Office network security starts with knowing what is connected and who administers it. A strong Wi-Fi password is useful, but it does not answer questions about guest access, remote management or unsupported equipment.
Draw the practical connection map
List the internet connection, router or firewall, switches, wireless access points and important connected systems. Include printers, recorders, cameras and devices installed by suppliers. The first map can be simple as long as it identifies ownership and important dependencies.
Do not publish detailed network diagrams or credentials in an initial enquiry. A general description is enough to scope a review; sensitive configuration can be examined through an authorised method later.
Ask beyond the wireless password
| Area | Question for the responsible administrator |
|---|---|
| Administration | Who owns management accounts and how is access reviewed? |
| Guest use | How is visitor connectivity separated from business resources where supported? |
| Connected equipment | Which printers, cameras and appliances need which connections? |
| Remote access | Which remote routes are necessary and who can use them? |
| Updates | Who tracks supported firmware and security advisories? |
| Configuration | Is there an approved record and recovery copy of important settings? |
Separate availability symptoms from security decisions
Slow Wi-Fi may involve radio conditions, device behaviour, network congestion or the internet provider. A security review and a performance diagnosis can share an inventory, but they are not interchangeable. Avoid replacing equipment or weakening controls without understanding the symptom.
For example, turning off a restriction may make a device connect while creating access the business never intended. Identify the required communication and configure a supported route through an authorised change instead of leaving a broad exception.
Review supplier-installed devices
A CCTV recorder or access appliance can remain on the network long after its installer’s account is forgotten. Ask who owns the administrator credentials, update process and remote-access arrangement. Confirm what happens when the supplier relationship ends.
Where separation or firewall rules are appropriate, they need a design supported by the actual equipment and operational requirements. This guide does not supply generic rules to paste into a production firewall. A mistake can interrupt essential services or expose them unnecessarily.
Accept evidence that matches the scope
- An inventory and connection map with known gaps.
- A record of authorised administrative and remote access.
- Approved configuration changes and their test results.
- A list of unsupported equipment or unresolved dependencies.
- The owner for maintenance and future additions.
Use the resulting action list to prioritise work. A diagram and a few screenshots are useful only when they describe the real environment and lead to accountable next steps.
Sources and further reading
Put the decision into practice
Describe the sites, network equipment and remote-access needs for a scoped review.
Explore Managed Cybersecurity Discuss the requirement by email