The router is more than the Wi-Fi box
For many small businesses, the router is installed once, placed on a shelf, and mostly forgotten until the internet stops working. But from a security standpoint, it is one of the most privileged devices in the building. It controls how devices reach the internet, which services are exposed, how DNS requests are handled, and often how remote management is performed.
That means a router problem can affect far more than the router itself. A misconfiguration can expose an administrative service. Outdated firmware can leave a known vulnerability open. A compromised router can potentially observe, redirect, or relay traffic without creating the kind of warning an employee would notice on a laptop.
Recent incidents show why that matters. In September 2026, CERT Polska disclosed actively exploited vulnerabilities in MikroTik RouterOS. Attackers were observed taking over internet-accessible routers when vulnerable SSH services were exposed. CERT Polska advised administrators not only to patch, but also to check for unknown users, scripts, scheduled tasks, proxy servers, tunnels, and other signs that a device may already have been altered.
Patching is important, but patched does not always mean clean
Software updates close vulnerabilities. They do not automatically prove that a device was never compromised before the update was installed.
This distinction matters for small businesses because the signs of a router compromise may be subtle. An attacker may add an administrative account, change a setting, create a tunnel, alter DNS behavior, or cause the router to contact infrastructure it has never used before. A routine firmware check can miss those signals.
That is why effective router security is becoming less about a one-time checklist and more about ongoing visibility: What is the router? What firmware is it running? What services are exposed? Has its configuration changed? Is it communicating with unusual destinations?
The risk extends beyond the router itself
The same network usually contains devices that cannot run traditional endpoint security: cameras, printers, streaming devices, smart TVs, access-control systems, environmental controls, and other Internet of Things equipment.
In March 2026, the FBI warned that criminals use residential proxy networks to route malicious traffic through home and small-business internet connections. The result is a practical problem: a business can have a device abused by criminals even if employees never see a conventional malware warning.
VulnCheck also documented router firmware implants in 2026 that could communicate outbound to command-and-control infrastructure. One of those implants, SPEAKINGSTONE, was designed to phone home rather than expose an obvious listening port. That is a useful reminder that a network device can behave maliciously while still appearing normal during a basic open-port check.
What should a small business actually monitor?
A useful small-business approach is to focus on a short list of high-value questions:
- Do we know which router and firmware version we are running?
- Are unnecessary management services or ports exposed?
- Has the router configuration changed unexpectedly?
- Are DNS and network settings still enforcing the intended policy?
- Are important devices contacting new or high-risk external destinations?
- Are normally predictable devices suddenly using unusual ports or communicating outside normal hours?
- If a vulnerability is known, is it actually applicable and exposed in our environment?
The goal is not more alerts. It is better decisions.
Small businesses do not need another dashboard full of technical noise. They need to know what changed, why it matters, and what should happen next.
A critical CVE number alone is not enough. A useful security service should distinguish between a theoretical vulnerability and a situation that is actually reachable, known to be exploited, or paired with suspicious behavior. It should also recognize when a device is still in a learning period so normal activity is not mistaken for an attack.
The practical outcome is fewer, higher-confidence findings: a router management service that unexpectedly appeared; an IoT device contacting a known high-risk destination; a gateway whose configuration drifted; or a device whose behavior changed materially from its established baseline.
Where JACKR Defense and Leonidas fit
JACKR Defense built Leonidas around this visibility gap. Leonidas Base focuses on network inventory, unknown-device detection, DNS protection, security events, vulnerability and port visibility, alerts, and monthly security health reporting.
Leonidas Pro extends that model with managed router health, device behavioral monitoring, enriched threat intelligence, traffic intelligence, and priority security alerts. The objective is not to replace endpoint antivirus or an enterprise security operations center. It is to give a small business an always-on view of the network layer that is too often left unmonitored.
For an owner without a full-time security team, that can answer a much more useful question than "Is the internet working?" It can help answer: "Is my network behaving the way it should?"
Sources and Further Reading
This briefing is written for small-business owners and summarizes publicly available cybersecurity research and advisories. Sources used for this edition:
- Verizon, 2026 Data Breach Investigations Report. 31% of breaches now begin with vulnerability exploitation; broader 2026 breach trends. Source
- FBI, "Evading Residential Proxy Networks" (March 12, 2026). Warning on criminal use of home and small-business networks as residential proxies. Source
- CERT Polska, "Critical vulnerabilities in MikroTik RouterOS are being actively exploited" (September 5, 2026). Active exploitation of RouterOS vulnerabilities and post-patch compromise checks. Source
- VulnCheck, "Chinese Implants in the Supply Chain" (August 2026). Research on router firmware implants including outbound command-and-control behavior. Source
- CISA/FBI, "Malicious Cyber Actors Exploiting Insecure SOHO Routers." Government guidance on threat actors exploiting insecure small-office/home-office routers. Source
Note: This article provides general cybersecurity information and is not a guarantee that any product or control will prevent every incident. Security recommendations should be evaluated in the context of each organization's environment.