, for example for Remote Desktop. Open doors like this are scanned automatically and constantly across the internet. Remote access belongs behind a VPN, and the VPN behind multi-factor authentication.

Modern solutions such as WireGuard or NetBird are fast, stable and easy to set up on laptops and smartphones.

Look after the firewall

A firewall isn’t something you set up once and forget. Three things should happen regularly:

  1. Install updates. Firewalls and VPN appliances in particular keep turning up vulnerabilities that are actively exploited.
  2. Clean up the rules. Openings created years ago for a single project are often still active.
  3. Review the logs. Ideally automatically, in a central system that flags anything unusual.

Where to start?

If you do just one thing this week, check which ports your firewall has open to the internet and close everything that isn’t strictly needed. After that, a separate guest Wi-Fi is worth it, and the third step is separating office, servers and devices.

We’re happy to check your network on site, map out what is connected where and set up the separation without disrupting your business. More under IT security and servers & virtualisation.

Frequently asked questions

Do we need new hardware?

Not necessarily. Many firewalls and switches already support VLANs; the feature just hasn’t been set up. A cheap provider router usually isn’t enough, though.

Will printing still work after the separation?

Yes. The firewall specifically allows connections from the office to the printers, but not the other way round. Nothing changes for your staff.

Is an open Remote Desktop port really that dangerous?

Yes. These ports are searched for automatically and attacked with stolen or guessed passwords. They are among the most common entry points for ransomware attacks.

How often should the firewall be checked?

Updates as soon as they are released, the rules at least once a year. With a support contract, we take care of both.

More articles

Questions?

We are happy to review your environment and tell you honestly where action is needed.