Walk around a typical office and count the devices nobody patches: the CCTV recorder, the biometric attendance terminal by the door, the networked printers, the meeting-room TV, the visitor's phone on Wi-Fi. They sit on the same network as the accounts PCs because that was the easiest place to plug them in. They are also the devices most likely to be running old firmware with a default password.
Why these devices are the soft spot
- They are rarely updated. Camera and recorder firmware is often updated by hand, and the installer who set them up has long moved on.
- They ship with default credentials, and many installations never change them.
- Some are deliberately exposed to the internet so the owner can view cameras from a phone, usually through a port forward on the router.
- They cannot run endpoint protection, so nothing on the device will notice a compromise.
The Mirai botnet showed how this is exploited at scale: scan the internet for exposed devices, try the default passwords, recruit whatever answers. A device recruited that way, sitting on a flat office network, is also a foothold next to your servers.
Guest Wi-Fi: internet only
- A separate SSID on its own VLAN, mapped to a guest zone on the firewall.
- Internet access only, with no route to any internal network. If visitors need to print, give them a printer that lives in the guest network rather than opening a path to the office printers.
- Client isolation on the access points, so guests cannot reach each other's devices.
- A bandwidth limit, plus DNS or URL filtering, because whatever guests do appears to the outside world as coming from your public IP address.
- A password that changes regularly, or vouchers through a captive portal, so last year's visitors and former staff are not still connected.
IoT: reach only what each device needs
| Device | Needs to reach | Should not reach |
|---|---|---|
| CCTV cameras | The recorder (NVR) | Anything else, including the internet |
| CCTV recorder | The vendor's cloud service, if remote viewing is used; a time server | Staff devices and servers |
| Attendance terminals | The attendance or HR server, or its cloud service | Everything else |
| Printers and scanners | The print server; the mail relay or file share for scan-to-email or scan-to-folder | The internet, apart from firmware updates if you allow them |
| TVs and meeting-room displays | The internet for casting and apps | Internal networks |
The pattern is the same each time: list what the device needs, allow exactly that from the IoT zone, and deny the rest. Staff who view cameras or manage the attendance system reach those devices from the staff zone through a specific rule. The devices themselves never open connections into the staff network.
Where cameras sit on their own PoE switch with the recorder, the cameras may not need to route anywhere at all. Only the recorder needs a rule.
Remote viewing without port forwarding
The usual way to view cameras from a phone is a port forward on the router to the recorder, which puts a rarely updated device directly on the internet. Two better options: the vendor's cloud service, which keeps the recorder making outbound connections only, or the company VPN with multi-factor authentication, so the recorder is reachable only by people who have signed in. Vendor cloud services have had vulnerabilities of their own, so keep firmware current either way. If a port forward to a recorder exists today, removing it is the first job.
Doing it without breaking anything
- Inventory first. The DHCP lease table on the firewall or server, plus a walk around the office, finds most devices. Note what each one talks to.
- Create the guest and IoT VLANs and zones, with rules that match the inventory.
- Move guest Wi-Fi first. It is a single SSID change and rarely breaks anything.
- Move IoT devices one type at a time, starting with printers, which are the easiest to test.
- Log before you block. Keep a logging catch-all rule on the IoT zone for a week, check what it caught, then make it a deny.
- Change default passwords as you go, and store the new ones in the password manager, not on a label on the device.
For the firewall side of this, see zones first; for why a flat network is the bigger risk, one laptop should not reach everything; and for how we carry it out, network segmentation and VLANs.