Home Network Security Settings for 2026: Nine Router Changes Worth Twenty Minutes
Key takeaways
- WPA3 removes the offline dictionary attack against your wifi handshake, so switch if the router supports it
- The router admin password is a different thing from the wifi password, and it is the one nobody changes
- Putting IoT devices on their own SSID or VLAN stops a compromised smart plug from reaching your laptop
Nothing on this list stops a determined attacker. Almost all of it stops one bad device from reaching everything else, which is the security work most home networks have never had done. It costs nothing and takes about twenty minutes.
Here are the home network security settings worth doing, in the order worth doing them.
Start with encryption and passwords
1. Switch to WPA3
WPA2 is not broken, but WPA3 removes the offline dictionary attack against your handshake. If someone captures a WPA2 handshake they can grind at it on their own hardware for as long as they like. WPA3 takes that option away. Most routers sold since 2019 support it, often behind a WPA2/WPA3 mixed mode.
2. Change the router admin password
This is a different password from the wifi one, and it is the one people forget exists. It is what protects the settings page itself, including DNS. Sixteen characters or more, and not the one printed on the sticker.
3. Change the wifi password
If it is still the factory default, change it. Twenty characters or more. You type it roughly twice a year, so length costs you very little.
Close the doors you are not using
4. Update the firmware, then turn automatic updates on
Router firmware is patched for real vulnerabilities and then sits unapplied for years. If yours is two versions behind, update now. The Oracle patch cycle from August is a useful reminder of how much shipped code is quietly holding known holes.
5. Turn WPS off entirely
The PIN method is brute-forceable in four to ten hours. The convenience it buys you is one button press when adding a printer.
6. Turn off remote management
Unless you genuinely administer the router from outside the house, this is an internet-facing login on consumer-grade code. Off is the correct setting.
Separate the devices you do not trust
7. Put IoT devices on their own network
A separate SSID or VLAN with client isolation switched on means a compromised smart plug or camera cannot see your laptop, your NAS, or your phone. This is the single highest-value item on the list, and the one that takes the longest.
8. Use the guest network for guests
Same logic, lower stakes. Anything that does not need to reach your other devices belongs on it.
9. Rename the SSID
Not your name, not your flat number, not the router model. The model number tells anyone in range which vulnerabilities to look up.
What this actually buys you
The whole argument is blast radius. Isolation between devices is the same principle that makes a hypervisor escape worth taking seriously when it happens: the boundary is doing more work than any individual patch. On a home network the boundary is free, and most people have never turned it on.
If your router cannot do any of this
Kit older than about 2019 often has no WPA3 and no usable guest isolation, and firmware support has usually ended. A current WiFi 7 router such as the TP-Link Archer BE550 covers WPA3, guest networking and automatic firmware updates without any configuration expertise.
Set a calendar reminder for six months from now to check the firmware version. That is the only part of this list that needs doing twice.
Some links in this article are affiliate links. We may earn a small commission at no extra cost to you.