Infrastructure Security

Home & Small Office Network Hardening

Your router is the front door to every device on your network. We configure it like a perimeter firewall — segmenting traffic, encrypting DNS, isolating IoT devices, and closing the ports attackers probe first. On-site service in the Detroit metro area, or guided video sessions for cloud-managed hardware.

How It Works

1

We Map Your Network

We identify every device on your network, document your current router configuration, check firmware versions, and scan for exposed services. This becomes your baseline network topology.

2

We Harden Layer by Layer

Router credentials, WiFi security, DNS encryption, network segmentation, and monitoring — each layer addressed in order. For Firewalla/UniFi setups, we configure remotely. For consumer routers, we guide you through the admin panel live.

3

We Segment Your Traffic

IoT devices (cameras, smart speakers, thermostats) get isolated from your work devices. Guest traffic stays separate. VLANs or guest networks configured depending on your hardware capabilities.

4

We Verify & Document

Port scan from outside to confirm nothing unexpected is exposed. DNS leak test to confirm encryption. Every change documented with before/after configuration. You receive a full network topology diagram and written report.

Defense in Depth — Layer by Layer

We harden your network at every layer, from the ISP handoff to the device level.

1

Router & Gateway

The first line of defense. Most routers ship with default credentials and outdated firmware.

  • Firmware updated to latest stable release
  • Default admin credentials changed
  • Remote management disabled
  • UPnP disabled (prevents automatic port opening)
  • WPS disabled (brute-force vulnerability)
  • Admin interface bound to LAN only
2

WiFi Security

Wireless is the most common entry point for attackers within physical range.

  • WPA3 enforced (WPA2-AES minimum)
  • Strong passphrase (20+ characters)
  • Guest network isolated for visitors
  • Hidden SSID evaluation
  • Connected device audit & unknown removal
3

Network Segmentation

IoT devices should never share a network with your work devices.

  • VLAN configuration (IoT / Trusted / Guest)
  • IoT devices isolated from admin traffic
  • Inter-VLAN routing rules defined
  • Smart home devices contained
  • Work devices on dedicated segment
4

DNS & Traffic Security

DNS is how attackers redirect you to phishing sites and how malware phones home.

  • Encrypted DNS (DoH/DoT) configured
  • Ad & malware domains blocked at network level
  • Pi-hole or NextDNS setup (optional)
  • DNS leak testing verified
  • Outbound port restrictions where supported
5

Monitoring & Alerting

You can't defend what you can't see.

  • Router logging enabled and reviewed
  • New device connection alerts
  • Port scan detection (where supported)
  • Network map documented
  • Periodic scan schedule established

Two Service Levels

Choose based on your network complexity and security needs.

Standard — Home Network

  • Single router configuration
  • WiFi security hardening
  • DNS encryption setup
  • Guest network creation
  • Connected device audit
  • Firmware update
  • Port scan & close unnecessary services
  • Written config report

Advanced — SOHO / Multi-AP

  • Everything in Standard, plus:
  • VLAN segmentation (IoT / Trusted / Guest)
  • Multiple access point configuration
  • Pi-hole or NextDNS deployment
  • Network monitoring setup
  • Firewall rule creation
  • Bridge mode / double-NAT resolution
  • Network topology diagram

Sample Completion Report

Every engagement includes a completion report documenting what was changed and verified.

Completion Report

Network Hardening — SOHO

Router hardening, VLAN segmentation, DNS encryption, and monitoring configuration for home office network.

Overview

Full network hardening session covering router gateway security, WiFi upgrade, VLAN segmentation (3 segments), encrypted DNS deployment, and monitoring setup. External port scan confirmed no exposed services. All devices verified on correct network segments post-implementation.

5
Layers Hardened
3
VLANs Created
14
Devices Mapped
0
Open Ports (External)
ControlBeforeAfterStatus
Router Firmwarev2.1.3 (18 months old)v3.0.1 (current)Updated
WiFi ProtocolWPA2-TKIPWPA3Upgraded
DNSISP default (unencrypted)NextDNS (DoH, ad-blocking)Complete
Network SegmentationFlat (all on one subnet)3 VLANs (IoT/Trusted/Guest)Complete
UPnPEnabledDisabledFixed
Admin Credentialsadmin/adminUnique 20+ char passphraseFixed

What You Get

  • Full router hardening (firmware, credentials, UPnP, WPS, remote management)
  • WiFi security upgraded to WPA3 or WPA2-AES with strong passphrase
  • DNS encrypted and ad/malware blocking active at the network level
  • Network segmentation — IoT, Trusted, and Guest segments isolated
  • Connected device inventory with MAC addresses and assigned VLANs
  • External port scan confirming no exposed services
  • Network topology diagram showing all segments and devices
  • Before/after configuration documentation
  • Written report with all changes and maintenance recommendations