Security
Published September 2026 · 11 min read · BoltProof Insights
A Synology NAS sitting on the open internet is a target. Shod indexes it within hours. Bot scanners probe the DSM port constantly. And if you've left the default admin password, enabled QuickConnect with a guessable ID, or forwarded port 5000 without a reverse proxy — congratulations, you're already in someone's exploitation queue.
A properly hardened Synology, on the other hand, is a fortress. It's the difference between leaving your front door wide open and having a security system, deadbolt, and a camera. The problem is that most NAS deployments fall somewhere in between — partially secured, with one or two critical gaps that negate the rest of the effort.
Here's the 12-point checklist we apply to every Synology we deploy. Follow it and your NAS will be substantially more secure than the vast majority of devices on the internet.
This is the single most important step on this list. Enable 2FA (TOTP-based, via an app like Authy, 1Password, or Google Authenticator) for every account on the NAS — not just admin. A compromised password without the second factor is useless to an attacker.
In DSM, go to Control Panel → Security → Account → 2FA and enforce it for all users. If you're using LDAP or Active Directory, enforce 2FA at the directory level as well. No exceptions for "convenience" accounts.
The default admin account is the most-targeted username in the Synology ecosystem. Create a new admin-level account with a non-obvious name, then disable the default admin account entirely. Do the same for any default service accounts.
This eliminates an entire class of brute-force attacks that assume the username admin exists. Every attacker's wordlist starts with it. Remove it from the equation.
This is the mistake that causes the most catastrophic breaches. If your NAS is accessible by forwarding port 5000 (or 5001 for HTTPS) through your router to the internet, stop right now and close it. There is no scenario in which this is safe, even with a strong password and 2FA.
Instead, use one of these approaches for remote access:
The principle is simple: if it's not behind a VPN or authenticated reverse proxy, it shouldn't be reachable from the internet. Period.
DSM includes a built-in firewall that most people leave unconfigured. Don't be most people. In Control Panel → Security → Firewall, create rules that:
A firewall that allows everything is the same as no firewall. A firewall that denies by default and allows only what you explicitly specify is what actually protects you.
Synology releases DSM updates regularly, and many of them contain security patches for vulnerabilities that are being actively exploited. Enable automatic DSM updates in Control Panel → Update & Restore → DSM Update and set it to install critical updates automatically.
The same applies to installed packages — Container Manager, Active Backup, Surveillance Station, and every other package you've installed. Check Package Center → Updates monthly, or better, enable auto-update where available.
Every service running on your NAS is a potential attack surface. If you don't use Telnet, SSH, FTP, or AFP — disable them. In Control Panel → Terminal & SNMP, disable any protocols you don't actively use. In File Services, disable SMB1 (it's insecure and deprecated) and any file protocols you're not using.
If SSH is needed (and for our remote management, it is), configure it with key-based authentication only — disable password authentication entirely.
A hardened NAS is still a single device. If it's destroyed by fire, flood, theft, or a ransomware attack that compromises the entire network — your primary storage is gone. The 3-2-1 rule:
Configure Synology's built-in Hyper Backup to a cloud provider (Backblaze B2 is our preferred choice — it's S3-compatible and significantly cheaper than AWS), and set up Snapshot Replication to a second NAS or an external drive that's rotated off-site. Test the restore process at least quarterly. An untested backup is not a backup — it's a hope.
Snapshots are point-in-time copies of your data that can be restored in seconds. They're the single best defense against ransomware because they let you roll back to a state before the encryption happened.
In Storage Manager → Snapshot, configure hourly snapshots with at least 7 days of retention for active data, and daily snapshots with 30 days of retention. For critical datasets, consider 15-minute snapshots. The storage overhead is minimal (snapshots only store the deltas), and the recovery value is enormous.
Then, replicate those snapshots to a second NAS or an external location. If the primary NAS is compromised, the replicated snapshots on a physically separate device are your last line of defense.
This should be obvious, but it's worth stating: every account on your NAS needs a strong, unique password. Not a variation of a password you use elsewhere. Not a "company standard" that's the same across all systems. Unique per account, generated by a password manager, at least 16 characters.
Pair this with point #1 (2FA) and point #2 (no default admin) and your authentication layer is solid. Without it, the other 11 points on this checklist are built on sand.
DSM can automatically block IP addresses that fail login attempts repeatedly. In Control Panel → Security → Account → Auto Block, configure it to block IPs after 5 failed attempts within a 5-minute window, and keep them blocked for at least 24 hours.
This won't stop a determined distributed attack, but it will throttle opportunistic brute-force attempts and give you visibility into who's trying. Pair this with login notification emails so you're alerted to repeated failures in real time.
The principle of least privilege applies to file shares too. In Control Panel → Shared Folder, review every shared folder and ensure that:
Also, enable Advanced Sharing Permissions and verify that the NTFS/NFS permissions at the file level match the share-level permissions. Mismatches between share and file permissions are a common source of unintended data exposure.
This is the point that most guides miss. If your backup is always connected to the same network as your primary storage, ransomware that compromises your network can encrypt both — primary and backup — simultaneously. That's game over.
An air gap means your backup is physically or logically disconnected from the production network at least some of the time. Options include:
The goal is to ensure that even a total compromise of your primary NAS doesn't compromise all your recovery options. If every backup is reachable from the compromised system, you don't have a backup — you have a target.
Once you've implemented all 12 points, you're in the top 5% of Synology deployments from a security standpoint. If you want to go further, consider:
Security isn't a state — it's a process. The checklist above gets you to a strong baseline. But devices age, vulnerabilities emerge, and configurations drift. The businesses that stay secure are the ones that treat security as ongoing maintenance, not a one-time setup.
Ransomware on a Synology is not hypothetical. We've seen it. The typical scenario: an attacker gains access through an exposed DSM port or a compromised client device on the same network, encrypts the primary storage, and then targets the backups. Without snapshots and air-gapped backups, the business is faced with paying a ransom (often 5-6 figures), losing the data entirely, or rebuilding from whatever fragmented backups survive.
The 12-point checklist above takes 2-4 hours to implement on a properly set up NAS. The alternative — recovering from a ransomware incident — takes weeks, costs orders of magnitude more, and may still result in permanent data loss.
Security is cheap. Insecurity is expensive. The math is that simple.
Book a free discovery call. We'll review your current configuration, identify any gaps in the 12-point checklist, and give you a clear security assessment — no obligation, no upsell pressure.
Book a security review →