Infrastructure Security
Home & Small Office Network Hardening
Your router is the front door to every device on your network. We configure it like a perimeter firewall — segmenting traffic, encrypting DNS, isolating IoT devices, and closing the ports attackers probe first. On-site service in the Detroit metro area, or guided video sessions for cloud-managed hardware.
How It Works
We Map Your Network
We identify every device on your network, document your current router configuration, check firmware versions, and scan for exposed services. This becomes your baseline network topology.
We Harden Layer by Layer
Router credentials, WiFi security, DNS encryption, network segmentation, and monitoring — each layer addressed in order. For Firewalla/UniFi setups, we configure remotely. For consumer routers, we guide you through the admin panel live.
We Segment Your Traffic
IoT devices (cameras, smart speakers, thermostats) get isolated from your work devices. Guest traffic stays separate. VLANs or guest networks configured depending on your hardware capabilities.
We Verify & Document
Port scan from outside to confirm nothing unexpected is exposed. DNS leak test to confirm encryption. Every change documented with before/after configuration. You receive a full network topology diagram and written report.
Defense in Depth — Layer by Layer
We harden your network at every layer, from the ISP handoff to the device level.
Router & Gateway
The first line of defense. Most routers ship with default credentials and outdated firmware.
- Firmware updated to latest stable release
- Default admin credentials changed
- Remote management disabled
- UPnP disabled (prevents automatic port opening)
- WPS disabled (brute-force vulnerability)
- Admin interface bound to LAN only
WiFi Security
Wireless is the most common entry point for attackers within physical range.
- WPA3 enforced (WPA2-AES minimum)
- Strong passphrase (20+ characters)
- Guest network isolated for visitors
- Hidden SSID evaluation
- Connected device audit & unknown removal
Network Segmentation
IoT devices should never share a network with your work devices.
- VLAN configuration (IoT / Trusted / Guest)
- IoT devices isolated from admin traffic
- Inter-VLAN routing rules defined
- Smart home devices contained
- Work devices on dedicated segment
DNS & Traffic Security
DNS is how attackers redirect you to phishing sites and how malware phones home.
- Encrypted DNS (DoH/DoT) configured
- Ad & malware domains blocked at network level
- Pi-hole or NextDNS setup (optional)
- DNS leak testing verified
- Outbound port restrictions where supported
Monitoring & Alerting
You can't defend what you can't see.
- Router logging enabled and reviewed
- New device connection alerts
- Port scan detection (where supported)
- Network map documented
- Periodic scan schedule established
Two Service Levels
Choose based on your network complexity and security needs.
Standard — Home Network
- Single router configuration
- WiFi security hardening
- DNS encryption setup
- Guest network creation
- Connected device audit
- Firmware update
- Port scan & close unnecessary services
- Written config report
Advanced — SOHO / Multi-AP
- Everything in Standard, plus:
- VLAN segmentation (IoT / Trusted / Guest)
- Multiple access point configuration
- Pi-hole or NextDNS deployment
- Network monitoring setup
- Firewall rule creation
- Bridge mode / double-NAT resolution
- Network topology diagram
Sample Completion Report
Every engagement includes a completion report documenting what was changed and verified.
Network Hardening — SOHO
Router hardening, VLAN segmentation, DNS encryption, and monitoring configuration for home office network.
Overview
Full network hardening session covering router gateway security, WiFi upgrade, VLAN segmentation (3 segments), encrypted DNS deployment, and monitoring setup. External port scan confirmed no exposed services. All devices verified on correct network segments post-implementation.
| Control | Before | After | Status | |
|---|---|---|---|---|
| Router Firmware | v2.1.3 (18 months old) | → | v3.0.1 (current) | Updated |
| WiFi Protocol | WPA2-TKIP | → | WPA3 | Upgraded |
| DNS | ISP default (unencrypted) | → | NextDNS (DoH, ad-blocking) | Complete |
| Network Segmentation | Flat (all on one subnet) | → | 3 VLANs (IoT/Trusted/Guest) | Complete |
| UPnP | Enabled | → | Disabled | Fixed |
| Admin Credentials | admin/admin | → | Unique 20+ char passphrase | Fixed |
What You Get
- Full router hardening (firmware, credentials, UPnP, WPS, remote management)
- WiFi security upgraded to WPA3 or WPA2-AES with strong passphrase
- DNS encrypted and ad/malware blocking active at the network level
- Network segmentation — IoT, Trusted, and Guest segments isolated
- Connected device inventory with MAC addresses and assigned VLANs
- External port scan confirming no exposed services
- Network topology diagram showing all segments and devices
- Before/after configuration documentation
- Written report with all changes and maintenance recommendations