Making something reachable.
WHAT IT IS
Configuring your router to send inbound connections on a port to a specific internal device.
WHEN IT IS NEEDED
Running a service at your premises that must be reachable externally.
WHY TO BE CAUTIOUS
Anything exposed is found by automated scanning within hours.
WHAT TO DO IF YOU MUST
Expose only the specific port needed Ensure the service is current and configured securely Use strong authentication Restrict by source address, where possible Monitor it
WHAT NOT TO EXPOSE
Administrative interfaces Remote desktop Database services Anything with default credentials
WHY NOT
Those are scanned for continuously and compromised quickly.
WHAT TO CONSIDER INSTEAD
Hosting the service properly, where it is maintained An encrypted tunnel, rather than direct exposure
FOR MOST SMALL BUSINESSES
Hosting elsewhere is simpler and safer than exposing equipment at your premises.
WHAT TO REVIEW
What is currently exposed. Frequently more than anyone intended.