An unsecured or poorly configured Wi-Fi network isn't just a speed problem β it's an open door to your files, your smart home devices, and potentially your online banking sessions. This guide covers the router settings that genuinely improve security, in order of importance, so you can lock down your home network in under an hour without needing to be a network engineer.
Step 1: Change the Default Admin Password
Before touching Wi-Fi settings, secure the router itself. Default admin logins (often "admin/admin" or "admin/password") are publicly documented for every router model and are the first thing an attacker on your network tries.
- Find your router's admin address, commonly 192.168.1.1 or 192.168.0.1.
- Log in with the current credentials, printed on the router's label if unchanged.
- Find Administration or System Settings and change the admin password to something unique β not the same as your Wi-Fi password.
- Store it in a password manager, since router admin pages are logged into rarely and easy to forget.
Safety note: If you've ever given your router admin credentials to a technician, guest, or previous housemate, change them now β they don't expire on their own.
Step 2: Use WPA3 or WPA2 Encryption β Never WEP or Open
- In the router admin page, find the Wireless Security or Wi-Fi Security section.
- Set the security mode to WPA3 if your router and devices support it, or WPA2-AES (sometimes labelled WPA2-Personal) as a strong fallback.
- Avoid WEP entirely β it can be cracked in minutes with freely available tools and offers essentially no real protection.
- Avoid Open (no password) networks for your main household network β reserve open access for a dedicated guest network only (see below).
- If your router offers "WPA2/WPA3 mixed mode," this is a sensible default for compatibility with older devices while still protecting newer ones.
Step 3: Set a Genuinely Strong Wi-Fi Password
- Use at least 12-16 characters, mixing words, numbers, and symbols β a memorable passphrase like
Bramble-Fence-47-Otter!is both stronger and easier to type on a games console than a random string. - Avoid anything tied to your address, name, or date of birth.
- Never reuse your email or banking password for Wi-Fi β if it leaks (e.g. shared with a tradesperson or written on a sticky note a photo captures), the blast radius stays contained.
- Change it whenever someone who no longer needs access has had it β an ex-housemate, a completed building project, or after a lost phone that was connected.
Step 4: Rename Your Network (SSID) Sensibly
- Avoid using your surname, house number, or router model in the network name β this gives an attacker free information about who they're targeting and what hardware to look up known vulnerabilities for.
- Don't bother trying to "hide" your SSID (disabling broadcast) as a security measure β it's trivially bypassed with free scanning tools and mainly just causes connection headaches for your own devices.
Step 5: Set Up a Separate Guest Network
Almost all modern routers support a guest Wi-Fi network, isolated from your main devices.
- In the router admin page, find Guest Network or Guest Wi-Fi and enable it.
- Give it a different name and its own password.
- Enable client isolation or AP isolation if offered β this stops guest devices from seeing or accessing your main devices (PCs, NAS drives, smart home hubs) even while connected.
- Use this network for visitors, smart plugs and cheap IoT gadgets of uncertain security, and any device you don't fully trust β this keeps a compromised smart bulb from becoming a stepping stone to your laptop.
Pro tip: Many home network intrusions don't come from someone parked outside cracking your password β they come from a cheap, insecure IoT device (a smart plug, doorbell, or budget camera) already inside your network. A guest network with client isolation is one of the single most effective, least effort security upgrades you can make.
Step 6: Keep Router Firmware Updated
- Check Administration > Firmware Update (naming varies) in your router's admin page every few months.
- Enable automatic updates if your router offers it β most modern ISP-supplied routers do this silently, but older or third-party routers often don't.
- If your router is more than 6-7 years old and no longer receives updates from the manufacturer, treat this as a genuine security risk, not just a performance one β replace it.
Step 7: Disable Risky Convenience Features
- WPS (Wi-Fi Protected Setup): the push-button pairing feature has known vulnerabilities in its PIN-based mode. If you don't actively use it to add devices, disable it in the wireless settings.
- Remote management / remote admin access: unless you specifically need to manage your router from outside the house, turn this off β it's an unnecessary door left open to the internet.
- UPnP (Universal Plug and Play): convenient for games consoles automatically opening ports, but it lets any device on your network request port forwarding without asking you. Disable it if you don't rely on it, or only enable it when needed.
Step 8: Audit Connected Devices Regularly
- Open your router's connected devices or client list page.
- Go through the list and confirm you recognise every device β most routers now label devices by manufacturer or hostname.
- Anything unfamiliar could be an unauthorised connection or simply an old device you forgot about (a previous phone, a neighbour's device that connected during a WPS window, a smart device you no longer use).
- If you find something you can't identify and can't account for, change your Wi-Fi password immediately and re-connect only your known devices.
Step 9: Consider Additional Layers for Sensitive Use
- Enable your router's built-in firewall (usually on by default, but worth confirming in Security settings).
- If you work from home with sensitive data, consider putting work devices on the guest/isolated network segment rather than the general household one.
- Turn on two-factor authentication on your router's cloud management app if it has one (increasingly common with mesh systems), so a leaked router password alone isn't enough to reconfigure your network remotely.
Quick Security Checklist
- [ ] Router admin password changed from default
- [ ] WPA2 or WPA3 encryption enabled (never WEP or open)
- [ ] Wi-Fi password is 12+ characters and not reused elsewhere
- [ ] SSID doesn't reveal your name, address, or router model
- [ ] Guest network enabled with client isolation for visitors and IoT devices
- [ ] Router firmware up to date
- [ ] WPS and remote management disabled unless actively needed
- [ ] Connected devices list reviewed and unfamiliar entries investigated
Securing your home Wi-Fi is mostly a one-off setup job, not an ongoing chore β spend the hour once, and revisit the checklist every six months or whenever you get new hardware or a new router.
Was this guide helpful? Explore more Networking & Wi-Fi Issues guides, or browse all Operating System & Software articles.