A trading company in Al Qusais has 14 staff, an ISP router, one shared Wi‑Fi name, a NAS full of invoices, 2 printers and 6 cameras. A salesperson offers a new firewall. In our experience the box is rarely the first gap; the gaps are a default password, a port opened years ago, a login shared by 5 people. This is the network security checklist small business owners can run first: 12 checks to finish before buying anything, and where a specialist earns the fee.
Quick Answer
In our experience a small office is safer after 12 basic checks than after a bigger firewall. List every device and its owner. Lock the router’s admin panel and update its firmware. Put Wi‑Fi on WPA2 or WPA3 with a separate guest network, and move cameras and printers to their own segment. Give every person their own account, with admin rights only where needed and two-factor authentication on email, VPN and admin panels. Close remote desktop to the internet and use a VPN. Patch on a schedule, run endpoint protection, keep one backup copy offline and test a restore. Remove leavers the same day. Then check which ports the internet sees. Repeat the list every quarter.
Why Small Offices Get Breached
In the offices we are called to, the cause is seldom clever. It is usually one of 5.
Defaults and open doors. The router keeps the password on its label, or an old port-forward to remote desktop or the NAS is still open.
Shared accounts. One login for the accounts system, one mailbox password for the sales team, so nobody can be removed.
A flat network. The camera recorder, guest phones and the accounts PC share one network, so a weak device reaches the rest.
No owner for updates. Laptops update themselves; the router, the NAS and the recorder often do not.
Leavers who keep access. A former employee still knows the Wi‑Fi key and the shared mailbox password months later.
Network Security Checklist for Small Business: Checks 1 to 4
1. List every device and who owns it. PCs, phones with company email, the NAS, printers, cameras. CISA’s Cyber Essentials guide for small businesses starts here too: keep inventories of hardware and software. A spreadsheet is enough; a device without an owner is a device nobody updates.
2. Lock the router or firewall. Change the default admin password, make sure the admin page cannot be reached from the internet, and install current firmware. If the ISP manages the router, ask in writing who holds the password.
3. Put Wi‑Fi on WPA2 or WPA3, with a guest network. Use a long key, not the company name. The Wi‑Fi Alliance says WPA3-Personal gives increased protection from password guessing, so choose it where every device supports it. Visitors and personal phones go on the guest network.
4. Give cameras, printers and TVs their own segment. A separate VLAN, with rules between segments, lets the recorder reach what it needs and nothing else. If it is ever compromised, the accounts PC is not one hop away.
Checks 5 to 8: Lock the Accounts and the Doors
5. One account per person. No shared logins; admin rights only for the people who install software.
6. Two-factor authentication on email, VPN and admin panels. CISA advises requiring it for all users, starting with privileged, administrative and remote access users. Our guide to two-factor authentication for business covers which accounts come first.
7. No remote desktop or NAS admin open to the internet. CISA’s ransomware guide says plainly: do not expose services such as remote desktop protocol on the web. Remote work goes through a VPN, with two-factor on the VPN.
8. Updates on a schedule. Laptops, servers, the router, the NAS and the camera recorder. Write the last update date beside each device in your list, and give the job to a named person.
Checks 9 to 12: Prepare for the Bad Day
9. Endpoint protection on every PC and Mac. Managed from one console, so you see which machine stopped reporting.
10. Backups with one copy offline or immutable, and a restore test. Ransomware often hunts for backups it can reach. Keep one copy it cannot, and restore a real folder every quarter. Our backup solutions cover servers, workstations and mailboxes on a schedule you choose.
11. A leaver process the same day. Disable the accounts, collect the devices, and change any password the person knew, including a shared Wi‑Fi key.
12. An outside check. Scan your office’s public IP from outside and list the open ports. Anything you cannot explain is closed or moved behind the VPN.
| Check | Do it yourself? | How often | Sign it is done |
|---|---|---|---|
| 1. Device list | Yes | Quarterly | Every device has an owner |
| 2. Router locked | Partly | Quarterly | Admin password changed |
| 3. Wi‑Fi and guest | Yes | Quarterly; after leavers | Visitors off the office network |
| 4. Device VLAN | Specialist | Quarterly | Cameras cannot reach PCs |
| 5. Own accounts | Yes | Quarterly | No shared logins |
| 6. Two-factor | Yes | Quarterly | On email, VPN, admin panels |
| 7. No open RDP | Specialist | Quarterly | Remote work only by VPN |
| 8. Updates | Partly | Monthly | Update date on every device |
| 9. Endpoint protection | Yes | Monthly | Every machine reporting |
| 10. Backups | Partly | Quarterly test | A file restored |
| 11. Leavers | Yes | Every leaver | Access removed the same day |
| 12. Outside check | Specialist | Quarterly | Every open port explained |
What to Hand to a Specialist
Most of the list is discipline, not engineering. 5 items are worth paying for, because mistakes in them stay invisible: firewall rule review (why does each rule exist?), VPN design (who connects, from which devices, reaching what), segmentation (separating cameras, guests and staff without breaking printing), a penetration test (an attempt to get in, written up) and monitoring (someone reads the alerts at night).
