For many small businesses, cybersecurity starts with the computers employees use every day. Antivirus is installed. Passwords are changed. Multi-factor authentication may be enabled. Backups might even be running.

Those are important protections.

But there is another device sitting quietly in almost every business that deserves considerably more attention: the router.

When that infrastructure is poorly configured, outdated, or exposed unnecessarily, an attacker may not need to start with an employee's computer at all.

Recent cybersecurity developments are providing an important reminder for small-business owners: the network itself needs to be monitored.

Routers are computers, too

It is easy to think of a router as an appliance that gets installed and forgotten.

In reality, modern routers run operating systems, management services, authentication mechanisms, firewall rules, and software that can contain vulnerabilities just like a traditional computer.

A recent example involves MikroTik RouterOS. On September 30, CISA warned about CVE-2026-84411, a critical vulnerability affecting the router's web-management service. According to CISA's warning, a specially crafted request from an unauthenticated attacker with network access could potentially result in code execution with root privileges. At the time of the warning, CISA said it had no knowledge of active exploitation of this particular vulnerability.

That distinction matters. A vulnerability does not automatically mean a device has been compromised.

But it does illustrate why businesses should know what equipment is running, what software it uses, which management services are accessible, and whether updates are being maintained.

This is not an isolated concern. Recent infrastructure-security research has documented large numbers of vulnerabilities across routers, switches, gateways, and other network products, including flaws that can be exploited remotely without authentication.

Most small businesses are not equipped to track that kind of information themselves. They should not have to.

Patching is important, but it is not the whole story

Imagine discovering that a router has been running vulnerable firmware for several months.

The first action is straightforward: update it.

But there is a second question that is often overlooked: What happened while it was vulnerable?

Installing an update can close a vulnerability. It cannot retroactively prove that nobody exploited it.

This is why mature network security needs to distinguish between several different conditions:

  • Vulnerable: the installed software contains a known security flaw.
  • Exposed: an attacker may actually be able to reach the vulnerable service.
  • Exploited in the wild: security authorities or researchers have evidence attackers are using the vulnerability.
  • Potentially compromised: configuration changes, unusual connections, or other evidence suggest something may already have happened.

Those are very different situations, and they should not produce identical warnings.

The same principle appeared in another recent incident. On September 30, Cisco disclosed a critical authentication-bypass vulnerability affecting Catalyst SD-WAN Manager and confirmed that exploitation had been observed during September. The affected product is aimed well above the typical small-business network, but the security lesson is broadly applicable: fixing the vulnerability and determining whether compromise occurred are two separate jobs.

The devices behind the router matter too

The network-security problem does not end with the router.

Small businesses increasingly operate environments filled with equipment that traditional endpoint-security software may never protect: security cameras, printers, access-control systems, smart televisions, wireless access points, environmental controls, and other connected devices.

You can usually install endpoint protection on a Windows workstation. You probably are not installing it on the security camera mounted above the front door.

That creates a visibility problem.

  • If an unfamiliar device joins the network, does anyone notice?
  • If a normally predictable device suddenly begins communicating with unfamiliar external destinations, does anyone know?
  • If a device starts contacting an address associated with malicious activity, does someone investigate?
  • If network equipment exposes a management service unexpectedly, who catches it?

For many small organizations, the answer is simple: nobody is watching that layer.

Endpoint security and network security solve different problems

This does not mean antivirus, EDR, or other endpoint protections are unnecessary. Quite the opposite.

Endpoint security can provide extremely deep visibility into supported computers and servers. Network monitoring provides another perspective.

A well-designed security strategy benefits from both.

For a small business without its own IT or cybersecurity department, however, understanding what is happening at the network layer can be especially difficult.

That is the problem JACKR Defense built Leonidas to address.

What small-business owners can do today

You do not need to become a network engineer to improve your security posture. Start with a few practical questions:

  • Do you know every device connected to your network?
  • Do you know whether your router firmware is current?
  • Is the router's management interface exposed unnecessarily?
  • Are old or unnecessary services still enabled?
  • Do you know when a new or unknown device appears?
  • Would anyone notice if a normally predictable device suddenly began communicating differently?
  • When a serious vulnerability is announced, do you know whether it actually applies to equipment you own?

If several of those answers are "no," you have identified a visibility gap worth addressing.

Where Leonidas fits

JACKR Defense's Leonidas platform is designed to give homes and small businesses practical visibility into the network layer without requiring them to operate an enterprise security team.

Leonidas Base focuses on foundational visibility: network inventory, unknown-device detection, DNS protection, security events, vulnerability and port visibility, alerts, and ongoing security-health reporting.

Leonidas Pro extends that model with managed router health, device behavioral monitoring, enriched threat intelligence, traffic intelligence, and priority security alerts.

The goal is not to overwhelm a business owner with every technical event occurring on the network. It is to answer more useful questions:

  • What is connected?
  • Is something behaving unexpectedly?
  • Does a vulnerability actually matter to this network?
  • And what deserves attention first?

Because the router should not be the device everybody depends on and nobody watches.

Sources and Further Reading

This briefing is written for small-business owners and summarizes publicly available cybersecurity advisories and research. Sources used for this edition:

  • CISA warning regarding MikroTik RouterOS CVE-2026-84411, September 30, 2026.
  • Recent infrastructure-security research documenting vulnerability volume across network and infrastructure products.
  • Cisco disclosure of CVE-2026-76504 affecting Catalyst SD-WAN Manager, including confirmed exploitation during September 2026.

Note: This article provides general cybersecurity information and is not a guarantee that any product or control will prevent every incident. Security recommendations should be evaluated in the context of each organization's environment.