News broke this week that a major TV brand was caught scanning the local network for phones and other gear it had no business touching. If you have a smart TV in your conference room, or a smart speaker, or a printer, or one of those fancy coffee machines with an app — assume it's doing the same thing. Because it probably is.
Consumer smart devices are built for a home. They assume they're on a network with a laptop, a phone, and maybe a game console. When you plug one into your office LAN, it starts poking at your file server, your accounting workstation, and the receptionist's PC the same way it would poke at a kid's Xbox. Some of it is telemetry. Some of it is "discovery" for features nobody uses. Some of it is straight-up data collection that gets sold downstream.
The probelm is not that the TV is evil. The problem is that it's sitting on the same flat network as your QuickBooks file, your shared drive, and the laptop your bookkeeper uses. One flat network means one compromised device can see everything. And these devices get patched on the vendor's schedule, which is to say, never.
The fix is network segmentation. You want at least three separate networks in your office, and any half-decent firewall handles this out of the box. We run pfSense for exactly this reason. Cisco or Netgear switches on the wired side, and you're done in an afternoon.
Here's the split I use for a small office:
Three VLANs, three firewall rules, done. The TV can still stream Netflix and get its updates. It just can't scan the CFO's laptop while it's at it.
Walk your office and write down every device with a power cord and a network jack or Wi-Fi radio. TVs, cameras, thermostats, printers, doorbells, that weird digital sign in the lobby. Anything you didn't personally choose the firmware update schedule for goes on the IoT VLAN. If your current router can't do VLANs, that's your sign to replace it. A pfSense box on refurbished hardware from Server Monkey runs about $300 and will outlive the next three TVs you buy.
Do not skip this because "we're too small to be a target." The scanning is automated. Nobody picked you. You're just on the list.
If your office network is one flat blob and the idea of splitting it into VLANs makes your eyes glaze, send us a note. This is the kind of afternoon project we knock out for small offices all the time.
— Alexander @ SBATC