Front Page: NCSC-FI
Front Page: NCSC-FI
Menu

Information security now!

This week we tell you how you can check if your home router is visible on the internet and the cybersecurity challenges of the highly digitised real estate and construction sector.

TLP:CLEAR

How to check your home network’s visibility on the internet

In recent weeks, the National Cyber Security Centre (NCSC-FI) and the media have highlighted the security of non-configured and non-updated devices, especially in homes. Botnets comprising unsecured devices in different countries can be used as part of espionage and influencing operations by state actors. In this article, we look at some ways to check the visibility of your home network or even your business network on the internet.

What is my public IP address?

The first step in finding out how visible your home network is is to find out the public IP address of your internet connection. A public IP address is, as the name suggests, the address from which devices in your network are visible to other internet users. In many mobile broadband routers, the connection is routed through a so-called NAT Network Address Translation, where the external (WAN) address of the home router is not yet actually a public IP address.
- You can check your public IP address 
   - In your router settings
   - From the https://bittimittari.fi/en (external link) (External link) addresses (remember to disable any VPN connection for the test)
       1. Select “Proceed to measurement”
       2. Select “Start measurement" and wait for the measurement to complete
       3. Once the measurement is complete, select "specifications" at the bottom of the page
       4. See your public IP address at: “IP address” (e.g., 123.134.245.67)

Infografiikka, jossa älytelevisio on yhdistetty riskialttiilla asetuksilla (esim. suoraan siltaamalla) internetiin. Rikollinen kurkisteleeinternetistä käsin televisiota kohti kiikareilla, koska kuka tahansa voi nähdä nettiin tällä tavoin avoinna olevan laitteen. Samaan aikaan älylelu, tulostin ja tietokone ovat kotiverkossa turvallisempien asetusten (esim. palomuuri ja NAT-yhteys) takana, jolloin reititin piilottaa kaikki laitteet yhden IP-osoitteen taakse.
The way in which devices on your home network appear on the internet depends on the settings on your router

What is visible on the internet from my home network?

You can then view the visibility of that address through services such as Shodan or Censys.
- https://search.censys.io/hosts/xxx.yyy.zzz.vvv/ (replace xxx.yyy.zzz.yyyy with the IP address you received in step 1) - https://www.shodan.io/host/xxx.yyy.zzz.vvv (replace xxx.yyy.zzz.yyyy with the IP address you received in step 1) The services do not always contain the same information, so it is advisable to check the information for both services. We have compiled examples of how different devices might appear in services in the drop-down elements of the article. In most situations, it is not a good idea to have anything visible from home networks on the public internet side. When you want to access home network services remotely, special care must be taken with the public visibility of the services.

If, after checking, you find that your home network devices appear open to the internet, we recommend that you first check your home router settings according to the manufacturer's instructions. The NCSC-FI has written general instructions for securing routers  (External link). You can also contact either your ISP or commercial operators, which offer help to home users.

Even if everything seems to be fine after the intervention, it is worth remembering that every IT device is made by us humans, both in terms of hardware and software, and we are fallible. The life cycle of home network devices is often longer than manufacturers have thought, and the world and cybercrime and evolving faster than we can possibly imagine. If you think of a traditional safe from 75 years ago, it is probably easy for a modern-day locksmith or criminal to open it, even if it was "unbreakable" when it was made. In today's IT age, it is good for us to consider the same analogies with our own IT devices, with the difference that the "obsolescence" of technology has accelerated many times over. The 75 years of a safe can be compared to about 7.5 years for routers. 

Infografiikka esittelee erilaisia reitittimiä ja niiden portteja. Internet-kaapeli kytketään yleensä WAN-nimiseen porttiin, joka on usein sininen tai punainen. Sisäverkon laitteille tarkoitetut LAN-portit ovat usein keltaisia, joskus myös sinisiä. Laitteessa saattaa olla myös monia muita portteja eri laitteille ja yhteyksille. Mielikuvitusreitiin sateenkaaren värisillä porteilla muistuttaa, että poikkeuksia on paljon, joten kytkennät kannattaa aina varmistaa käyttöohjeesta.
The rule of thumb is to connect the internet to the WAN port on the device and the devices on the internal network to the LAN ports. Although the products are made to be consistent in terms of, for example, gate naming and colour coding, there is still a lot of variation. You should always check the instructions for use of the appliance to make sure the connections are correct. While the above instructions will tell you how to map your home network and the visibility of your home devices on the internet, remember that even attempting to log in to someone else's device without permission is a crime.

