A lot of small businesses now run their core software as a virtual machine on a computer in the back room. Staff open it in a browser from the counter PC, a laptop or a phone, and the data stays in the building. That also means the shop's local network is now the front door to customer records, prices and inventory.
You don't need an IT department to lock that door. You need a handful of habits, done once and checked now and then. This checklist assumes one host machine, one VM and an ordinary small-business router.
1. Split the network: staff on one side, guests on the other
The single most useful change in most shops is a separate guest Wi-Fi.
Customers ask for the Wi-Fi password all day. If they join the same network as the business VM, their phones can see it, and so can whatever is running on those phones. Most routers offer a guest network option that isolates guest devices from the main LAN.
- Turn on the guest network and give it its own name and password.
- Enable client isolation or "allow guests to see each other / access local network: off," whatever your router calls it.
- Put the guest password on the sign at the counter. Keep the staff password off every sign, sticky note and receipt.
- Connect the host machine and staff devices to the staff network only, ideally the host by cable.
2. Give the VM an address that doesn't move
Staff bookmark the app's address. If the router hands the VM a new address after a power cut, every bookmark breaks.
Two ways to keep it stable:
- DHCP reservation (preferred): in the router's admin page, find the VM's network adapter in the client list and reserve its current address. The VM keeps getting the same address, and the router still knows about it.
- Static address inside the VM: pick an address outside the router's DHCP range so nothing else gets it, and set the gateway and DNS to match the router.
Write the address down in your shop's admin notes. For a business VM in VirtualBox, a bridged adapter makes the VM a normal device on the LAN, which is what makes reservations work cleanly.
3. Firewall basics: open only what staff need
On the router:
- Do not port-forward the business app to the internet. A LAN app that only staff use in the shop has no reason to be reachable from outside.
- Turn off UPnP unless something specific needs it. It lets devices open router ports on their own.
- Turn off remote administration of the router from the internet.
On the host machine:
- Enable the operating system firewall. On Linux,
ufwis a friendly front end; on Windows, keep Windows Defender Firewall on for private and public profiles. - Allow only what you use: remote management from your own admin computer, if you need it at all.
- Don't install extra services on the host "just in case." The host's job is to run the VM.
4. Passwords: change the defaults, separate the roles
Default passwords are printed on stickers and in manuals.
- Change the router admin password and the Wi-Fi passwords from the factory values.
- Use a different, long password for the host computer's admin account, the VM's system account and the app's owner account. One password everywhere means one leak opens everything.
- Give each employee their own login in the app. Shared logins make it impossible to tell who changed a price or closed a ticket.
- Store admin passwords in a password manager or a sealed envelope in the safe, not in a text file on the counter PC's desktop.
5. Updates without surprises
Unpatched software is how ordinary malware gets in. The trick in a busy shop is to update on purpose instead of letting updates reboot things mid-shift.
- Router: check for firmware updates on a regular schedule; many routers can notify you.
- Host OS: set updates to install outside business hours, and make sure the VM shuts down cleanly before the host reboots.
- VirtualBox: update it during a quiet window, then confirm the VM starts and staff can log in.
- The app and the VM's guest system: follow the vendor's update instructions.
Take a backup before any big update. If something breaks, you want a short path back.
6. Decide who has access, and write it down
Security in a small shop is mostly about people.
- Physical access: the host machine belongs somewhere customers can't reach, ideally a locked back room or cabinet with airflow. Anyone who can touch it can unplug it, boot it from a USB drive or walk off with it.
- App roles: give staff the lowest role that lets them do their job. Counter staff probably don't need to edit the price list. Technicians probably don't need to export the whole customer list.
- Departures: when someone leaves, disable their app login the same day, and change any shared password they knew, including the staff Wi-Fi.
- A short access list: who has the router password, who has the host admin password, who is an app owner or manager. Review it when staff change.
7. A short monthly check
Put a recurring reminder on the calendar and run through this list:
- Guest Wi-Fi still isolated? Join it with a phone and confirm the business app does not load.
- VM still at its reserved address?
- Any new port forwards or UPnP mappings on the router?
- Router, host and VirtualBox up to date?
- App user list matches current staff?
- Last backup restored successfully somewhere other than production?
None of this requires special gear, just settings you already have and a few minutes of attention.
Where this came from
We wrote this checklist while preparing RepairAmigo, free repair shop software made in Texas. It runs as one VirtualBox VM on the shop network and staff use it from any browser, so the advice above is exactly what we recommend to shops setting it up. We suggest a host with 16 GB of RAM, setup takes about an hour, and there are no ticket or user limits. It was built inside a busy repair shop that has processed more than 50,000 tickets with it, and there is a separate Spanish edition. RepairAmigo is coming soon; you can read more at repairamigo.com or see what free repair shop software means for us. Questions are welcome at support@repairamigo.com.
The RepairAmigo team
Top comments (1)
Practical checklist. The monthly test of joining the guest Wi-Fi and confirming the business app does not load is a nice touch, because it checks the isolation instead of just assuming the router setting works. Reserving the VM's address in DHCP also saves a lot of broken bookmarks after a power cut.