You don't need enterprise gear to have a secure home network. You need to undo a handful of insecure defaults and turn on the protections your router already has. Work down this list once and you're ahead of most homes and small offices.
Your router — the front door
- Change the admin password. The default (often admin/admin) is public knowledge. Set a strong, unique one.
- Update the firmware. Old router firmware is full of known holes. Enable auto-update if it exists.
- Turn off WPS and remote administration. Both are convenience features that are common attack paths.
- Change the default network name (SSID) so it doesn't advertise your router's make and model.
Your Wi-Fi
- Use WPA3 (or WPA2 if that's the newest your gear supports). Never WEP or an open network.
- Set a long passphrase — length beats complexity. A four-word phrase is strong and memorable.
- Create a guest network for visitors and smart-home devices, so a compromised gadget can't reach your computers.
The single highest-value move: put your smart-home devices (cameras, plugs, TVs) on the guest network. IoT gadgets are the weakest link, and isolating them means one hacked bulb can't see your laptop.
The devices on it
- Keep phones, laptops, and IoT devices updated — most breaches exploit known, already-patched flaws.
- Review the list of connected devices in your router now and then; investigate anything you don't recognize.
- Turn on the router's built-in firewall if it isn't already, and disable services (like UPnP) you don't use.
Get the full printable checklist
The Home Network Setup & Security Checklist is the complete, step-by-step version — every setting above plus router placement, DNS choices, and a device-by-device walkthrough anyone can follow. Instant download.
Get the checklist →