A security notice lands in your inbox: a serious flaw was found in the kind of VPN or firewall appliance that a lot of small businesses use as their remote-access door. Your IT provider installs the patch, everyone exhales, and the ticket closes. Here’s the uncomfortable part. If attackers reached that box before the fix went on, patching it doesn’t undo what they already took. Updating the appliance is the right first move, and it can’t wait. But on a device that was sitting on the public internet, the patch is only half the fix. The other half is assuming your logins already walked out the door.

First, Figure Out If You’re Even Exposed

Not every security headline is your headline. The question that matters is narrow: does your business run a VPN, a firewall appliance, or a remote-desktop gateway that faces the internet so staff can log in from home or the road? If the answer is yes, a disclosed flaw in that class of device is your problem until you prove otherwise.

If your team only works on-site and nothing accepts inbound connections from outside, your urgency drops a lot. Most small firms aren’t in that camp anymore. Remote work put a login page on the open internet for almost everyone, and that convenience is exactly how remote access turned into the entry point attackers reach for first. So before you panic or shrug, confirm what you expose.

Patching the Box Closes the Hole, Not the Break-In

Here’s the mental model people get wrong. A patch stops future abuse of a specific vulnerability. It does nothing about a session an attacker already opened or a password they already copied. Once someone has a valid login, they don’t need the exploit anymore. They just sign in like an employee.

Install the update fast anyway. CISA’s ransomware guidance is direct about it: “Update VPNs, network infrastructure devices, and devices being used to remote in to work environments with the latest software patches and security configurations.” That’s step one, and on an internet-facing appliance it can’t wait for next month’s maintenance window.

What trips businesses up is treating it as step one and step done. Patching is the beginning of the response, not the whole thing, which is why it helps to have a standing plan for pushing emergency fixes instead of scrambling each time.

Assume Your Passwords and MFA Codes Left With Them

On an exposed remote-access appliance, the real prize was never the hardware. It’s the credentials flowing through it. Attackers harvest usernames, passwords, active session tokens, and in some cases the secret seeds that generate one-time MFA codes. Patch the device and those stolen secrets still work, because they aren’t an exploit. They’re a legitimate login.

This is why, after a credential exposure on remote-access gear, CISA’s instruction is blunt: “Terminate sessions and reset credentials.” In plain terms: kill every active session, reset the password on any account that touched the gateway, and re-enroll multi-factor authentication so old codes stop working. Skipping the MFA re-enrollment is the common miss, because a stolen seed keeps minting valid codes long after you’ve changed the password.

Around-the-clock monitoring that flags logins from the wrong place at the wrong hour is how you catch a stolen credential being used before it becomes a full intrusion.

Check the Logs From the Window You Were Open

Between the day a flaw starts getting quietly exploited and the day you patch, there’s a window. Somebody needs to look at what happened inside it. New user accounts nobody created. Logins at 3 a.m. from a country you don’t do business in. Configuration changes on the appliance. VPN connections that don’t match anyone’s schedule.

If no one reviews those logs, an intruder who’s already inside looks identical to normal traffic. That’s the quiet danger. This is also where endpoint protection that watches for attacker behavior, not just known viruses earns its keep, because a signature scanner won’t blink at a valid login doing suspicious things. You’re not hunting for malware here. You’re hunting for a guest who used the real key.

Call Today, Book This Week, or Just Keep Watching?

Honest triage matters here, because not every business needs to sound the alarm over the same headline. The dividing line is simple: how exposed your remote access was, and how confident you can be that it was locked down before the flaw went public. Here’s the split that most small firms fall into once they answer those two questions.

  • Call today if you run an internet-facing VPN, firewall, or remote-desktop gateway that matches the disclosed flaw — especially if MFA wasn’t enforced on it, or you can’t confirm when it was last updated. Assume credential exposure and start the reset.
  • Book this week if you have remote access but MFA is enforced everywhere and patches already applied automatically. You’re in better shape, but verify the version and rotate credentials as a precaution rather than a hope.
  • Keep watching if you have no inbound remote access at all. Stay on your normal patch schedule and don’t let this become the reason you finally open one up without protection.

If you land in the “call today” group and don’t have someone to call, the fastest move is a quick check of what your business exposes before an attacker inventories it for you.

What a Real Response Looks Like After a Disclosure

The unknown is scary, so here’s what a competent response covers, in order. Confirm the appliance is running the fixed version. Terminate active sessions. Reset passwords on every account that touched the gateway, then re-enroll MFA. Review logs across the whole exposure window. Look for persistence — new accounts, scheduled tasks, unexpected admin access. Finally, lock down the management interface so it isn’t reachable from the public internet in the first place.

In the small businesses O&O Systems supports, the appliance itself is rarely the thing that gets missed. It’s that nobody rotated the passwords or reset the MFA that could have leaked while the device was exposed. Because remote monitoring and patch management run as standard managed services, a disclosed flaw becomes a scheduled response — patch, reset, review — instead of a fire drill where each step depends on someone remembering it at 5 p.m. on a Friday.

Not Sure Where You Stand? Find Out First

If you can’t answer “are we patched, and did we reset whatever might have leaked” with real confidence, that gap is the exposure. It’s not a hypothetical for a big enterprise. It’s the ordinary small business that patched the box, felt safe, and never closed the second half of the loop.

O&O Systems will run a security risk assessment that inventories your internet-facing logins, checks whether your remote-access appliances are current, and confirms MFA is enforced on every external gateway — the exact weak spots this kind of attack goes looking for. Better you find them on a calm Tuesday than an attacker finds them for you.

A Few Quick Questions

We already patched. Isn’t that enough?

Patching stops the flaw from being used again, but it doesn’t cancel a login an attacker already stole. If the device was exposed before you updated, treat credentials as compromised, reset them, and re-enroll MFA. The patch and the reset are two separate jobs, and only doing the first leaves the door propped open.

How could attackers still have our passwords after an update?

Because they grabbed them earlier, while the flaw was open. A password or session token captured last week is still valid this week, no exploit required. The update seals the crack in the wall, but anyone who already copied the keys can walk in the front door until you change the locks.

Do we need to reset MFA as well?

Often, yes. Some attacks against remote-access appliances capture the seed that generates your one-time codes, which means the attacker can produce valid MFA codes on their own. Changing the password alone won’t stop that. Re-enrolling MFA issues a fresh secret and makes any stolen seed useless.

We’re a small business. Would anyone bother with our VPN?

You’re not being singled out — that’s the point. Attackers scan the whole internet for exposed appliances and grab whatever answers, small or large. Being small doesn’t keep you off the list; it just means no one’s watching the door as closely. A reachable, unpatched gateway is an opportunity regardless of your size.