Firewall Configuration: Your First Line of Defense
A firewall sits between your internal network and the internet, inspecting every packet of data that enters or leaves your business. If you are running a consumer-grade router from Spectrum or Verizon with its default settings, you are getting the bare minimum of protection. A business-grade firewall provides granular control over what traffic is allowed, detailed logging for troubleshooting and incident investigation, and advanced features like intrusion prevention.
For small to mid-size businesses in Erie County, we typically recommend Ubiquiti UniFi or Fortinet FortiGate firewalls depending on the complexity of the environment. A proper firewall configuration includes blocking all inbound traffic except what your business specifically requires, setting up outbound filtering to prevent malware from communicating with command-and-control servers, enabling logging so you have a record of network activity, and configuring alerts for suspicious patterns like repeated failed login attempts or unusual data transfers.
Warning Sign: If you cannot tell us who last updated your firewall rules, or if your firewall is still using the configuration it had when it was installed years ago, your network security likely has significant gaps. Firewall rules should be reviewed and updated at least quarterly.
Network Segmentation: Limiting the Blast Radius
Network segmentation means dividing your network into separate zones so that a breach in one area cannot easily spread to others. Think of it as compartments in a ship. If one compartment floods, the others stay dry. Without segmentation, an attacker who compromises a single employee's workstation can potentially reach your financial systems, customer databases, and backup servers all from the same network.
A well-segmented small business network typically has at least three or four VLANs (virtual local area networks). Your business operations VLAN handles workstations and printers. A separate server VLAN isolates your file servers and databases with stricter access controls. Your guest Wi-Fi VLAN provides internet access to visitors without any path to your internal systems. And if you have IoT devices like security cameras, smart thermostats, or connected displays, an IoT VLAN keeps those devices isolated since they are frequently targeted and rarely receive security updates.
Setting up VLANs requires managed switches and proper firewall rules between segments. It sounds complex, but for a typical 10 to 30 person office, the initial configuration takes just a few hours and the ongoing maintenance is minimal.
VPN for Secure Remote Access
With more Erie County businesses adopting hybrid work arrangements, secure remote access has become essential. A Virtual Private Network (VPN) creates an encrypted tunnel between a remote employee's device and your office network, protecting sensitive data as it travels across the internet.
There are two main approaches for small business VPN. A site-to-site VPN connects two office locations over an encrypted link, useful if you have a second office or a data center. A remote access VPN lets individual employees connect from home or on the road. Modern solutions like WireGuard offer significantly better performance than older protocols like IPSec or OpenVPN, with connection speeds fast enough that remote employees do not notice they are on a VPN.
The key configuration details that matter: require certificate-based authentication rather than just a username and password, enable split tunneling selectively so only business traffic goes through the VPN (improving speed for personal browsing), and set up automatic disconnection after a period of inactivity to reduce the window of exposure if a device is lost or stolen.
Intrusion Detection and Network Monitoring
A firewall blocks known threats at the door, but intrusion detection systems (IDS) and intrusion prevention systems (IPS) watch for suspicious behavior inside your network. They analyze traffic patterns and flag anomalies like a workstation suddenly scanning other devices on the network, large volumes of data being transferred to an unfamiliar external address, or login attempts happening at unusual hours from unusual locations.
For Erie County businesses that do not have a dedicated IT security team, we deploy monitoring solutions that combine IDS/IPS with centralized logging and automated alerting. When something suspicious happens, the system sends an alert to our team and we investigate before it becomes a full-blown incident. This is far more practical than expecting a business owner or office manager to monitor network logs throughout the day.
Wi-Fi Security and Guest Network Best Practices
Wireless networks are a frequent weak point because they extend your network beyond the physical walls of your office. Anyone in your parking lot with the right tools can attempt to connect to a poorly secured Wi-Fi network. Proper Wi-Fi security starts with using WPA3 encryption (or WPA2-Enterprise at minimum), disabling WPS (Wi-Fi Protected Setup, which has known vulnerabilities), and using a strong, unique passphrase that is changed whenever an employee with access leaves the company.
Your guest network deserves special attention. Clients, vendors, and visitors will ask for Wi-Fi access, and you should absolutely provide it, but never on your business network. Set up a completely separate guest SSID that provides internet access through its own VLAN with no route to your internal resources. Apply bandwidth limits so a guest streaming video does not slow down your business operations, and consider enabling a captive portal that requires guests to accept an acceptable use policy before connecting.
Quick Audit: Open your phone's Wi-Fi settings and see how many networks are broadcasting from your office. If you see old SSIDs from previous equipment, networks with weak or no encryption, or your business SSID visible from the sidewalk at full signal strength, you have security improvements to make.
Vulnerability Scanning: Finding Problems Before Attackers Do
A vulnerability scan is like a health checkup for your network. It systematically checks your devices, servers, and software for known security weaknesses, such as missing patches, outdated firmware, default credentials, open ports that should be closed, and misconfigured services. Running regular vulnerability scans helps you find and fix problems proactively rather than discovering them during a breach.
For small businesses, we recommend running internal vulnerability scans monthly and external scans quarterly. Internal scans check devices on your network from the inside, while external scans probe your public-facing systems from the internet, simulating what an attacker would see. The results are prioritized by severity so you know what to fix first. Critical vulnerabilities like unpatched remote code execution flaws should be addressed immediately. Lower-severity items like informational disclosures can be scheduled into your regular maintenance window.
Common findings from vulnerability scans of Erie County businesses include printers with default admin passwords accessible from the network, Windows workstations missing security updates from months ago, old servers running end-of-life operating systems with no security patches available, and network devices with management interfaces exposed to the internet. Each of these is fixable, but you have to know they exist first.
IT Service Areas — Erie County
Driram Group provides network security services to businesses throughout Erie County, including: