Skip to content
SOS Informatique Computer repair in Lyon - Individuals and businesses

Securing a business network in Lyon

The way into a small business is almost never its firewall. It is remote access opened in a hurry and never closed again.

That is what we find audit after audit. The attacks that hit small and medium businesses in Lyon do not exploit sophisticated flaws: they exploit a remote-control service left open to the internet with a simple password, equipment still on its factory password, or a network where everything talks to everything.

The points we check first

Remote access. A remote desktop service exposed directly to the internet is attacked automatically, continuously, within days of being brought into service. It is the most critical and the most frequent point. The answer is not to remove it but to route it through an encrypted tunnel - see VPN installation.

Administration passwords. Routers, switches, NAS units, printers, cameras: this equipment leaves the factory with a password everyone knows, and it is rarely changed. A badly protected network printer gives access to everything that has been printed.

Separating uses. On most small networks, the accounting machine, the till, the visitors' Wi-Fi and the security camera sit on the same segment and can see each other. One compromised device then reaches everything else.

File shares. A shared folder writable by everyone is the ideal playground for ransomware: it encrypts everything it can reach.

Equipment updates. Routers, NAS units and switches receive security fixes that almost nobody applies.

The principle that governs everything else

Each machine, each user, each device reaches only what it genuinely needs. It sounds obvious and it is almost never done, because opening things up wide is quicker at installation time. On the day of an incident, though, that single principle determines whether the problem stays confined to one machine or reaches the whole business.

Separation, in practice

On a small business network, this is not about complex architecture but about three simple, inexpensive separations.

Visitor Wi-Fi on a separate network, giving internet access and nothing else. Most routers offer it natively.

Connected equipment - cameras, till, various devices - kept away from the workstations. They are often the least well updated devices on the network.

Sensitive machines, accounting or management, with distinct rights on the shares.

Cameras and connected objects

They deserve a mention of their own, because they have become the weak link on many small networks. A security camera, a video recorder or a cheap connected object rarely receives updates, often keeps its factory password, and is designed to be reachable from outside.

Placed on the same segment as your workstations, they offer a direct way in. Isolating them takes a few minutes of configuration and costs nothing: it is one of the best effort-to-risk ratios on the whole network.

The firewall, and what it does not do

A dedicated firewall brings a real gain on a network of several dozen machines, with logging and fine-grained filtering. On a five-machine setup, it is often oversized against the real need - and it protects against nothing if the machine is infected by an attachment, which remains the dominant scenario.

So we prefer to deal first with what pays off most: remote access, passwords, separation, backups. A firewall comes afterwards, when the size justifies it. See small business IT security.

What is left after an incident

Network security reduces the likelihood and the scale of an incident, it does not remove it. What determines what happens next is the ability to start again: an offline backup, tested, and documentation of the setup. Those two things are worth more, when things go badly, than any piece of equipment. See business backup and ransomware protection.

The human factor, here too

No amount of separation protects against a password shared on a sticky note, or an employee plugging in a USB stick found in the car park. Technology reduces the exposed surface, it does not replace a few shared reflexes in the team.

So we always spend a moment with the users: recognizing a fraudulent message, knowing who to report a doubt to, understanding why the visitor network exists. It takes little time, and it is what holds the rest together. See training.

How we go about it

A review of the network first: what is exposed, what talks to what, which equipment is up to date. Then a list of corrections ranked by effort against risk avoided - several are free and take a few minutes. You choose what to put in place. See security audit.

Frequently asked questions about this service

Our business is small, are we really a target?

The question no longer works that way: the attacks are automated and sweep the internet without choosing. An organization is hit because it is reachable, not because it was singled out.

Should we invest in a business firewall?

It depends on the size. On a small setup, dealing with remote access, passwords and separating uses brings far more, for far less.

Is remote desktop dangerous?

Exposed directly to the internet, yes, it is one of the most exploited ways in. Routed through an encrypted tunnel with two-factor authentication, it becomes perfectly acceptable.

How long does securing a network take?

The review takes half a day. The priority corrections are often handled straight afterwards, the structural changes are then scheduled.

Can't find your question? It may be in our full FAQ.

Going further

Everything worth knowing before you hand over your equipment.

Remote access that has been open for a long time?

It is the first thing we look at, and the one most often found wanting.

Contact Us