How secure configuration, wireless segmentation, device management, updates, and media handling reduce endpoint and small-office risk.
Security controls should match the asset, exposure, and operational need. Prioritize supported encryption, access control, current firmware and software, and segmentation over obscurity or convenience settings.
| Area | Practical control |
|---|---|
| Wi-Fi | Use a supported strong security mode and isolate guest access |
| Router | Change default credentials, update firmware, limit management exposure, and disable unneeded services |
| Mobile device | Screen lock, encryption, supported updates, and managed policy where appropriate |
| Browser and endpoint | Patching, controlled extensions, and safe download practices |
| Retired media | Sanitization or destruction appropriate to the data and media type |
NIST wireless guidance recommends separating guest and internal WLANs so guest devices cannot reach internal systems through the guest network. See NIST SP 800-153.