Every device in your home – laptops, phones, smart TVs, doorbells, baby monitors – talks to the internet through one box: your router. Yet most routers still run with the settings they shipped with, sometimes for a decade. The good news is that securing a home router is not a technical odyssey. It is about seven settings, and you can fix all of them in a quarter of an hour.
First, get into your router’s settings
Open a browser and type your router’s address, usually 192.168.1.1 or 192.168.0.1 (it is printed on the sticker on the bottom of the device, along with the admin password). Many modern routers also offer a phone app, which is often easier. If you rent your router from your internet provider, the same settings exist – they are just sometimes hidden behind a provider-branded interface.
1. Change the admin password
This is not your Wi-Fi password – it is the password that controls the router itself. Default admin passwords are printed on stickers, shared between thousands of units, and listed in public databases. Change it to something long and unique, and store it in your password manager. This one change locks out the majority of automated router attacks.
2. Use WPA3 (or WPA2) with a strong Wi-Fi password
In the wireless settings, choose WPA3 if available, otherwise WPA2-AES. Never leave a network on WEP or “open”. Your Wi-Fi password should be long – a phrase of four or five random words beats P@ssw0rd1 by an astronomical margin – because short passwords can be cracked offline once an attacker captures a single connection handshake from the street outside.
3. Turn off WPS
WPS is the push-button pairing feature, and its PIN variant is famously brute-forceable: the eight-digit PIN is effectively two short PINs checked separately, reducing millions of combinations to a few thousand attempts. Almost nobody actually needs WPS. Switch it off.
4. Update the firmware – and turn on auto-updates
Router vulnerabilities are discovered constantly, and unpatched home routers are recruited into botnets by the hundred thousand. Find the firmware or update section, install anything pending, and enable automatic updates if your model supports it. If your router is so old that updates stopped years ago, replacing it is a genuine security purchase, not gadget shopping.
5. Disable remote management
Remote management lets the router’s settings page be reached from the internet, not just from inside your home. Unless you have a specific, deliberate reason to use it, it should be off. This is one of the most commonly exploited router features.
6. Set up a guest network
Guests, and especially smart-home gadgets, do not need to be on the same network as the laptop where you do your banking. A guest network with its own password keeps visitors’ possibly-infected phones and your cheap smart plugs walled off from your important devices. Most routers make this a single toggle.
7. Review what is connected
Somewhere in the interface is a list of connected devices. Scan it once in a while. Most entries will be yours (phones, TVs, printers), but if you see something you cannot account for, change the Wi-Fi password and reconnect only the devices you recognise.
What about hiding the network name or filtering MAC addresses?
You will find guides recommending you hide your SSID or allow only approved hardware addresses. Both are security theatre: hidden networks are trivially visible to the free tools attackers actually use, and MAC addresses can be copied in seconds. They add daily inconvenience without adding real protection. The seven steps above are what actually matters.
The 15-minute checklist
- New admin password (stored in your password manager)
- WPA3 or WPA2-AES with a long passphrase
- WPS off
- Firmware updated, auto-update on
- Remote management off
- Guest network on for visitors and smart gadgets
- Connected-device list reviewed
Do this once, put a yearly reminder in your calendar to re-check firmware and connected devices, and your home network will be better protected than the vast majority of households.