Not all routers are equal, and in locations outside your control you often have no idea what kind of network your users are connecting through. Shared office spaces, client sites, serviced offices, coworking hubs, hotels, holiday rentals, even home networks, all fall into the category of unmanaged infrastructure.
These environments quickly become IT blind spots. You cannot patch what you cannot see, and you cannot harden what you do not control. Even when users apply firmware updates, many of those updates still contain known vulnerabilities, and in most cases there is no visibility over whether updates are applied at all.
The NSA has flagged network edge devices as a priority target, precisely because they bridge external networks and internal resources and can give attackers a way to gain access or persist on networks (NSA, February 2025). The risk is not theoretical. It is live, ongoing and growing.
There is lateral exposure too. When your users connect to a shared or unknown network, you do not know what else is on it. A compromised device elsewhere on that same Wi-Fi could scan or try to reach your user’s machine, and a compromised router could redirect traffic. Without control of the local network, your security posture rests on assumptions you cannot verify.