Network security priorities
- Start with: The systems reachable from the internet and the people who administer them.
- Use what you own: Review router, firewall, Wi-Fi, identity and device settings before adding a network-security subscription.
- First three actions: Remove unnecessary exposure, separate guest/IoT traffic, and enforce MFA on remote and administrator access.
- Evidence: NIST and CISA guidance; no product performance or deployment-time testing is claimed.
Last updated: September 24, 2026
A small business needs to know which devices and services can communicate, who can change those rules, and how to detect a mistake. A firewall purchase alone does not answer those questions. NIST's small-business CSF guide recommends choosing outcomes that fit the business, while CISA's exposure guidance starts by finding internet-facing assets and removing access that is not needed.
Build a one-page network map
Record internet connection, firewall/router, Wi-Fi networks, business devices, printers and IoT, servers, cloud apps, remote-access route and vendors with access. For each important path, name an owner and why the path exists. Include devices at branch offices and home offices if they can reach internal systems.
| Boundary | Minimum decision | Proof to keep |
|---|---|---|
| Internet to business systems | Which services genuinely need public access? | Current external inventory and approved exceptions |
| Guest/IoT to business devices | Which traffic must be blocked or isolated? | Network/VLAN settings and a connection test |
| Remote user to private resources | Who can connect, from which device, with what MFA? | Identity/access policy and offboarding test |
| Admin access to network gear | Who can change rules and firmware? | Named admin accounts, MFA where supported, change log |
| Monitoring | Who sees high-priority alerts and reviews them? | Routed alert, owner and review record |
Do not publish a network diagram with live secrets or management addresses. Keep the operational copy in a restricted location and update it when equipment or providers change.
A staged baseline
- Remove exposure you do not need. Review router port forwards, remote management, old VPN gateways and cloud firewall rules. Make changes through an authorized maintenance window and test essential business traffic afterward.
- Patch and secure the edge. Confirm supported firmware, administrator MFA or strongest available authentication, configuration backup and a recovery contact.
- Separate traffic by purpose. Put guest and untrusted IoT devices away from business systems; test that a guest device cannot reach a business file share or printer administration interface unless explicitly intended.
- Limit remote access. Use named identities, MFA, device requirements and prompt revocation for leavers. A consumer VPN subscription does not create team authorization or device controls. See the business VPN guide.
- Route a few useful signals. Start with failed admin logins, new external exposure, critical gateway updates and unusual remote logins. Give each an owner; collecting logs nobody reads is not detection.
- Review exceptions monthly. For each open port, bypass and vendor account, record business reason, expiry or review date and approver.
For office Wi-Fi specifics, see the wireless security guide. For a wider security operating model, use the NIST CSF 2.0 guide.
When to buy a tool
A product is justified by a specific unmet requirement: branch connectivity, managed DNS filtering, private-app access, better firewall policy, or useful alerting. Check whether your existing firewall, router, Microsoft/Google identity plan or IT provider already covers it. Then pilot the missing capability with one user, one device and one failure scenario.
If DNS protection is the need, the Cisco Umbrella review explains Cisco's product transition and quote requirement; compare it with Cloudflare's published options. For managed VPN access, the NordLayer review describes plan limits and costs. Neither category is a default purchase for every SMB. Affiliate status does not affect suitability.
Verify the next 30 days
| Week | Owner action | Completion test |
|---|---|---|
| 1 | Inventory public services and admin accounts | Every exposed service has a named owner |
| 2 | Remove or restrict unneeded paths | External test confirms the path is closed |
| 3 | Separate guest/IoT and business traffic | Guest device fails to reach restricted resources |
| 4 | Review remote access and alerts | Leaver test succeeds; alert reaches a responsible person |
Start with a gap, not a brand
The free Valydex assessment can help identify whether network exposure is among your top three actions. Use its local report to assign an owner and verification test; it is not a penetration test or certification.
Sources checked September 24, 2026: NIST SP 1300, CISA internet exposure reduction, and CISA SMB resources. This is documented implementation guidance, not a hands-on network assessment.