Home Wi-Fi Router Security: 10 Settings Every Household Should Change


 

Every device in your home — laptops, phones, TVs, cameras, thermostats, game consoles — passes its traffic through one box. Compromise that box and an attacker sits between you and the entire internet, able to redirect your banking site, watch your traffic, and reach devices you assumed were private.

Yet the typical home router runs on factory settings from the day it was plugged in. Here are the ten changes that matter most, roughly in order of impact.

Do the admin password change last, not first. On the router I set up, every settings change logged me straight back out afterwards, so changing credentials at the start meant re-authenticating after each of the following nine steps.

Before You Start: Get Into Your Router

Open a browser and go to your router's admin address — usually 192.168.1.1 or 192.168.0.1. The default login is often printed on a sticker on the router itself. Many modern routers are managed through a phone app instead, which works just as well.

1. Change the Admin Password Immediately

Default admin credentials for every major router model are published online in searchable lists. This is the single most important change: set a long, unique admin password and store it in your password manager. Note this is separate from your Wi-Fi password.

2. Update the Firmware — and Turn on Auto-Updates

Router firmware contains security holes that get patched over time, and unpatched routers are actively hunted by automated botnets. Check for updates now, then enable automatic updates if your router supports it.

⚠️ End-of-life routers: if your router is more than about five years old and the manufacturer no longer issues firmware updates, replace it. An unsupported router accumulates permanent, publicly documented vulnerabilities. No setting can fix that.

3. Use WPA3 (or at Minimum WPA2-AES)

In wireless security settings, choose WPA3 if available, or WPA2-AES if not. Never use WEP or WPA (original) — both are broken and crackable in minutes. If your router offers only WEP, that alone is reason to replace it.

4. Set a Strong Wi-Fi Password

Use a passphrase of at least 16 characters — four random words work well and are easy to type on a TV remote. Avoid your address, surname, or phone number, all of which are easy for a neighbour or passerby to guess.

5. Turn Off WPS

Wi-Fi Protected Setup — the push-button pairing feature — has a well-known flaw that lets attackers brute-force the PIN and recover your Wi-Fi password. The convenience isn't worth it. Disable it.

6. Disable Remote Management

Remote administration lets you configure the router from outside your home network. Almost nobody needs it, and leaving it on exposes your admin panel to the entire internet. Turn it off unless you have a specific reason.

7. Create a Guest Network — and Use It for Smart Devices

A guest network is isolated from your main network. Put two categories of device on it:

  • Visitors' phones and laptops — so a friend's infected device can't reach your computers
  • Smart home gadgets — cameras, bulbs, plugs, and speakers are notoriously insecure, and isolating them means a compromised bulb can't reach your work laptop

This one change contains the damage from an entire category of attack.

8. Turn Off UPnP

Universal Plug and Play lets applications automatically open ports through your firewall — convenient for some games and consoles, but also a favourite of malware that uses it to expose internal devices. Disable it, and manually forward the specific ports you actually need.

9. Change the Network Name (SSID)

Default names like "TP-Link_4A2C" or "BTHub6-XYZ" advertise your router's make and model, which tells an attacker exactly which known vulnerabilities to try. Choose a neutral name that reveals nothing about the hardware, your family name, or your flat number.

10. Review Connected Devices Periodically

Most routers list every connected device. Check it every few months. Unrecognized devices mean either a forgotten gadget or an intruder — and if it's the latter, change your Wi-Fi password immediately, which kicks everything off until it re-authenticates.

Bonus: Consider Changing Your DNS

Switching your router's DNS to a filtering resolver adds a layer of protection for every device in the house, blocking known malicious and phishing domains before they load. Several reputable providers offer this free, and some include family content filtering as an option.

Signs Your Router May Be Compromised

  • Your browser redirects to unexpected sites or shows unusual certificate warnings
  • The admin password no longer works
  • DNS settings have changed to servers you didn't configure
  • Internet is unusually slow with no explanation
  • Unfamiliar devices appear repeatedly in the connected-device list

If you suspect compromise: factory-reset the router, update the firmware, then reconfigure it from scratch with the settings above.

Final Thoughts

Router security is genuinely a one-evening job that then protects you for years. Change the admin password and update the firmware tonight — those two alone eliminate most real-world attacks. Do the rest over the weekend, and put a calendar reminder to check firmware every six months.

Related reading: extend the same thinking to your devices with our 12 essential smartphone security settings.

Comments

Popular posts from this blog

Best Antivirus Software of 2026: Top 5 Compared After Real Testing

Public Wi-Fi Dangers: 7 Critical Steps to Stay Safe

Best Identity Theft Protection Services of 2026: Top 5 Ranked and Reviewed