Terms

  • Public IP address – the home address of your internet connection, which may change periodically
  • Network address translation (NAT) – a bit like poste restante, i.e., all devices in your home will see one address on the internet, but each device on your home network will have its own private IP address.
  • Private IP address – the standard governing IP addresses states that the following IP address ranges are reserved for private use
    • 192.168.0.0 - 192.168.255.255
    • 172.16.0.0 - 172.31.255.255
    • 10.0.0.0 - 10.255.255.255

Real estate and construction sector in digital upheaval

The real estate and construction sector has become rapidly digitised in recent years. This has led to an increasing number of network-connected devices, known as the Internet of Things (IoT), being found in properties. For example, heating, air conditioning, CCTV, locking and alarm systems, especially in new buildings, are often connected to a network and can be remotely managed for ease of use.

This rapid development has brought cybersecurity challenges to the industry. Remote management connections must be protected, and security updates must be installed on digital devices in buildings. From time to time, it may also be necessary to update the whole stock of devices, especially in situations where a device manufacturer no longer produces updates for a device.

Although digital development has brought with it security challenges, the major players in the real estate and construction sector in Finland are aware of the actions required to meet these challenges. At the EU level, there has also been a wake-up call for the regulation of IoT devices. In August 2025, a regulation [1] will enter into force, setting out the security features of wireless IoT devices placed on the EU market. Another regulation, the Cyber Resilience Act (CRA) [2], is more comprehensive and arguably more relevant to IoT devices. CRA Regulation increasingly requires manufacturers of digital products to take cybersecurity into account. CRA will start to be visible to users after 2027 at the latest, when digital devices entering the EU market will have to comply with the regulation, although the fastest players can already adopt it now.

Links to regulation:
[1] Delegated regulation: https://eur-lex.europa.eu/legal-content/FI/TXT/?uri=CELEX:32022R0030 (external link) (External link)
[2] CRA: https://eur-lex.europa.eu/legal-content/FI/TXT/?uri=CELEX:52022PC0454 (external link) (External link)

Information security at the Cyber Security Nordic event

People from the cybersecurity industry came together on 29–30 October for the Cyber Security Nordic fair at the Helsinki Messukeskus. Traficom's National Cyber Security Centre was present at a joint presentation with the Digital and Population Data Services Centre and Cyber Citizen. In addition, XX Director General of the NCSC-FI, gave a speech on 30 October on topics such as cyber sovereignty and the importance of cooperation in developing cybersecurity.

Visitors to the NCSC-FI's demonstration point were interested in the services offered by NCSC-FI, including Hyöky and CyberMeter. Visitors were also interested in the forthcoming EU regulation on cybersecurity. Thank you to everyone who visited our stand for all the good discussions!

Director General of the NCSC-FI XX spoke under the heading: "Cyber Sovereignty – Shaping the Future of Security and Collaboration"

Kyberturvallisuuskeskuksen ylijohtaja Anssi Kärkkäinen puhui otsikolla: Cyber Sovereignty – Shaping the Future of Security and Collaboration
Director General of the NCSC-FI Anssi Kärkkäinen spoke under the heading: "Cyber Sovereignty – Shaping the Future of Security and Collaboration"
Kävijöitä Kyberturvallisuuskeskuksen osastolla
Visitors to the NCSC-FI stand at Cyber Security Nordic

Recently reported scams

In this summary, we provide information about scams reported to the NCSC-FI during the past week.

WHAT TO DO IF YOU GET SCAMMED

Learn how to detect and protect yourself against online scams

Tutustu Viikkokatsaukseen

This is the weekly review of the National Cyber Security Centre Finland (reporting period 25–31 October 2024). The purpose of the weekly review is to share information about current cyber phenomena. The weekly review is intended for a wide audience, from cybersecurity specialists to regular citizens.