All articles
Cybersecurity6 min read

5 Signs Your Business Network Is Vulnerable (and What to Do About Them)

From default router passwords to forgotten smart devices, these are the weak points we find in nearly every security audit — and how to close them fast.

Illustration of a glowing shield above a network mesh, with several nodes lit in warning orange.

Security assessments rarely turn up something exotic. The same handful of gaps come up again and again, and most of them were introduced by someone doing something reasonable at the time — plugging in a device, sharing a password, getting a contractor online quickly.

Here are the five we find most often, and what closing each one actually involves.

1. Equipment still using its factory password

Routers, network switches, cameras, printers, and door controllers ship with a default administrator login. Those defaults are published in the manuals, which are online, which means they are not secrets.

The fix is unglamorous: make a list of every device on your network with an admin interface, and change the credentials on each one. The listing exercise is usually more revealing than the password change — most businesses find hardware nobody remembered was there.

2. One flat network for everything

If your guest Wi-Fi, your smart thermostat, your security cameras, and the computer holding your accounting files are all on the same network, then anything that compromises the weakest device has a path to the most important one.

Separating traffic is standard on business-grade equipment and costs nothing extra once the hardware supports it. At minimum you want three lanes:

  • Staff devices and the systems that hold real business data
  • Guest access, fully isolated from everything else
  • Smart devices, cameras, and anything that just needs internet access

3. Accounts that outlived the people who used them

When someone leaves, their email usually gets shut off quickly. The accounts that linger are the ones nobody thinks about — the shared login for the booking system, VPN access, the account on the camera system, the file share.

4. No second factor on anything that matters

A password alone is one thing standing between an attacker and your email, and email is the account that can reset every other account. Multi-factor authentication is the single highest-value change most small businesses can make, and it is usually free with the services you already pay for.

Turn it on for email first, then banking, then anything holding customer data. App-based codes are meaningfully stronger than text messages, though a text message is still far better than nothing.

5. Hardware that stopped getting updates

Network equipment has a support lifespan. Once a manufacturer stops issuing firmware, any newly discovered flaw in that device stays open permanently. A five-year-old router that still works is not the same as a five-year-old router that is still safe.

Check the manufacturer's support page for your model. If it has reached end of life, replacement is not optional maintenance — it is the only fix available.

Where to start

If you do only one thing this week, turn on multi-factor authentication for email. If you do two, add the access list from section three. Those two changes close more real risk than anything else on this page.

For the rest, a proper assessment is worth it — the gaps that matter are usually the ones nobody knew existed. Our networking and security team does this work across the Bay Area.