Home Wi-Fi Router Security Checklist: 10 Settings to Fix Tonight
Your router is the front door for every device in the house, and most ship with that door on the latch. Ten settings ranked by impact, then a 20-minute pass through the admin page to set them all.

- Read time5 min
- StatusSeptember 2026
The checklist, most important first
1. Change the admin password
The sticker password (or "admin/admin") is printed in every manual online. Anyone on your Wi-Fi, or malware on a laptop, can log in and rewrite your settings. CISA and the FTC both put this first.
- Where: Administration or System, then Password; change the username too if the router allows it
- Use: a generated 16-plus character password saved in your password manager
2. Use WPA3, or WPA2 with a long passphrase
Encryption stops a neighbour or a parked car reading your traffic or joining your network. The NSA's guidance: WPA3-Personal where every device supports it, WPA2/WPA3 mixed mode where not, and a passphrase of at least 20 characters.
- Where: Wireless, then Security; pick WPA3-Personal or WPA2/WPA3-Personal, AES only
- Never: WEP, original WPA, TKIP, or an open network
3. Update the firmware and turn on auto-update
Router bugs are patched constantly, and unpatched routers are what botnets are built from. Most current routers can install updates on their own overnight; Netgear and TP-Link both document the switch.
- Where: Administration, Firmware or Router Update; enable automatic updates
- Habit: if there is no auto option, put a quarterly reminder in your calendar
4. Turn off WPS
Wi-Fi Protected Setup lets devices join by button press or an eight-digit PIN. The PIN scheme is broken by design: CISA warned in 2012 that it can be brute-forced in hours, handing an attacker your Wi-Fi password. Nothing in your house needs it.
- Where: Wireless, then WPS; set it to Off or Disabled
- Instead: type the passphrase once per device, or share it with a QR code from your phone
5. Turn off remote management
Remote management exposes the router's login page to the whole internet so you can tweak settings from anywhere. In practice it exposes it to scanners hunting weak passwords and unpatched bugs. The FTC says turn it off.
- Where: Administration or Advanced, then Remote Management, Web Access from WAN, or similar
- Need it anyway? Use the maker's phone app, which connects through its cloud rather than an open port
6. Turn off UPnP
Universal Plug and Play lets any device on your network ask the router to open a hole in the firewall, with no password. It is why a console "just works" online, and why malware on one device can quietly expose another. Canada's Cyber Centre recommends disabling it on home routers.
- Where: Advanced, NAT Forwarding or WAN, then UPnP
- Trade-off: a console may report "strict NAT"; add a manual port-forward rule for that one device
7. Turn on a guest network for visitors
A guest network gives visitors internet without your main password or a view of your printer, backup drive and laptops. Turn on client isolation (sometimes "AP isolation") so guest devices cannot see each other.
- Where: Wireless, then Guest Network; give it its own name and password
- Rotate: change the guest password whenever a house guest or contractor leaves
8. Put smart-home devices on their own network
Smart plugs, bulbs, cameras and TVs get security updates rarely, then not at all. Move them to the guest network (or an IoT network if your router offers one) so a compromised gadget cannot reach the devices holding your files.
- Where: the same Guest Network page; some mesh systems (eero, Orbi, Deco) offer a dedicated IoT network
- Watch-out: casting to a TV on the other network may need isolation loosened; test as you go
9. Rename the network, and keep it visible
The default name ("NETGEAR47", "TP-Link_3C2A") tells a passer-by your router model and, for some brands, hints at the default password. Change it to something bland, and do not hide it: the NSA advises against hidden networks because your devices then broadcast the name everywhere they go.
- Where: Wireless, then Network Name (SSID)
- Avoid: your surname, flat number or anything that identifies the house
10. Retire end-of-life routers
When a maker stops publishing updates, every bug found afterward stays open forever. In May 2025 the FBI warned that criminals were mass-infecting end-of-life routers to sell as proxy nodes. Check your model on the maker's support page; if it is unsupported, replace it.
- Cost: a solid WPA3 router runs roughly $80 to $150 in September 2026
- ISP box? the NSA suggests your own router behind the ISP modem; at minimum change the ISP box's admin password
What doesn't matter much
- Hiding the network name. Scanners still see it, and your phone leaks it in cafés.
- MAC address filtering. Addresses are copied in seconds and phones randomise theirs anyway.
- Static IP addresses or disabling DHCP. Inconvenience for you, no obstacle to anyone else.
- Turning the router off at night. Harmless, but the threats above do not keep office hours.
The 20-minute pass
- Open the admin page. The address is on the sticker (often 192.168.0.1 or 192.168.1.1) or in the maker's app.
- Change the admin password and save it to your password manager first.
- Fix Wireless Security. WPA3-Personal or WPA2/WPA3, a new 20-plus character passphrase, and a fresh network name. Every device will reconnect afterwards.
- Check for firmware and turn on automatic updates.
- Switch off WPS, remote management and UPnP. Three toggles, usually under Advanced.
- Turn on the guest network with isolation and move smart-home devices over one at a time.
- Log out of the admin page. The FTC recommends it; it stops a stray browser tab being used against you.
Quick answers
Should I use WPA2 or WPA3 on my home router?
WPA3-Personal if every device supports it, otherwise the WPA2/WPA3 mixed mode most routers offer. Either is fine with a passphrase of 20 characters or more. Never use WEP, WPA (the original) or an open network.
Is it safe to leave WPS turned on?
No. The WPS PIN method has a design flaw, documented by CISA in 2012, that lets an attacker within range guess the PIN in hours and pull your Wi-Fi password. Turn WPS off in the wireless settings and connect new devices by typing the passphrase.
Do I need a separate network for smart home devices?
It is the most useful upgrade after the basics. Smart plugs, cameras and TVs get patched rarely; putting them on a guest or IoT network with device isolation means one compromised gadget cannot reach your laptop, phone or backups.

