Who may connect?
Which devices and people are allowed onto the network, and what they can reach once they are on it.
Home/Network Security
Network security
Network security in plain terms first, technical detail second. The same principles apply whether the network serves a household or an organisation.
In plain English
Strip away the terminology and network security comes down to a short list. Every product and policy below is a way of answering one of these.
Which devices and people are allowed onto the network, and what they can reach once they are on it.
Which traffic is permitted across the boundary, in both directions, and which is stopped.
Which decisions are kept, so activity can be reviewed and a rule corrected if it was wrong.
Internal network security
Most networks are flat by default: everything connected can reach everything else. That is convenient right up until one device is compromised, at which point convenience becomes the problem.
Internal security defines which zones may reach which. A camera does not need access to a file server; a visitor's laptop does not need either. Available segmentation depends on your architecture.
External network protection
Any network connected to the internet receives steady background traffic it never asked for: scans, probes and connection attempts. Filtering that at the boundary is the baseline.
Outbound traffic deserves the same attention. Connections leaving the network are measured against policy, which is how activity that does not fit the usual pattern becomes visible.
Wi-Fi, routers and gateways
The router is the one device with a permanent connection to the outside, which makes its configuration disproportionately important. Administrative access, remote management and network separation are the settings that matter most and get looked at least.
Wi-Fi separation between main, guest and device networks limits how far a problem can travel. Options depend on your equipment.
The technical layer
Same subject, more detail. Capabilities below depend on the service and architecture selected.
Rule sets defining permitted traffic in both directions, applied consistently across protected networks.
Visibility of what is crossing the network, with controls over how different kinds of traffic are handled.
Continuous observation with events recorded for review rather than discarded.
Structured separation so access follows the shape of the household or organisation.
Encrypted access back to a protected network for people working away from it.
A current picture of what is connected and how it behaves — usually the first real benefit.
FAQ
Deciding who may connect to a network, what may pass across it, and keeping a record of both. Everything else — firewalls, segmentation, monitoring, secure access — is a way of implementing those three decisions.
No. Antivirus protects an individual device from software running on it. Network security governs traffic crossing the network, which covers devices that cannot run protective software at all. They address different problems.
External protection concerns traffic crossing the boundary between your network and the internet. Internal protection concerns how devices inside the network reach each other. A flat internal network means one compromised device can reach everything else.
A home network carries personal files, financial logins, cameras and conversations, usually with no administrator. The scale is smaller than a business network; the value of what crosses it often is not.
Being able to see what is connected and what it is doing. Most networks accumulate devices nobody remembers adding, and visibility is what turns that into something you can make decisions about.
Where the configuration supports it, encrypted connections back to a protected network can be part of the service. Availability varies by plan and architecture.
Next step
Home, office or both. Describe what you are protecting and we will explain what fits.