
Home Wi-Fi security is mostly a small checklist of router settings. The important items are not exotic; they are the defaults people forget to replace after installation.
Does this affect you?
Use this for any home router or ISP gateway if you have not reviewed its security settings since setup.
Work through the security checklist
Do these from the router app or admin page. The first two matter most.
- Change the router admin password from the factory default. This protects the settings page and is separate from the Wi-Fi password.
- Use WPA3 if supported, or WPA2 if not. Avoid WEP and old WPA modes.
- Set a strong, unique Wi-Fi password. A longer passphrase is better than a short complicated one.
- Turn off WPS unless you actively need it. Button/PIN pairing has a history of weaknesses.
- Create a guest network for visitors and less-trusted smart home devices.
- Turn off remote management unless you truly need to administer the router from outside the home.
- Check for firmware updates and install available security fixes.
- Review connected devices occasionally so unknown devices are noticed.
More control
Hidden SSID is mostly theater
Turning off name broadcast hides the network from casual lists but not from basic scanning tools. It also makes setup harder. Modern encryption and a strong password matter more.
MAC filtering is only a speed bump
Approved-device lists can be bypassed by spoofing a MAC address. Use it only as an extra layer, not as your main protection.
Guest isolation limits damage
A compromised smart plug or visitor device has less reach when it cannot see your main computers, files, printers, and trusted devices.
Factory reset is a last resort
A reset lets you start over, but it erases Wi-Fi names, passwords, port forwards, parental controls, and custom settings. Try normal configuration changes first.
Sources
- CISA – Securing Wireless Networks (2025)
- Wi-Fi Alliance – WPA3 Security (2025)
- FCC Consumer Guide – Wireless Network Troubleshooting (2024)
