Insights › Essential Eight

Securing Your Business Router and Firewall

SecurityScore article cover: Securing Your Business Router and Firewall, Essential Eight

Your router is the front door to your business network. Every email, cloud login, card payment and file transfer passes through it, yet for most small businesses it is the one device nobody ever logs into after the day it was installed. That makes it an easy target. The good news is that locking a router down takes an afternoon, costs nothing in most cases, and closes off some of the most common ways attackers get a foothold. This guide walks through the practical steps, drawn from the Australian Cyber Security Centre’s own guidance, plus what the firewall behind your router is actually doing for you.

Why your router is a target

A router sits at the edge of your network, facing the internet, twenty-four hours a day. Attackers run automated scans across the internet looking for routers with known weaknesses: factory default passwords that were never changed, old firmware with unpatched holes, or management features left switched on that should have been turned off. None of this is targeted. It is opportunistic, and small businesses get caught precisely because they assume nobody would bother with them.

If someone does get control of your router, the damage is not limited to slow internet. They can watch traffic, redirect staff to fake login pages, add their own devices to your network, and use your connection to launch attacks elsewhere. Securing the router is one of the cheapest, highest-value jobs on the list, and it is worth doing properly once rather than worrying about it forever.

Start with the logins

Every router ships with a default administrator username and password, and for many models those defaults are printed in the manual and published online. The single most important step is to change the username and password you use to log in to the router itself. Pick a long, unique passphrase and store it in your password manager, not on a sticky note taped to the unit.

While you are in the settings, change the Wi-Fi network name and the Wi-Fi password from their factory defaults too. The network name, or SSID, does not need to advertise your business or the router’s make and model; a plain, non-identifying name gives an attacker less to work with. These login basics matter far beyond the router, so if your business has not yet sorted out how it stores and shares passwords, our guide to cyber security for small business in Australia is a good place to start.

Keep the firmware updated

Router firmware is just software, and like all software it gets security fixes over time. The problem is that routers almost never prompt you the way a phone or laptop does, so the updates quietly pile up unapplied. The ACSC recommends checking for firmware updates at least every six months, and choosing a router that can update itself automatically if the option is available. Set a recurring reminder so it does not slip.

There is a limit to how long any router stays supported. Once a manufacturer stops releasing updates, usually somewhere between three and five years after release, the device stops getting security fixes and becomes a growing liability. If your router is past that point, replacing it is the only real fix. Firmware updates follow the same logic as every other kind of patching, which we cover in why software updates matter more than almost anything else you do.

Turn off the features attackers use

Routers come with a long list of features switched on by default, and several of them are far more useful to an attacker than to you. Log in to the settings and work through the list below, disabling anything you are not actively using.

Every feature you turn off is one less thing an attacker can probe. The principle here is the same one that runs through the ACSC Essential Eight: reduce what is exposed, and only run what you actually need.

Lock down the Wi-Fi

Your Wi-Fi encryption setting decides how hard it is for someone nearby to intercept or join your wireless network. Set it to WPA3 if your router and devices support it, or WPA3 transition mode if you run into compatibility problems with older equipment. WPA2 is the minimum you should accept; if a router cannot support at least WPA2, it is too old to keep using. Anything labelled WEP or open should never be used for business.

Turn on the guest Wi-Fi feature and put visitors, and anything that does not need to reach your business systems, onto it. A guest network keeps those devices isolated from the computers, servers and printers that hold your business data, so a compromised visitor laptop or a dodgy app on someone’s phone cannot reach the things that matter. The same thinking applies to smart devices such as cameras, TVs and sensors, which are often poorly secured and are better kept on the guest network than alongside your core systems.

It is also worth periodically reviewing the list of devices connected to your network and disconnecting anything you do not recognise. If staff work from home or on the road, the router in their house is now part of your risk too, and our guide to securing remote and hybrid work covers how to extend these habits beyond the office.

What a firewall actually does

A firewall is the gatekeeper that decides which network traffic is allowed through and which is blocked. Most business routers have a firewall built in, and it is usually on by default, quietly dropping unsolicited connection attempts from the internet before they ever reach your computers. The key points are to confirm it is actually enabled in your router settings, and to avoid poking holes in it with the unused port forwarding and UPnP rules mentioned above.

There are three layers worth knowing about. The router firewall protects the boundary between your office and the internet. The software firewall built into Windows and macOS protects each individual computer, including when staff take a laptop to a cafe or client site, so leave it switched on rather than disabling it to make an app work. Larger or more regulated businesses may also run a dedicated hardware firewall or a security appliance that adds filtering, logging and intrusion detection; that is a worthwhile conversation to have with your IT provider once the basics above are in place, but it is not where you start.

A short checklist to work through

If you do nothing else this quarter, log in to your router once and run through these points:

Find out where you stand

Securing your router and firewall is one piece of a bigger picture that also covers passwords, backups, phishing and your obligations under Australian privacy law. If you are not sure how your business measures up, you can find out in a few minutes. Our free self-assessment at SecurityScore.com.au asks 27 plain-English questions and gives you an instant, personalised PDF report mapped to the ACSC Essential Eight, ISO 27001 and SOC 2. It takes five to ten minutes, costs nothing, and shows you exactly where to focus next.

Discover more from Security Score

Subscribe now to keep reading and get access to the full archive.

Continue reading