Skip to content

How to secure a small-business Wi-Fi network

Short answer. Change the router’s admin password, put visitors on a separate guest network, use WPA3 or WPA2 with a long passphrase, keep the router’s firmware updated, and turn off WPS. That is most of the real protection available to a small office. Hiding your network name and filtering MAC addresses are widely recommended and do almost nothing.

The router admin password, which is usually still the default

The Wi-Fi password and the router admin password are different things, and the second is the one people forget exists. It is often still "admin", printed on a sticker, and identical across every unit of that model. Anyone who reaches that page can redirect all your traffic.

  1. 1Sign in to the router’s admin page. The address is usually on a label underneath it.
  2. 2Change the admin password to something long and unique, and store it where the business can find it, not on one person’s phone.
  3. 3Disable remote administration from the internet unless you specifically need it.
  4. 4Turn off WPS, the push-button pairing feature. It is a known weak point and almost nobody uses it.

A separate guest network, the highest-value change

If visitors, contractors or personal phones join the same network as your work computers, every one of those devices sits alongside your business machines. An infected visitor laptop does not need to get past a firewall, because it is already inside.

Nearly every business router supports a guest network. It is free, it takes ten minutes, and it is the change we would make first if we could only make one.

  1. 1Enable the guest network and give it its own password.
  2. 2Make sure "allow guests to access local network" is switched off. Without that, the separation is cosmetic.
  3. 3Move phones, tablets, smart TVs and anything you do not manage onto it.
  4. 4Put the guest password on a card in reception, and change it periodically.

Encryption and the passphrase

  1. 1Use WPA3 if your router and devices support it, WPA2 otherwise.
  2. 2If you see WEP, or WPA/WPA2 mixed with TKIP, change it. WEP in particular is broken.
  3. 3Use a long passphrase. Length beats complexity: four unrelated words are stronger and easier to type than a short string of symbols.
  4. 4Change the passphrase when someone with access leaves.

The advice that does not help

Two suggestions come up constantly and are worth skipping so the effort goes somewhere useful.

Hiding the network name does not hide the network. It is trivially visible to anyone looking, and it makes connecting harder for your own staff. MAC address filtering sounds like an allowlist, but MAC addresses are easily copied, so it stops nobody who is actually trying while creating work every time you add a device.

Firmware updates are the unglamorous one that genuinely matters. Router makers patch real vulnerabilities, and most small-office routers have never been updated once. Check whether yours can update automatically, and switch it on.

When to stop and call someone

  • You cannot get into the router admin page at all
  • You have several access points and changes on one break another
  • You need staff, guests and payment devices genuinely separated
  • The router is old enough that no firmware updates are available
  • You suspect someone unauthorised is already on the network

Want this handled for you?

A technician can look at it directly. First session is $49, up to 45 minutes, and we confirm the scope and price before any work starts.