About this interactive
Every piece of equipment arrives with vulnerabilities. It left the factory weeks or months ago, so its firmware, operating system and software are already out of date, with known flaws people can use. And it arrives with everything turned on, because the maker wants it to work with as few steps as possible.
What to harden: everything you put on the network. Firewalls, routers, switches, wireless access points and controllers, VoIP phones, servers, laptops and desktops, copiers and printers, cameras, IoT appliances.
The general steps (each kind of device has its own details to look up):
- Patch the firmware, operating system and software.
- Change the default passwords.
- Disable or remove unneeded hardware, ports, services and functions.
- Set a BIOS password and the boot order, so nobody can change the settings or boot from their own USB stick and bypass your security.
- Remove bloatware and any malicious code.
- Validate software sources: download from the maker (the OEM), or make sure a third-party site is legitimate, and check the file's hash against the value the maker publishes. (A hash posted on the same untrusted site as the file proves little.)
A baseline is the standard each kind of device is raised to: the minimum you must do to put it on the network securely, written up as a checklist for switches, firewalls, laptops and so on.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →