Before the five checks: confirm what you are responsible for

Write down the firewalls, switches, wireless systems, internet circuits, cloud phone services, servers and remote-access methods the business depends on. Include the person or provider that administers each one. An incomplete inventory is itself a useful finding because unknown equipment and unclear ownership slow down both routine support and incident response.

Record software or firmware versions and support status when available. Do not make production changes just to complete the list. The first objective is visibility: know what exists, where it is, what business service it supports and who can authorize work on it.

1. Review firewall rules and internet exposure

Firewall rules accumulate through vendor installations, remote-work changes and one-time troubleshooting. A rule can still pass traffic exactly as configured even when the original business need ended years ago. Review inbound exposure, broad allow rules, management services and temporary access with the person who owns the affected service.

Every retained rule should have a business purpose, an owner, appropriately narrow sources and destinations and a review or expiration date. Export and protect the current configuration before approved changes, identify dependencies and define how service will be validated afterward.

  • Confirm management interfaces are not open to the public internet
  • Remove or expire rules with no current approved purpose
  • Review vendor and remote-access paths separately
  • Use a change plan with prechecks, validation and rollback

2. Test guest Wi-Fi separation

A separate guest network name does not prove that guest devices are isolated. From an authorized test device on guest Wi-Fi, confirm that internal printers, file shares, cameras, servers and network-management pages are unreachable while ordinary internet access still works.

Staff, guest and connected devices often need different access rules. Cameras, displays and building devices may deserve their own segment because their update cycles and vendor requirements differ from employee computers. Document the intended boundary so later troubleshooting does not quietly remove it.

  • Use separate VLANs or equivalent network boundaries
  • Block guest access to internal address ranges
  • Limit wireless administration to approved management paths
  • Use supported encryption and unique administrative credentials

3. Audit VPN, vendor and remote administration

List every method used to administer the network or reach internal systems from outside the office. Check that accounts belong to current, named users and that shared credentials are being replaced. Multifactor authentication should be used wherever the management platform supports it.

Vendor access needs a clear owner and a way to revoke it quickly. Review whether the path is always available or enabled only when needed, what the vendor can reach, and whether important administrative events are logged to a protected destination.

4. Identify unsupported systems and missing update ownership

Security updates cannot protect equipment that the manufacturer no longer supports. Compare important device models and software versions with current vendor support information, then assign an owner for routine review and planned updates. End-of-support systems need a dated replacement, isolation or exception decision.

Do not update a firewall or core switch during an informal check. Firmware and software changes require current backups, release-note review, compatibility checks, a maintenance window, success criteria and a rollback method. The immediate value of this step is knowing where the risk and ownership gaps are.

5. Prove one recovery path

A dashboard showing successful backups is not the same as a successful restore. Choose a representative configuration, file or supported system and run a time-boxed recovery exercise. Record the evidence, elapsed time, missing access, dependencies, decisions and the date of the next test.

For network equipment, confirm that a known-good configuration is stored away from the device and can be retrieved by an authorized person. Document console or emergency access, required licenses, software images and the order in which critical services would be restored.

Turn observations into an owned action list

Prioritize findings by business impact, exposure and recoverability rather than by the number of technical warnings. An internet-exposed management service, loss of administrative access or an untested backup for a mission-critical system usually deserves attention before cosmetic cleanup.

Assign an owner and due date to each action. Record accepted exceptions and schedule the next review. If the environment is unclear, the Wolex Small Business Network Security Checkup provides a fixed starting point with firewall, Wi-Fi, VPN and remote-access review, a basic diagram, five prioritized recommendations and a findings call.

Local context for Beaverton businesses

Wolex Technologies is based in Beaverton and serves organizations across Hillsboro, Portland, Tigard, Aloha, Raleigh Hills, Lake Oswego and nearby Oregon communities. The guidance above is general and should be adapted to the authorized environment, business requirements and change procedures before use.