Skip to content
HOW BISCUITPractical guides

Explore How Biscuit

Search How Biscuit

Enter a word or phrase to search.

Home Router Security Checklist: Passwords, Updates, Encryption, and Guests

Change the router administrator password, use WPA2 or WPA3 with a strong Wi-Fi password, install firmware updates, disable unnecessary remote administration and obsolete features, separate guests and untrusted smart devices where possible, and keep a private recovery record.

What to know

  • The router administrator password and the Wi-Fi network password protect different things and should not be identical.
  • Firmware updates and support status matter because the router is the gateway for every connected device.
  • A guest or IoT network can reduce exposure, but it does not make an unsupported or compromised device safe.

A home router controls who can join the local network, which devices can reach one another, and how traffic leaves the home. The most useful security review starts with administrator access and software support rather than hiding the network name or buying decorative “security” accessories.

Record the exact router identity

Photograph the model, hardware revision, serial number, and internet-provider information. Save the official manual and support page. Check whether the router is still receiving security and firmware updates.

An old router that no longer receives updates may need replacement even when its Wi-Fi signal remains strong. Keep retirement dates and configuration backups in a private household inventory.

Change the administrator credentials

The router administration account controls configuration. Replace default or provider-generic credentials with a unique password stored in a password manager. The Federal Trade Commission recommends changing default administrator information and logging out after making changes. [1]

Do not use the Wi-Fi password as the administrator password. If the router supports multifactor authentication for cloud management, enable it.

Keep the administration page local unless remote access is genuinely needed. Disable internet-facing administration, vendor cloud access, or support access that you do not use and can safely turn off.

Use current Wi-Fi encryption

Select WPA3 when every necessary device supports it. WPA2 remains widely supported and is preferable to obsolete WEP or original WPA. Use a long, unique network password that is not shared with other accounts.

Do not operate an open household network merely for convenience. If one old device supports only obsolete security, consider replacing it or isolating it instead of weakening the primary network.

Install firmware updates

Enable automatic updates when the manufacturer provides a trustworthy option. Otherwise, set a recurring reminder to check the official app or support page.

Do not download firmware from a forum, file-sharing site, or search advertisement. Preserve the current configuration and recovery instructions before a major update.

Restarting a router is not the same as updating it. A restart can clear a temporary fault but does not patch known vulnerabilities.

Disable features you do not need

Review Wi-Fi Protected Setup, UPnP, port forwarding, DMZ host settings, file sharing, USB storage, remote administration, and vendor cloud services. Disable unused services after confirming they are not required by phones, games, work equipment, cameras, or accessibility systems.

Do not blindly turn off every feature. Record the existing state and make one controlled change at a time so you can reverse a compatibility problem.

Create a guest network

Use a guest network for visitors rather than sharing the primary password. Confirm whether guests are isolated from household devices; some routers use “guest” only as a second name without full isolation.

A separate IoT network can be useful for speakers, plugs, appliances, cameras, and other products that do not need access to personal computers. The FTC also recommends keeping connected devices updated, changing default passwords, and reviewing the data they collect. [2]

Review the connected-device list

Compare the router client list with a private household inventory. Investigate unknown entries methodically by checking device names, manufacturer identifiers, randomized phone addresses, and recent guests.

Do not accuse someone based only on a vague client label. When unauthorized access is credible, update the router, change the Wi-Fi password, reconnect known devices deliberately, and review account security.

Protect DNS and configuration settings

Use the provider or another reputable DNS service selected intentionally. Unexpected DNS servers, port forwards, or administrator accounts can indicate unauthorized configuration changes.

Back up the router configuration only when the manufacturer provides a secure method. Treat the backup as sensitive because it may contain network names, settings, and credentials.

Keep recovery information private

Store the model, administrator URL, account owner, support contact, configuration date, and password-manager entry name. Do not tape the administrator password to the router or post label photographs publicly.

A secure router configuration is not a one-time project. Review it after firmware changes, provider replacements, a move, an account compromise, or the addition of sensitive connected devices.

Limits and cautions

  • Available security settings, update methods, encryption modes, network isolation, and support periods vary by router and internet provider.
Sources reviewed

Source notes

  1. How To Secure Your Home Wi-Fi NetworkFederal Trade Commission
  2. Securing Your Internet-Connected Devices at HomeFederal Trade Commission