DEVICE SECURITY CyberArtical Editorial Team

How one compromised device reaches the rest of a small office

Yellow fibre-optic cables looping in front of dark rack-mounted network equipment

Most small offices run one network. The laptops, the till system, the printer, the cameras and whatever the landlord installed are all on the same Wi-Fi, all able to discover and talk to one another. That arrangement is convenient and it is the reason a single compromised device so often turns into a bad week. This is how the movement happens, what it looks like from the outside, and what separation is realistic without a network engineer.

The separation the agencies specify

  • CISA: enable guest Wi-Fi with its own strong password and ‘Connect any smart home and other IOT devices to your Guest Wi-Fi if internet access is the only thing they require’.
  • FTC’s reason for a guest network: fewer people hold the primary password, and malware on a guest device will not infect the primary network.
  • CISA on encryption: use ‘WPA3 Personal or WPA2 AES (also referred to as WPA2 Pre-Shared Key [PSK])’ — WEP, WPA or WPA2 TKIP means replace the router.
  • CISA: ‘Disable Wi-Fi Protected Setup (WPS). This setting increases the likelihood that a threat actor could gain unauthorized access to your Wi-Fi network.’
  • Report a cyber incident to CISA at cisa.gov/report, Central@cisa.dhs.gov or 1-844-729-2472.

How the movement actually works

The first device is usually reached from outside — a phishing message opened on a laptop, or a device exposed by an unpatched flaw. That part is ordinary.

What makes a flat network expensive is what happens next. Devices on the same segment can discover each other. Shared drives, printers, network storage and management interfaces are all reachable without crossing any boundary, and many of them are protected by nothing more than a default password. CISA’s reason for putting internet-only devices on a separate segment is exactly this: to prevent device discovery from one part of the network onto another.

Older equipment makes it worse. Anything still running WEP, WPA, or WPA2 with TKIP is in CISA’s replace-or-upgrade category rather than the acceptable one, which is WPA3 Personal or WPA2 AES. Wi-Fi Protected Setup is another standing invitation; CISA’s instruction is to disable it because it increases the chance of unauthorised access to the network.

What gives it away

  • Devices you do not recognise appearing in the router’s list of connected clients.
  • A machine showing the FTC’s malware symptoms: sudden slowdowns or crashes, software that will not uninstall, a changed default search engine, emails sent that nobody wrote.
  • Router settings that have changed on their own — remote management switched back on, a different DNS server, a new administrator account.
  • Staff reporting password reset emails or verification codes they did not request.
  • Shared drives or backups that have become inaccessible or renamed, which is usually late-stage rather than early.

If it has already happened

  1. Disconnect the affected device from the network rather than switching it off, so you keep the machine intact while cutting its reach.
  2. Check the router’s administrator account first, change its password to something long, random and unique, and confirm remote management is off — the FTC notes that enabling it allows the router’s settings to be changed over the internet.
  3. Follow the FTC’s malware sequence on affected machines: stop sensitive activity, ensure all software is up to date, then run a scan. If that fails, recover or reinstall the operating system using the manufacturer’s instructions.
  4. Do not pay a ransom if one is demanded. The FBI’s stated position is that it does not support paying, because payment does not guarantee data is returned and it encourages further attacks.
  5. Restore from a backup that was not connected to the network at the time — which is why CISA says not to leave a backup drive attached when you are not actively using it.

Where to report it

CISA takes incident reports at cisa.gov/report, and provides technical assistance for ransomware at Central@cisa.dhs.gov or 1-844-729-2472. Network intrusion, router compromise and unauthorised access are reportable to the FBI at IC3.gov.

If money moved, add a report at ReportFraud.ftc.gov, and for cyber-enabled financial crime the US Secret Service field offices are also a route.

The separation a small office can actually manage

You do not need managed switches and VLANs to get most of the benefit. The guest network already in your router is a real boundary, and CISA’s instruction is concrete: give it its own strong password and put anything that only needs internet access on it. Cameras, thermostats, smart plugs, displays, the television in the meeting room.

Keep the primary network for the machines that genuinely need to reach each other, and keep the number of people holding its password small — the FTC lists that as one of the two reasons a guest network is worth having.

Then the ordinary hardening: WPA3 Personal or WPA2 AES only, unique administrative credentials rather than the printed defaults, WPS and UPnP disabled, remote management off, the router firewall on, and firmware updates applied — automatically if the router supports it, since CISA notes some do.

NIST’s September 2024 requirements for consumer routers, IR 8425A, treat shared default passwords as a manufacturer defect and expect routers to keep their own firmware current. Until your hardware meets that, changing the defaults yourself is the substitute.

Sources: CISA Project Upskill, Module 5 · FTC — how to secure your home Wi-Fi network · FBI — ransomware · CISA — report a cyber incident · NIST IR 8425A, consumer-grade router requirements

Reviewed 27 August 2026 by the CyberArtical editorial team against primary guidance from CISA, the FTC, the FBI and NIST. Security guidance changes over time; where our earlier version of this page said something different, we say so in the article rather than editing it out quietly.

More Stories