Security

Securing Your NAS: A 12-Point Checklist

Published September 2026 · 11 min read · BoltProof Insights

A Synology NAS sitting on the open internet is a target. Shod indexes it within hours. Bot scanners probe the DSM port constantly. And if you've left the default admin password, enabled QuickConnect with a guessable ID, or forwarded port 5000 without a reverse proxy — congratulations, you're already in someone's exploitation queue.

A properly hardened Synology, on the other hand, is a fortress. It's the difference between leaving your front door wide open and having a security system, deadbolt, and a camera. The problem is that most NAS deployments fall somewhere in between — partially secured, with one or two critical gaps that negate the rest of the effort.

Here's the 12-point checklist we apply to every Synology we deploy. Follow it and your NAS will be substantially more secure than the vast majority of devices on the internet.

Before you begin: This guide assumes you're running DSM 7.2 or later. Some settings and menu paths differ between versions. If you're on DSM 6.x, upgrade first — running an outdated DSM is itself a security vulnerability.

1Enable Two-Factor Authentication

This is the single most important step on this list. Enable 2FA (TOTP-based, via an app like Authy, 1Password, or Google Authenticator) for every account on the NAS — not just admin. A compromised password without the second factor is useless to an attacker.

In DSM, go to Control Panel → Security → Account → 2FA and enforce it for all users. If you're using LDAP or Active Directory, enforce 2FA at the directory level as well. No exceptions for "convenience" accounts.

2Disable the Default Admin Account

The default admin account is the most-targeted username in the Synology ecosystem. Create a new admin-level account with a non-obvious name, then disable the default admin account entirely. Do the same for any default service accounts.

This eliminates an entire class of brute-force attacks that assume the username admin exists. Every attacker's wordlist starts with it. Remove it from the equation.

3Never Expose DSM Directly to the Internet

This is the mistake that causes the most catastrophic breaches. If your NAS is accessible by forwarding port 5000 (or 5001 for HTTPS) through your router to the internet, stop right now and close it. There is no scenario in which this is safe, even with a strong password and 2FA.

Instead, use one of these approaches for remote access:

The principle is simple: if it's not behind a VPN or authenticated reverse proxy, it shouldn't be reachable from the internet. Period.

4Configure the Firewall

DSM includes a built-in firewall that most people leave unconfigured. Don't be most people. In Control Panel → Security → Firewall, create rules that:

A firewall that allows everything is the same as no firewall. A firewall that denies by default and allows only what you explicitly specify is what actually protects you.

5Keep DSM and Packages Updated

Synology releases DSM updates regularly, and many of them contain security patches for vulnerabilities that are being actively exploited. Enable automatic DSM updates in Control Panel → Update & Restore → DSM Update and set it to install critical updates automatically.

The same applies to installed packages — Container Manager, Active Backup, Surveillance Station, and every other package you've installed. Check Package Center → Updates monthly, or better, enable auto-update where available.

6Disable Unused Services

Every service running on your NAS is a potential attack surface. If you don't use Telnet, SSH, FTP, or AFP — disable them. In Control Panel → Terminal & SNMP, disable any protocols you don't actively use. In File Services, disable SMB1 (it's insecure and deprecated) and any file protocols you're not using.

If SSH is needed (and for our remote management, it is), configure it with key-based authentication only — disable password authentication entirely.

7Implement a 3-2-1 Backup Strategy

A hardened NAS is still a single device. If it's destroyed by fire, flood, theft, or a ransomware attack that compromises the entire network — your primary storage is gone. The 3-2-1 rule:

Configure Synology's built-in Hyper Backup to a cloud provider (Backblaze B2 is our preferred choice — it's S3-compatible and significantly cheaper than AWS), and set up Snapshot Replication to a second NAS or an external drive that's rotated off-site. Test the restore process at least quarterly. An untested backup is not a backup — it's a hope.

8Enable Snapshot Replication

Snapshots are point-in-time copies of your data that can be restored in seconds. They're the single best defense against ransomware because they let you roll back to a state before the encryption happened.

