WISP Tower Cybersecurity Checklist
A practical checklist for securing routers, management traffic and physical access at remote tower sites.
WISP towers are attractive targets: they are often unattended, connected to the public internet, and packed with gear that is expensive to replace. A compromised tower can interrupt service, become a launch point for attacks, or expose customer data.
This checklist covers the highest-impact security controls for WISP tower sites. Use it during new builds, quarterly reviews, or incident response preparation.
1. Change all default credentials
- Router admin passwords
- Switch management accounts
- Radio / CPE management interfaces
- IPMI, iDRAC, or BMC credentials on any server gear
- Default SNMP community strings
Use a password manager or secrets vault. Never reuse credentials across towers.
2. Segment management traffic
- Create a dedicated management VLAN
- Restrict management access to known source IPs
- Disable management interfaces on customer-facing ports
- Use out-of-band management where possible
3. Encrypt remote access
- Use SSH keys instead of passwords
- Disable Telnet, HTTP, and other plaintext protocols
- Use a VPN or jump host for remote access
- Enforce multi-factor authentication where supported
4. Patch and harden
- Keep router, switch, and radio firmware current
- Disable unused services and ports
- Apply vendor hardening guides
- Schedule quarterly firmware reviews
5. Monitor and log
- Forward syslogs to a centralized SIEM or log server
- Alert on login failures, config changes, and reboots
- Monitor bandwidth for anomalies
- Keep logs for at least 90 days
6. Physical security
- Lock cabinets and enclosures
- Use tamper-evident seals where appropriate
- Document who has physical access
- Secure fiber entrances and power disconnects
Download the full checklist
This page covers the essentials. For a printable checklist with scoring and remediation tracking, talk to SmashByte Security.
Request WISP Security Assessment