← All posts

2026 · JULY 20  ·  Security

IPv6 The Security Issue You Never Knew You Already Had

IPv6 is already in your environment and a massive security risk.

By Vishal Vashisht

A quick blog post that summarises my Substack newsletter

Many organisations believe they are not using IPv6 because they have never approved a formal migration. In reality, IPv6 is already enabled on most modern laptops, phones, servers and operating systems. This means IPv6 traffic may already be moving across the business without being properly monitored or controlled.

The main risk is not IPv6 itself. The risk is the gap between what the organisation believes is happening and what is actually happening.

Devices can automatically create IPv6 addresses and may prefer IPv6 connections without users noticing. A badly configured laptop, travel router or virtual machine can also advertise itself as a network router. Other devices may then send traffic through it, causing outages or creating an opportunity for interception.

Traditional security habits can make the problem worse. Network Address Translation should not be treated as a security control, while blocking all ICMPv6 traffic can break essential network functions and create difficult-to-diagnose failures.

Security monitoring may also be incomplete. Some alerting rules, traffic logs and investigation processes were designed around IPv4. IPv6 activity may therefore be harder to detect, trace or link to a user.

The answer is not an immediate company-wide migration. The first step is an audit.

Organisations should identify where IPv6 is active, prevent ordinary devices from acting as routers, review firewall rules and confirm that security tools can detect IPv6 traffic. They should also ensure that IPv6 is included in future technology purchases and network standards.

The key question for leaders is not, "Have we deployed IPv6?"

It is, "Do we know where IPv6 is already running, and can we see when it is being misused?"