Short answer: If your firm has routers, firewalls, remote-access devices, or branch-office network gear, make sure someone owns the inventory, patching, management access, logging, and recovery evidence. These controls are not glamorous, but they protect the systems your team relies on every day.
What this helps you check
Use this as a practical technology review, not as a compliance checklist.
- Router and firewall inventory, ownership, and supplier responsibility
- Firmware, end-of-life devices, management access, and credentials
- Monitoring, configuration backups, incident evidence, and Microsoft 365 continuity planning
On 14 July 2026, New Zealand's National Cyber Security Centre published a joint agency advisory on router hygiene. The advisory focuses on poorly configured and vulnerable networking devices, including routers, and recommends practical mitigations such as restricting management protocols, using stronger SNMP settings, applying firmware updates, and replacing unsupported devices.
The advisory is aimed at network defenders and includes technical detail. For most legal, financial, accounting, and advisory firms, the useful business takeaway is simpler: network devices are part of the firm's trust infrastructure, and they need visible ownership.
This article does not assess any firm's exposure to a specific threat actor. It is a calm prompt to check whether the basics around network-device governance are documented, current, and recoverable.
The current NZ signal
NCSC-NZ's 14 July 2026 advisory says poorly configured networking devices are being exploited worldwide, and identifies financial services as one of the critical infrastructure sectors most at risk in the advisory context. The same page notes that the mitigation actions are useful against similar techniques used by other malicious cyber actors.
For EQIQ's audience, the right angle is not panic. It is housekeeping. Routers, firewalls, remote-access devices, and branch-office equipment often sit quietly in the background until there is an outage, supplier change, office move, security review, or incident.
1. Know which devices the firm relies on
Start with a current inventory. List routers, firewalls, Wi-Fi controllers, VPN appliances, internet-facing remote-access tools, and any devices managed by a telco, landlord, branch office, or previous IT provider.
For each device, record the location, owner, supplier, model, support status, firmware version, administrator contacts, and what business services depend on it. If the inventory lives only in someone's memory, it will be weak under pressure.
2. Check management access before there is an emergency
Network devices should not be managed through shared passwords, stale accounts, open internet-facing portals, or undocumented remote-access paths. The firm should know who can log in, how access is approved, and how access is removed when people or suppliers change.
The NCSC advisory specifically recommends stronger management protocol settings, strong unique passwords, restricted management access, and secure handling of credentials. Those are practical checks a firm can request from its IT provider without needing to interpret every technical detail itself.
3. Treat old firmware and unsupported devices as business risk
Firmware updates are easy to defer because the devices are often invisible when everything is working. That deferral can become a problem when a device is known-vulnerable, unsupported, or too old to receive reliable fixes.
Ask for a support-status review. Which devices are current? Which need planned updates? Which are end-of-life and should be replaced? The answer should be documented in plain language, with timing and business-impact notes.
4. Make logs and configuration backups part of the evidence trail
If a network device is compromised, misconfigured, or fails during an outage, the firm needs evidence. That may include logs, configuration backups, firmware history, change notes, supplier tickets, and incident actions.
Configuration backups should be stored securely and tested carefully. They should not be exposed in broad shared folders or personal downloads. The same applies to diagrams, admin notes, and emergency access details.
5. Connect network hygiene to cloud and Microsoft 365 resilience
Many firms think of Microsoft 365 as separate from office networking. In practice, staff still need reliable and secure connectivity to reach email, Teams, SharePoint, practice-management tools, document systems, and client portals.
A router or firewall issue can become a client-service issue quickly. Include network-device ownership in business continuity planning, especially for remote work, branch offices, MFA access, emergency communications, and supplier support.
6. Keep the review calm and specific
The best question is not "Are we secure?" It is "Can we show that the devices we rely on are known, supported, patched, restricted, monitored, and recoverable?"
That answer should be easy for firm leaders to understand. A short register, a supplier confirmation, a patch plan, and a recovery note are more useful than a dense technical report that nobody reads.
What should firm leaders ask this month?
Use these questions to start a practical conversation with your internal team or IT provider:
- Do we have a current list of all routers, firewalls, VPN, Wi-Fi, and branch network devices?
- Who administers each device, and how is access approved, logged, and removed?
- Are any devices unsupported, end-of-life, or waiting on important firmware updates?
- Are management services restricted so they are not unnecessarily exposed to the internet?
- Are device credentials strong, unique, and stored in an approved system?
- Do we have secure configuration backups, useful logs, and a clear recovery path?
- How would a network-device outage affect Microsoft 365, client communication, remote work, and time-sensitive matter handling?
If the answers are unclear, start with a focused network-device review. Keep the work practical: inventory, access, patching, monitoring, backups, and recovery evidence.
Common questions
Is this article legal or regulatory advice?
No. It is general technology-risk information for professional services firms. Firms should take appropriate professional advice for their own legal, financial, regulatory, privacy, or compliance obligations.
Why should professional services firms care about router hygiene?
Routers, firewalls, and other network devices often sit at the edge of the firm. Weak management access, old firmware, shared credentials, and poor records can make incidents harder to prevent, detect, or recover from.
What should firms check first?
Start with an inventory of routers and firewall devices, then confirm who owns them, whether firmware is supported and patched, how management access is restricted, whether credentials are unique, and whether logs and backups are available.
Source note
This article is based on official National Cyber Security Centre material: Improve router hygiene to protect against Russian state-sponsored targeting, published at 10:15am on 14 July 2026, and the NCSC alerts page. Sources were checked on 14 July 2026.
Compliance note: This article is general information only. It is technology-risk and cybersecurity governance guidance, not legal advice, not financial advice, not regulatory advice, not privacy advice, and not compliance advice. Firms should take appropriate professional advice for their own obligations and circumstances.
