Start with the administrator password
The Wi-Fi password controls who can join your network. The administrator password controls who can change every setting on the router, including the Wi-Fi password, the DNS servers your traffic uses and whether remote management is open to the internet. They are different credentials and the second one matters more.
Default administrator credentials for every common router model are published and widely known. If yours is still at the factory value, anyone who reaches your network — a guest, a neighbour who has your Wi-Fi password, or malware on a family laptop — can take full control of it.
Change it to something long and unique, store it in a password manager, and do not reuse it anywhere else. This is a two-minute change that removes the most common real-world attack on home networks.
Encryption and passphrase
Use WPA3 if all your devices support it, or WPA2/WPA3 mixed mode if you have older equipment that would otherwise be locked out. WPA2 with AES remains acceptable. WEP and WPA are broken and should never be used, and an open network with no password is only appropriate for a deliberately isolated guest network.
Choose a passphrase of at least twelve characters. Length matters far more than exotic characters, and three or four unrelated words with a digit are both strong and easy to read out to a visitor. Avoid your phone number, address, business name or anything else someone could guess from knowing you.
Turn WPS off. The push-button pairing feature has known weaknesses in several implementations, and connecting a device by typing the passphrase takes only a few seconds longer.
- WPA3, or WPA2/WPA3 mixed mode for older devices.
- Twelve characters minimum, longer is better.
- WPS disabled.
- Remote or WAN management disabled unless you genuinely need it and have secured it.
- Firmware kept up to date, automatically where the router supports it.
Separate your guests and your devices
A guest network gives visitors internet access while keeping them away from your computers, printers, network storage and cameras. Almost every modern router offers one, it takes a minute to enable, and it is the single most effective structural improvement you can make to a home network.
For a business, this is not optional. Customer Wi-Fi and the network carrying your till system, payment terminal or patient records should never be the same network. On managed equipment, use VLANs to enforce the separation properly rather than relying on a consumer guest mode.
Smart home devices deserve the same treatment. Cheap connected plugs, bulbs and cameras are rarely well maintained and are a realistic route into a network. Putting them on the guest or an IoT network limits what a compromised device can reach.
Technician’s tip
Give the guest network a rotating passphrase and change it when staff or tenants change. It is far easier than changing the main passphrase and reconnecting every device you own.
Keep the router itself patched
Router firmware fixes real, exploited security vulnerabilities. Enable automatic updates where the manufacturer offers them; where they do not, put a reminder in your calendar to check every few months. An unpatched internet-facing device is exposed for as long as it stays unpatched.
Disable remote management, UPnP and any WAN-side administration you do not actively need. These features exist for convenience and each one widens the surface available to an attacker. Turn them on deliberately, for a reason, not by default.
When a router stops receiving firmware updates entirely, treat that as the end of its service life for anything sensitive. Old equipment can be repurposed as a wired-only access point on an isolated segment, but it should not be the device facing the internet.
Advice you can safely ignore
Hiding your network name provides no real security. The network is still visible to anyone with basic tools, and hiding it only makes connecting your own devices harder and, on some platforms, slightly less secure.
MAC address filtering is similarly weak. Addresses are transmitted unencrypted and are trivial to copy, so the filter stops a curious neighbour and nobody else, at the cost of a great deal of administrative irritation every time you buy a device.
Spend your effort on the things that work: a strong unique passphrase, a changed administrator password, current firmware, network separation and remote management switched off. That set of five puts a home network well ahead of most.