How to secure a small-business Wi-Fi network
The router admin password, which is usually still the default
The Wi-Fi password and the router admin password are different things, and the second is the one people forget exists. It is often still "admin", printed on a sticker, and identical across every unit of that model. Anyone who reaches that page can redirect all your traffic.
- 1Sign in to the router’s admin page. The address is usually on a label underneath it.
- 2Change the admin password to something long and unique, and store it where the business can find it, not on one person’s phone.
- 3Disable remote administration from the internet unless you specifically need it.
- 4Turn off WPS, the push-button pairing feature. It is a known weak point and almost nobody uses it.
A separate guest network, the highest-value change
If visitors, contractors or personal phones join the same network as your work computers, every one of those devices sits alongside your business machines. An infected visitor laptop does not need to get past a firewall, because it is already inside.
Nearly every business router supports a guest network. It is free, it takes ten minutes, and it is the change we would make first if we could only make one.
- 1Enable the guest network and give it its own password.
- 2Make sure "allow guests to access local network" is switched off. Without that, the separation is cosmetic.
- 3Move phones, tablets, smart TVs and anything you do not manage onto it.
- 4Put the guest password on a card in reception, and change it periodically.
Encryption and the passphrase
- 1Use WPA3 if your router and devices support it, WPA2 otherwise.
- 2If you see WEP, or WPA/WPA2 mixed with TKIP, change it. WEP in particular is broken.
- 3Use a long passphrase. Length beats complexity: four unrelated words are stronger and easier to type than a short string of symbols.
- 4Change the passphrase when someone with access leaves.
The advice that does not help
Two suggestions come up constantly and are worth skipping so the effort goes somewhere useful.
Hiding the network name does not hide the network. It is trivially visible to anyone looking, and it makes connecting harder for your own staff. MAC address filtering sounds like an allowlist, but MAC addresses are easily copied, so it stops nobody who is actually trying while creating work every time you add a device.
When to stop and call someone
- You cannot get into the router admin page at all
- You have several access points and changes on one break another
- You need staff, guests and payment devices genuinely separated
- The router is old enough that no firmware updates are available
- You suspect someone unauthorised is already on the network
Want this handled for you?
A technician can look at it directly. First session is $49, up to 45 minutes, and we confirm the scope and price before any work starts.