How do I secure my home WiFi?
The router settings that matter for security — the admin password, encryption type, firmware updates and guest networks.
- Difficulty
- beginner
- Time
- 45 min
- Read
- 3 min
Short answer
Change the router's admin password (separate from the WiFi password), use WPA3 or WPA2 encryption with a long passphrase, keep the firmware updated, and put smart-home devices and visitors on a guest network. Most home networks are compromised through a default admin password, not a cracked WiFi key.
Home network security has two distinct doors: the WiFi password that lets devices join, and the router admin password that lets someone change everything. People change the first and leave the second at its default, which is the wrong way round in terms of consequence.
What you'll need
- Access to the router's admin page
- The router's manual (optional)
Step by step
- Log into the router's admin page — usually 192.168.0.1 or 192.168.1.1 in a browser.The address and default credentials are usually printed on a label on the router itself.
- Change the admin password immediately if it's still the default.This is the most important step. Default admin credentials are published and universally known.
- Set encryption to WPA3 if available, or WPA2 (AES) if not.Never WEP or WPA — both are broken. If your router only offers those, it's old enough to replace.
- Set a long WiFi passphrase — several random words is ideal.Length matters more than symbols. A long passphrase is both stronger and easier to give to a visitor.
- Update the router firmware, and turn on automatic updates if offered.Router vulnerabilities are actively exploited. Many routers never get updated after installation.
- Turn off WPS.The PIN-based version has known weaknesses that allow the WiFi key to be recovered.
- Set up a guest network for visitors and smart-home devices.It isolates them from your computers and phones. Smart devices are frequently the weakest thing on a home network.
- Turn off remote administration unless you specifically need it.It exposes the router's admin interface to the internet, which is rarely necessary at home.
- Rename the network to something that doesn't identify you or the router model.A default name advertising the model tells an attacker which known vulnerabilities to try.
Tips
- If your internet provider supplied the router, check whether they push firmware updates automatically — many do, and it's one less thing to manage.
- A router more than about five years old may no longer receive security updates. That's a reason to replace it independent of speed.
- Write the new admin password somewhere you'll find it — a router admin password you've lost means a factory reset and reconfiguring everything.
- Smart plugs, cameras and doorbells are often the least-maintained devices on a network. The guest network is the practical containment for them.
Common mistakes
- Leaving the default admin password — Defaults are published online. It's the most commonly exploited weakness in home networks.
- Using WEP or WPA encryption — Both are broken and can be cracked quickly. WPA2 minimum, WPA3 if available.
- Never updating firmware — Router vulnerabilities are actively targeted and updates are the only fix.
- Putting smart devices on the main network — They're often poorly maintained and become the entry point to everything else.
Questions people ask
Does hiding my network name help?
Barely. A hidden SSID is trivially discoverable and makes connecting legitimate devices more awkward. Spend the effort on a strong passphrase and WPA3 instead.
Do I need to change my WiFi password regularly?
Not on a schedule. Change it if you've shared it widely, if a device was lost, or if you suspect access. A long unique passphrase left alone is better than frequent short ones.