Most home routers are set up once, at install, and never touched again — including the default admin password. That's the setting that matters most, and it's also the one most people skip. Here's a short list of changes that cover almost all of the real risk, without turning into a weekend networking project.

Step 1: Change the router admin password

This is different from your Wi-Fi password, and it's the one guides most often leave out. Log into your router's admin page (usually by typing its IP address, like 192.168.1.1, into a browser — check the label on the router itself if unsure) and change the default admin login. Default admin credentials for common router models are public knowledge, which makes this the single highest-value fix on this list.

Step 2: Use WPA3 or WPA2, never WEP or "open"

In your router's wireless security settings, confirm encryption is set to WPA3 if your router supports it, or WPA2 otherwise. Older WEP encryption is trivially breakable and shouldn't be used if it's still an option on your hardware. An open network with no password at all means anyone in range can join and potentially see unencrypted traffic.

Step 3: Set up a guest network for visitors and smart devices

Most modern routers support a separate "guest" Wi-Fi network, isolated from your main one. Use it for visitors and for smart-home devices like cameras, speakers, and plugs. This means a compromised smart bulb can't act as a stepping stone into the laptop where you do your banking — a real and increasingly common attack path.

Skip changing your Wi-Fi channel or fiddling with QoS settings unless you already have a specific speed problem — see our Wi-Fi speed guide for that. For security, the admin password, encryption type, and guest network cover the vast majority of real-world risk.

Step 4: Keep router firmware updated

Router firmware updates patch security vulnerabilities the same way phone and computer updates do. Many routers can check for and install these automatically — look for an "auto-update" toggle in the admin settings. If your router is old enough that the manufacturer no longer issues updates, that's a legitimate reason to replace it, security-wise, even if it still "works fine."

Step 5: Turn off remote administration if you don't need it

Some routers allow logging into the admin panel from outside your home network. Unless you specifically manage the router remotely, this setting is worth turning off in the admin panel — it removes an entire avenue of attack for something almost nobody actually uses.

A quick setup order