Give households a vendor-neutral router and Wi-Fi security checklist.
Your router is both the front door to the home network and the system that decides which connected devices can talk. Secure its administrator account, keep its software supported, use modern Wi-Fi encryption, disable features you do not need, and know how to reset and recover it.
Identify the router and its support status
Find the exact manufacturer, model, hardware revision, internet-provider ownership, current firmware, and official administration address or app. If the model no longer receives security updates, plan replacement. Download instructions only from the provider or manufacturer’s verified site.
Harden the important settings
- Unique router administrator password and protected account email
- Automatic or regularly checked firmware updates
- WPA3 Personal when all devices work, otherwise WPA2 with AES; avoid obsolete modes
- Long unique Wi-Fi passphrase and non-identifying network name
- WPS, remote administration, UPnP, and exposed services off unless specifically needed
- Guest or isolated network for visitors and untrusted smart devices where supported
Separate credentials and purposes
| Credential or network | Controls | Good practice |
|---|---|---|
| Administrator login | Router configuration | Unique and never shared with guests |
| Main Wi-Fi | Household network access | Unique long passphrase |
| Guest or IoT network | Lower-trust device access | Isolation and separate passphrase |
Make changes without losing recovery
- Save provider details and current configuration where supported.
- Update firmware and reboot deliberately.
- Change administrator and Wi-Fi credentials.
- Configure modern encryption and disable unused features.
- Reconnect known devices and isolate guests or smart products.
- Review connected devices and test reset instructions.
Watch for fragile conveniences
- Default administrator password still active
- Router app protected by a reused email password
- Port forwarding left from an old game or camera
- Unknown devices ignored rather than identified and removed
Maintain a private network record
Record model, owner, support page, firmware check date, administrator recovery route, network purposes, intentionally enabled remote features, port forwards, reserved addresses, backup date, and replacement review. Do not store live passwords in an unprotected note.
Continue with the next decision
Sources and further reading
Primary and contextual sources used to verify definitions or give readers a relevant next resource.
- CISA Secure Our World Official public cybersecurity guidance supporting updates, strong credentials, and multi-factor authentication.