If you found this blog post interesting you might also enjoy our regular series of webinars about practical ways to improve the security of people working outside the office.

EDITED APRIL 2026

Security agencies including the NSA, GCHQ, CISA and their Five Eyes partners have issued repeated warnings about network edge devices: the routers, gateways and firewalls that sit between staff and the systems they use. Their guidance is consistent. If these devices are not secured and centrally managed, they become entry points into business systems.

Yet they are still routinely overlooked. Attention tends to concentrate on data centres, cloud platforms and employee laptops. One of the most exposed parts of a modern network sits beyond all of those: the routers and gateways staff connect through from homes, hotels, serviced offices and client sites. These devices form the uncontrolled network edge, where IT has little or no oversight, and where some of the least visible risks now sit.

Why edge devices pose a growing threat

Most consumer and small-office routers ship with firmware that is patched infrequently, is awkward to update, or stops receiving updates altogether once the manufacturer moves on to a newer line. Attackers rely on exactly this. Automated tools scan the internet continuously for devices with known flaws, and once a weakness is found it can be exploited at scale with very little effort.

Two structural problems make this worse. Many routers stay in service for years without a firmware update, leaving long-known vulnerabilities open. And a good number ship with default credentials or exposed management interfaces that are never changed.

This is not theoretical

Compromised routers have been at the centre of some of the most significant campaigns of the past decade:

  • Mirai turned large numbers of insecure routers and other connected devices into a botnet used for record-breaking denial-of-service attacks.
  • VPNFilter, documented by Cisco Talos, is estimated to have infected in the region of 500,000 routers and network devices worldwide, with the ability to steal data and render devices unusable.
  • More recently, the UK’s NCSC and Five Eyes partners attributed a sustained campaign to APT28, in which unpatched consumer routers were used to hijack DNS and harvest credentials and authentication tokens for email and Microsoft 365 accounts. We covered how to check your exposure to that campaign in a separate post.

The pattern across all of them is the same. Attackers do not treat routers as background equipment. They treat them as targets, because they are exposed, long-lived and rarely maintained.

Edge risk in everyday work

The danger becomes concrete in ordinary settings:

  • Home access. A member of staff signs in through a router that has not been updated since it was installed. A family member’s infected device on the same Wi-Fi becomes a bridge into the company connection.
  • Hotel Wi-Fi. A manager reviews sensitive dashboards late at night on a shared hotel network that has never been patched, alongside every other guest on the same connection.
  • Serviced office. A law firm works from a co-working space whose routers are managed by the building, not the firm, and have never been hardened. Sensitive files pass through a network no one at the firm controls.
  • Client site. A consultant logs into internal systems from a client’s office. The client’s router is outside anyone’s control on the firm’s side, yet the firm’s business traffic still runs through it.

Each of these happens daily, and each puts company data on infrastructure the organisation cannot see.

Why traditional tools are not enough

It is tempting to assume that VPNs and endpoint security cover this. They do not, at least not on their own.

  • VPNs encrypt traffic in transit but cannot stop an attacker already inside the local network from attempting lateral movement once the connection is open.
  • Endpoint protection secures the laptop or phone, but it cannot patch or reconfigure the router sitting between the device and company systems.
  • Firewalls are effective inside a controlled network, but at the uncontrolled edge they depend on a router that may already be compromised.

If the entry point itself is unsafe, the rest of the stack is built on shaky ground. That is why the router remains the weak link.

How Loxada helps

Loxada turns that blind spot into a controlled, consistent access point. Instead of relying on whatever router happens to be available, staff connect through a Loxada managed secure router that creates a separate, work-only network wherever it is used.

  • Hardened firmware. Loxada’s own firmware replaces the manufacturer’s software entirely, removing dependence on vendor update practices and the class of flaws that come with abandoned or exposed manufacturer firmware.
  • Automatic updates. Firmware and configuration are managed centrally and applied without user action.
  • Traffic separation. Company traffic is kept apart from other devices on the local network, closing off the lateral-movement path.
  • Central control. IT manages device assignment and revocation centrally. A lost or reassigned device can be deactivated remotely, and cannot reconnect in secure mode.

To be clear about the line we hold: Loxada is not a monitoring or threat-detection product, and does not inspect user traffic. What it provides is a hardened, centrally managed network edge, with deployment-level assurance of which devices are in use, whether they are connected, and which firmware they are running, captured in a monthly assurance summary. For a risk that is fundamentally about unmanaged, unpatched, invisible devices, that shift from invisible to managed is the point.

Securing the uncontrolled network edge is where Loxada started. If your people connect to sensitive systems from networks you cannot see, we would be glad to talk through what bringing that edge under control would look like.

Want to learn more? Read more about how Loxada creates secure devices

If you found this blog post interesting you might also enjoy our regular series of webinars about practical ways to improve the security of people working outside the office.