
Routers, firewalls and VPN appliances are supposed to protect corporate networks. Their position between an organisation and the internet is also making them valuable targets.
The US Cybersecurity and Infrastructure Security Agency issued a binding directive on unsupported edge devices in February 2026, requiring federal civilian agencies to identify and replace internet-facing equipment that no longer receives security updates.
The directive applies only to US federal agencies, but the underlying problem is common across the private sector. Edge devices are often difficult to inventory, run proprietary software and remain in service for much longer than conventional endpoints. Once a manufacturer ends support, newly discovered vulnerabilities may never be patched.
These weaknesses are attracting more attention as attackers move towards exploiting internet-facing infrastructure. According to Verizon’s 2026 Data Breach Investigations Report, software vulnerabilities have overtaken stolen credentials as the most common initial route into breached organisations, accounting for 31 per cent of cases.
Firewalls and VPN gateways are particularly attractive because they must be exposed to the internet to perform their intended function. They also sit in a trusted position within the network. Compromising one can give an attacker an entry point that bypasses many of the controls designed to detect malicious activity on employee devices and servers.
Security tools can become entry points
Edge appliances occupy an awkward place in security programmes. They are critical enough to affect large parts of the business, but they may not receive the same monitoring and patching attention as laptops, servers or cloud workloads.
Endpoint detection tools cannot always be installed on them, while logs may be limited, stored locally or unavailable after a device is compromised.
Maintenance can also require downtime, encouraging organisations to delay updates to systems that support remote access or essential network traffic.
Research published by VulnCheck identified 181 exploited vulnerabilities affecting network edge devices during 2025. It found that 42.5 per cent affected devices that were already at, or likely approaching, the end of their supported life. Only 23.7 per cent of the vulnerabilities appeared in CISA’s Known Exploited Vulnerabilities catalogue.
The findings suggest that organisations cannot rely on a single vulnerability list to determine which equipment is being targeted. An appliance may remain operational long after it has disappeared from routine procurement records, while responsibility for maintaining it becomes unclear following staff changes, mergers or office closures.
This is why the first challenge is often visibility rather than patching. Security teams cannot update or replace equipment they do not know exists.
A reliable inventory should include the device model, software and firmware versions, location, internet exposure, business owner and vendor support date. It should also cover equipment operated by managed service providers, which may be absent from internal asset-management systems even though it provides access to the organisation’s network.
The edge is expanding beyond the perimeter
The same governance problem becomes more difficult as organisations move data processing away from central data centres and cloud platforms.
Edge computing allows information to be processed close to where it is generated, whether in a factory, hospital, shop, vehicle or energy facility. This can reduce latency and allow services to continue when connectivity is unreliable. It also distributes workloads across many locations where physical security, technical expertise and monitoring capabilities may vary.
A remote edge server may process sensitive operational or customer data without the protections available in a central facility. Some sites may have no dedicated IT staff, while others depend on third parties to install and maintain equipment. Connections may be intermittent, leaving devices unable to receive updates or transmit security logs consistently.
The distinction between network appliances and edge-computing infrastructure matters, but both expose the same weakness: security responsibility becomes harder to maintain as technology moves further from central control.
Guidance developed jointly by cyber authorities in the UK, US, Canada, Australia and New Zealand warns that edge devices have become a preferred target for state-sponsored and other threat actors. It recommends centralised configuration management, timely firmware updates, network segmentation and the use of dedicated administrative workstations.
These are familiar controls, but applying them across hundreds of sites, devices and suppliers is considerably harder than applying them within one corporate network.
Procurement decisions shape long-term exposure
Edge security therefore begins before equipment is deployed. Procurement teams need to consider how long a product will receive updates, how quickly the supplier addresses exploited vulnerabilities and whether the organisation can monitor the device using its existing security tools.
Contracts should define patching responsibilities, support periods, incident-notification requirements and access to security logs. Organisations should also establish how equipment will be securely decommissioned when support ends, rather than waiting for a critical vulnerability to force an emergency replacement.
Long-term costs matter because an inexpensive device can become a security liability if the vendor provides only a short update window or requires manual maintenance at every site. Replacement plans should be based on support dates and operational importance, not simply whether equipment continues to function.
The edge is not a single product category that can be secured with another platform. It is a collection of devices and workloads placed in exposed or difficult-to-manage locations. Protecting it requires organisations to understand what is deployed, who is responsible for it and how quickly it can be updated or isolated.
CISA’s directive is aimed at federal networks, but its wider message is relevant to any organisation still relying on ageing perimeter equipment. A device does not become safe because it continues to work. At the network edge, continued operation without continued support may be the risk.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543