Our network security service covers firewall setup and policy review, VPN for remote access, vulnerability assessments and penetration testing, and audit and incident reports. The UK NCSC’s Cyber Essentials scheme reduces the same ground to 5 technical controls: firewalls, secure configuration, security updates, user access control and malware protection. If your list is complete and your office is small, a yearly review may be all you need.
The other question is who runs the list every month. Our FAQ explains how our Annual Maintenance Contract covers networks, servers and workstations with a guaranteed response time, with onsite support in Dubai, Sharjah and Ajman and remote support anywhere.
The UAE Angle: Customer Data Is Your Responsibility
The UAE’s Personal Data Protection Law, Federal Decree-Law No. 45 of 2021, sets a framework to keep personal information confidential and obliges companies holding personal data to secure it. Customer records on your NAS and in your mailboxes are such data. This is not legal advice; the practical side is in our articles on the UAE data protection law and your website and the UAE website security requirements. The 12 checks are the office-network half of the same duty.
From Our Work
A NAS reachable from the internet. During a network review we found an office’s NAS admin page could be opened from any browser in the world, through a port-forward an old installer had left in the router. We closed the forward and moved remote access to the NAS behind a VPN. If several installers have worked on your network, assume a forgotten forward exists until check 12 proves otherwise.
Cameras beside the accounts PC. A company had its CCTV recorder and the accounts PC on the same flat network. We separated them with a guest and IoT VLAN: the recorder on one side, staff machines on the other. If you plan the same split, first list what must still talk across the line, such as a shared printer.
A leaver who never left. A former employee’s shared Wi‑Fi password and shared mailbox login kept working for months, because nothing was personal. We replaced the shared logins with per-person accounts and wrote a leaver checklist for every departure, so access now ends with the person, not with the next password change.
Frequently Asked Questions
What should a network security checklist for a small business include?
Who owns each device, a locked router, WPA2 or WPA3 Wi‑Fi with a guest network, cameras on their own segment, personal accounts with two-factor authentication, no remote desktop open to the internet, scheduled updates, endpoint protection, a tested offline backup, same-day leaver removal and an outside port check.
Do I need a firewall for a small office in Dubai?
Your ISP router usually includes a basic one. The question is whether it is configured: default password changed, admin page closed to the internet, no forgotten port-forwards. In our experience many offices of 5 to 50 people need the 12 checks done before they need a dedicated firewall. A specialist review shows which case is yours.
How often should a small office review its network security?
Run the full list every quarter, and the account and Wi‑Fi checks whenever someone leaves. Updates and endpoint protection need a monthly look. Put a named person and a date against each check, because in our experience a list without an owner stops after the first quarter.
Is it safe to use remote desktop to work from home?
Not when remote desktop is opened directly to the internet; CISA advises against exposing it on the web. Connect through a VPN first, with two-factor authentication on the VPN, then use remote desktop inside the office network. Close any remote desktop port-forward you find in the router, even one called temporary.
What should we do if we think we have already been hacked?
Do not wipe or reinstall anything yet. Disconnect the affected machine from the network, change passwords from a clean device, and call your IT provider so the evidence is kept. Our first-hour response runbook is written for websites, but its order of steps applies to an office network too.
Sources
- Cyber Essentials — Cybersecurity and Infrastructure Security Agency (CISA) (accessed 2026-10-03)
- #StopRansomware Guide — Cybersecurity and Infrastructure Security Agency (CISA) (accessed 2026-10-03)
- Security — Wi‑Fi Alliance (accessed 2026-10-03)
- Cyber Essentials overview — UK National Cyber Security Centre (accessed 2026-10-03)
- Small organisations guide to cyber security — UK National Cyber Security Centre (accessed 2026-10-03)
- Data protection laws — UAE Government Portal (u.ae) (accessed 2026-10-03)
Where We Are
BIGBANG ITS has planned and run technology for UAE businesses since 2003, headquartered at the Sharjah Research, Technology and Innovation Park with a branch in Business Bay, Dubai. Support runs 24/7 and the office is open Saturday to Thursday, 09:00–18:00 Gulf time. For a network review sized to your office, send us your device list or ask us to build it with you, contact us or call +971 4 378 2255.
Talk to us directly — we usually reply within minutes during business hours.