In Storage Manager → Snapshot, configure hourly snapshots with at least 7 days of retention for active data, and daily snapshots with 30 days of retention. For critical datasets, consider 15-minute snapshots. The storage overhead is minimal (snapshots only store the deltas), and the recovery value is enormous.

Then, replicate those snapshots to a second NAS or an external location. If the primary NAS is compromised, the replicated snapshots on a physically separate device are your last line of defense.

9Use Strong, Unique Passwords

This should be obvious, but it's worth stating: every account on your NAS needs a strong, unique password. Not a variation of a password you use elsewhere. Not a "company standard" that's the same across all systems. Unique per account, generated by a password manager, at least 16 characters.

Pair this with point #1 (2FA) and point #2 (no default admin) and your authentication layer is solid. Without it, the other 11 points on this checklist are built on sand.

10Configure Auto-Block and Login Limits

DSM can automatically block IP addresses that fail login attempts repeatedly. In Control Panel → Security → Account → Auto Block, configure it to block IPs after 5 failed attempts within a 5-minute window, and keep them blocked for at least 24 hours.

This won't stop a determined distributed attack, but it will throttle opportunistic brute-force attempts and give you visibility into who's trying. Pair this with login notification emails so you're alerted to repeated failures in real time.

11Secure Shared Folders with Proper Permissions

The principle of least privilege applies to file shares too. In Control Panel → Shared Folder, review every shared folder and ensure that:

  • Access is granted only to users who genuinely need it
  • Read-only access is used where full read-write isn't required
  • Guest access is disabled (unless you have a specific, deliberate reason for it)
  • Encryption is enabled for sensitive folders (Synology supports folder-level encryption)

Also, enable Advanced Sharing Permissions and verify that the NTFS/NFS permissions at the file level match the share-level permissions. Mismatches between share and file permissions are a common source of unintended data exposure.

12Air-Gap Your Backups

This is the point that most guides miss. If your backup is always connected to the same network as your primary storage, ransomware that compromises your network can encrypt both — primary and backup — simultaneously. That's game over.

An air gap means your backup is physically or logically disconnected from the production network at least some of the time. Options include:

  • An external USB drive that's connected only during backup runs and disconnected afterward
  • A second NAS on a separate VLAN that's only reachable during replication windows
  • Cloud backup that uses a separate set of credentials stored outside the primary environment

The goal is to ensure that even a total compromise of your primary NAS doesn't compromise all your recovery options. If every backup is reachable from the compromised system, you don't have a backup — you have a target.

Going Beyond: The Next Level

Once you've implemented all 12 points, you're in the top 5% of Synology deployments from a security standpoint. If you want to go further, consider:

  • Network segmentation — Put your NAS on a dedicated VLAN with firewall rules controlling exactly which devices can reach it and on which ports.
  • Certificate-based authentication for all services — Use Let's Encrypt certificates via DSM's built-in ACME client or DNS-01 challenges for all web-facing services.
  • Regular security audits — Review firewall logs, login attempts, and access patterns monthly. Anomalies are often the first sign of a compromised account.
  • Incident response plan — Document what happens if (when) something goes wrong. Who to call, how to isolate, how to recover. A plan you've never tested is worthless.
Security isn't a state — it's a process. The checklist above gets you to a strong baseline. But devices age, vulnerabilities emerge, and configurations drift. The businesses that stay secure are the ones that treat security as ongoing maintenance, not a one-time setup.

The Cost of Getting It Wrong

Ransomware on a Synology is not hypothetical. We've seen it. The typical scenario: an attacker gains access through an exposed DSM port or a compromised client device on the same network, encrypts the primary storage, and then targets the backups. Without snapshots and air-gapped backups, the business is faced with paying a ransom (often 5-6 figures), losing the data entirely, or rebuilding from whatever fragmented backups survive.

The 12-point checklist above takes 2-4 hours to implement on a properly set up NAS. The alternative — recovering from a ransomware incident — takes weeks, costs orders of magnitude more, and may still result in permanent data loss.

Security is cheap. Insecurity is expensive. The math is that simple.

Not sure if your NAS is secure?

Book a free discovery call. We'll review your current configuration, identify any gaps in the 12-point checklist, and give you a clear security assessment — no obligation, no upsell pressure.

Book a security review →