Endpoint security starts with understanding which devices on a network require protection and how to harden them against attack. This covers the full scope of endpoints — from workstations and servers to mobile devices, IoT systems, and managed network infrastructure.
Endpoint Security
What are these endpoints? Let's make sure we have a good definition of what these endpoints are, so we get a scope of what we're talking about.
Let's first get into what nodes are when it comes to networking. Nodes are any devices that are going to send, receive, transfer or pass on any kind of network communication. So in this case right here, we've got computers that are sending and receiving, servers, switches, routers — any of these devices are all nodes on this network.
We can essentially break down nodes into two different categories: intermediary devices and end devices. End devices are all of these devices that are sitting at the end of the network that are really built to send and receive the data. They're either the source or the destination of most of our traffic. Then what we have is the intermediary devices. Intermediary devices are the switches and the routers that are helping facilitate this communication.
So here we have a PC right here that's communicating to this server right here. These are the end devices within here. And then the intermediary devices are what is transferring the data back and forth between these devices.
From a cyber security perspective, this is mainly what we're trying to protect. We have these resources here — these endpoints, or you hear me call them endpoints or end devices. These end devices or endpoints are what's transferring the data, but they're also what stores that asset, and so these are largely what we're trying to protect.
What we want to do is go through the process of hardening these devices. Hardening is when we're securing these, when we're locking them down, when we're making sure that they're going to be resilient to an attack, so if they get attacked, they're not going to be susceptible to those types of attack. So we want to go through a hardening process to be able to secure these devices.
The thing is that we have intermediary devices that could be susceptible to certain types of attacks as well, and because of that we want to harden those as well. So for the purpose of this module, we're going to actually include these inside of our endpoints. When we're talking about hardening endpoints, we're also talking about hardening these intermediary devices, if they're something that can be managed and something that we can get into.
Usually routers — almost always routers — we're managing those. Those are something that can be manageable, so we need to harden those devices. If a switch is a managed switch, then we need to harden those as well. If it's an unmanaged switch, then maybe we don't need to be as concerned about that.
So we're going to be really talking about hardening these different devices and what steps we can do to do that, and we're going to include a lot of these intermediary devices. Here's a list of those devices that we would want to consider hardening:
Any device that's sitting on our network, we want to start thinking about how we would go about hardening those.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →