How to secure your home Wi-Fi router: a practical guide
Your router sits between every device in your home and the internet, yet it is the device most people configure once and forget. Here are the checks that matter, in order, and what they cannot protect against.

Every phone, laptop, television, camera and smart speaker in a home reaches the internet through one box. If that box is poorly configured or runs outdated software, an attacker who gets into it may be able to observe or redirect traffic, or reach other devices on the network. Most households never open its settings after installation, which is why a short, deliberate review is worthwhile.
This is a vendor-neutral guide for US readers. It draws on public home-network guidance from CISA and small-business basics from NIST; the order and examples are editorial recommendations, not a guarantee. Menus differ by manufacturer and internet provider, so use your device's own documentation for exact steps.
The short answer
Change the router's administrator password, use the strongest Wi-Fi encryption your devices support (WPA3 where available, otherwise WPA2), keep the router's firmware current, turn off remote administration you do not use, and replace the router if the manufacturer no longer issues security updates.
Step 1: Separate the two passwords
Routers have two credentials people confuse. The Wi-Fi password lets devices join the network. The administrator password lets someone change the router's settings. Default administrator credentials are often printed on a label or widely documented, so change them to a long unique value, ideally stored in a password manager. Do the same with the default network name if it reveals the model or your name.
Step 2: Choose the right encryption
Open the wireless settings and select WPA3 if every device you own supports it, or WPA2 with AES if not. Avoid open networks, WEP and the older WPA setting. A long passphrase of several unrelated words is easier to type on a television than a random string and is still strong. Turning off WPS, a push-button pairing feature, removes one known weak point on many devices.
Step 3: Update the firmware
Router software has vulnerabilities like any other software. Check the administration page for a firmware update option and enable automatic updates if one exists. If your router is provided by your internet provider, the provider may manage updates for you; confirm that rather than assuming. Our guide to deciding when to install updates covers the broader trade-off: when to install a major software update.
Step 4: Turn off what you do not use
Remote administration lets someone manage the router from outside your home. Unless you deliberately need it, disable it. Review port forwarding and any other exposed services, and remove entries for devices you no longer own. Features such as UPnP are convenient but can open paths automatically; disable them if nothing in your home depends on them.
Step 5: Give guests and smart devices their own network
Many routers offer a guest network. Put visitors there, and consider placing cameras, televisions and other connected devices there too. The goal is separation: if a low-cost gadget is compromised, it should not sit on the same network as your work laptop and family files. Not every router isolates guest devices equally well, so check the setting that blocks guests from reaching each other and the main network.
Step 6: Know what is connected
Look at the list of connected devices in the administration page. Unfamiliar entries are not proof of an intruder, since many devices use generic names, but they are a reason to investigate. If you are unsure, change the Wi-Fi password and reconnect only devices you recognize.
Know when to replace the router
A router that no longer receives security updates cannot be made safe through settings alone. Check the manufacturer's support page for an end-of-life date. If you rent equipment from your internet provider, ask for a replacement instead of buying around it, and reset old equipment to factory settings before returning or discarding it.
Common mistakes
- Hiding the network name and assuming that adds security. It adds inconvenience and little protection.
- Leaving the administrator password at its default because the Wi-Fi password is strong.
- Buying a new router but never running its updates.
- Treating a VPN as a substitute for a secure router. They solve different problems.
What the evidence supports — and what it cannot promise
CISA and NIST both encourage changing default credentials, using current encryption, updating software and limiting unneeded features. These are widely accepted practices, not the result of a controlled study showing that a specific checklist prevents a particular share of home-network attacks. Many compromises begin with phishing or reused passwords rather than the router, so these steps complement, not replace, careful account habits; see our guide to spotting phishing messages.
We cannot see your router model, your provider's configuration or the devices on your network. Treat this guide as a starting routine and adapt it to your equipment.
The practical conclusion
An hour spent once, plus a quick firmware check every few months, puts most households well ahead of the default setup. Start with the administrator password and updates; they cost nothing and address the most common weaknesses.