Most home routers are set up once, at install, and never touched again — including the default admin password. That's the setting that matters most, and it's also the one most people skip. Here's a short list of changes that cover almost all of the real risk, without turning into a weekend networking project.
Step 1: Change the router admin password
This is different from your Wi-Fi password, and it's the one guides most often leave out. Log into your router's admin page (usually by typing its IP address, like 192.168.1.1, into a browser — check the label on the router itself if unsure) and change the default admin login. Default admin credentials for common router models are public knowledge, which makes this the single highest-value fix on this list.
Step 2: Use WPA3 or WPA2, never WEP or "open"
In your router's wireless security settings, confirm encryption is set to WPA3 if your router supports it, or WPA2 otherwise. Older WEP encryption is trivially breakable and shouldn't be used if it's still an option on your hardware. An open network with no password at all means anyone in range can join and potentially see unencrypted traffic.
Step 3: Set up a guest network for visitors and smart devices
Most modern routers support a separate "guest" Wi-Fi network, isolated from your main one. Use it for visitors and for smart-home devices like cameras, speakers, and plugs. This means a compromised smart bulb can't act as a stepping stone into the laptop where you do your banking — a real and increasingly common attack path.
Step 4: Keep router firmware updated
Router firmware updates patch security vulnerabilities the same way phone and computer updates do. Many routers can check for and install these automatically — look for an "auto-update" toggle in the admin settings. If your router is old enough that the manufacturer no longer issues updates, that's a legitimate reason to replace it, security-wise, even if it still "works fine."
Step 5: Turn off remote administration if you don't need it
Some routers allow logging into the admin panel from outside your home network. Unless you specifically manage the router remotely, this setting is worth turning off in the admin panel — it removes an entire avenue of attack for something almost nobody actually uses.
A quick setup order
- Change the router's admin password from the default.
- Confirm wireless encryption is set to WPA3 or WPA2.
- Set up a guest network for visitors and smart-home devices.
- Turn on automatic firmware updates, or check manually every few months.
- Disable remote administration unless you specifically need it.