Network Security Checklist for Small Businesses
Use this network security checklist to reduce risk, secure Wi-Fi and remote access, manage firewall policies, and keep business operations protected daily.
A network security checklist should begin with the systems your business cannot afford to lose: payment terminals, patient or client records, line-of-business applications, cameras, phones, and internet connectivity. A firewall alone does not protect those systems if wireless access is open, remote users are unmanaged, old accounts remain active, or security updates are delayed. The objective is to build a network that is secure, supportable, and reliable during normal operations and during an incident.
Start With a Complete Network Inventory
Security decisions are only as good as the inventory behind them. Document every internet circuit, firewall, switch, wireless access point, server, workstation, printer, phone, camera, cloud application, and third-party connection. Include the device owner, physical location, management IP address, firmware version, serial number, and support or license status where applicable.
This is especially relevant for businesses that have grown in stages. It is common to find an older wireless router still broadcasting, a switch installed for an office expansion, or a vendor VPN account that was never removed. These devices may not appear in day-to-day IT discussions, but they can create an unmanaged path into the network.
The inventory should also identify where sensitive data moves. A medical practice may need to separate clinical systems from guest Wi-Fi. A restaurant may need to isolate payment card systems from point-of-sale support devices and public internet access. A law office may need tighter controls around document storage and remote file access. The design depends on the business, but the visibility requirement is the same.
Network Security Checklist: Identity and Access
Most security incidents involve a valid account, whether it was guessed, stolen, reused, or left active after an employee or vendor departed. Start by reviewing every account that can access the network, firewall, cloud administration portals, VPN, and critical business applications.
Require multi-factor authentication for remote access, administrator accounts, email, cloud services, and any application that supports it. Avoid shared administrative credentials. Each person who administers a FortiGate firewall, switch, wireless platform, or business application should use an individual account so activity can be traced and access can be removed cleanly.
Review user access when roles change, not only during an annual audit. Disable accounts promptly when staff leave, including accounts held by outsourced IT providers, software vendors, alarm companies, and cabling contractors. Vendor access is sometimes necessary, but it should be limited to the required system, approved for a defined period, and protected with MFA.
Password requirements should balance security with practical adoption. Long, unique passphrases managed through an approved password manager are generally more effective than frequent forced password changes that lead users to predictable variations. Privileged accounts should have stronger controls than standard user accounts.
Harden the Firewall and Review Policy Hygiene
The firewall is where business requirements must be translated into enforceable security policy. Review firewall rules for purpose, source, destination, service, logging, and expiration. Rules that allow any source, any destination, or broad service access deserve particular scrutiny. They may have been created during troubleshooting and never revisited.
For a FortiGate environment, confirm that FortiGuard security services are licensed and active as appropriate for the organization. Common controls include intrusion prevention, web filtering, application control, antivirus inspection, DNS filtering, and botnet protections. Turning on every inspection feature without considering hardware capacity can affect performance, so protection profiles should be sized and tested against the firewall model, internet bandwidth, and traffic patterns.
Administrative management should not be exposed broadly to the internet. Restrict management access to approved internal networks or secure VPN connections, use encrypted protocols, and disable services that are not required. Confirm that configuration backups are current, encrypted, and stored where they can be recovered during a hardware failure or ransomware event.
Firmware management also belongs in the checklist. A current firmware version is not automatically the right version if it has not been validated for the deployed model and features. Establish a maintenance window, review release notes, back up configurations, and have a rollback plan before upgrades.
Segment the Network and Secure Wireless Access
Flat networks make lateral movement easy. If a compromised guest device can reach accounting workstations, cameras, file shares, and payment devices, one problem can spread through the environment quickly. VLAN segmentation limits that exposure by separating systems according to their function and trust level.
A practical small-business design may separate corporate workstations, servers, voice, security cameras, point-of-sale or payment devices, guest Wi-Fi, and network management. Segmentation does not end with creating VLANs. Firewall rules between those VLANs must allow only necessary traffic. For example, guest Wi-Fi should normally receive internet access only, while cameras may need access to a recorder but not to employee laptops.
Wireless networks should use modern encryption, unique credentials, and separate staff and guest SSIDs. Avoid sharing a single Wi-Fi password across every employee, contractor, and visitor. Where the wireless platform supports it, use individual authentication or time-limited guest access. Disable outdated wireless security modes and review access point placement to prevent coverage gaps that encourage staff to use unauthorized hotspots.
Control Remote Access and Third-Party Connectivity
Remote work, mobile staff, and cloud applications have made secure access design a business continuity issue. A VPN should authenticate users with MFA, limit access based on role, and log successful and failed connections. Remote users should reach only the systems they need, rather than receiving unrestricted access to the full internal network.
For organizations with multiple locations, SD-WAN can improve availability by using more than one internet connection and steering traffic based on performance. It also requires careful policy design. A backup circuit should not become an unmonitored path that bypasses security inspection or exposes management services.
Third-party connections need the same discipline. Document why each connection exists, who owns it, what data it can reach, and when it should be reviewed. A permanent, unrestricted vendor tunnel may be convenient, but it increases risk long after the original support project ends.
Protect Endpoints, Data, and Recovery Paths
Network controls work best when endpoints are managed as part of the same security program. Maintain supported operating systems, deploy endpoint protection, enforce screen locks, encrypt portable devices, and remove local administrator rights where they are not required. FortiClient EMS or another centralized endpoint management platform can help organizations apply consistent posture and access controls, particularly for remote users.
Backups are equally critical. Verify that important data, firewall configurations, cloud application data, and critical servers are backed up on a defined schedule. Keep at least one backup copy protected from routine network access. A backup that is always reachable from an administrator workstation may be encrypted alongside production data during a ransomware incident.
Test recovery rather than relying on a backup dashboard. Restore a sample file, validate access to a key application, and confirm that the staff responsible for recovery knows where credentials, encryption keys, network diagrams, and vendor contacts are stored.
Monitor, Log, and Maintain the Environment
A security event cannot be investigated if there is no usable record of what happened. Configure firewall, VPN, wireless, switch, and endpoint logs with appropriate retention. A platform such as FortiAnalyzer can centralize security events, improve reporting, and help identify unusual activity across the environment.
Monitoring should focus on actionable conditions: repeated failed VPN logins, new administrator accounts, firewall policy changes, endpoint detections, internet circuit failures, and devices appearing on restricted VLANs. Alerts without an owner become background noise, so define who reviews them and what escalation path applies after hours.
Configuration changes should follow a simple operational process. Record the reason for the change, the person making it, the affected systems, the backup status, and the rollback steps. This discipline reduces troubleshooting time and provides useful evidence for PCI DSS, NIST, CIS, or other compliance-aligned reviews.
Set a Review Cadence That Fits the Business
Some controls need daily attention, while others need scheduled review. Critical alerts, endpoint detections, failed backups, and internet outages should be addressed immediately. Monthly work can include reviewing firewall changes, validating active VPN users, checking firmware advisories, and confirming security subscriptions. Quarterly reviews are a good time to assess dormant accounts, vendor access, VLAN rules, wireless settings, and recovery testing.
A yearly review remains valuable for risk assessment, documentation updates, lifecycle planning, and budget decisions. However, an annual assessment alone will not catch the policy added during a weekend troubleshooting call or the employee account that remained active after a departure.
The most useful checklist is one your team can maintain. Start with the controls that protect revenue, sensitive data, and connectivity, assign clear ownership, and turn findings into scheduled remediation work. Security improves when network operations are treated as an ongoing engineering responsibility rather than a project completed once.
Need help applying this to your business network? Share your equipment, location and project goals with Kamanel Consulting.
