Save $25 First-time repair — call today
75 North Bridge St, Somerville NJ 08876 - (Behind Bank of America) Hours M-F 10am-5pm Sa 9-2 (908) 428-9558

How to Secure Home WiFi: The Six Settings That Matter and the Two Tips You Can Skip

Your home WiFi is the front door to every device you own: laptops, phones, cameras, the thermostat, and increasingly your work. Securing it is not a weekend project. It is six settings in your router, most of which take under a minute each, and together they close off essentially every attack a home network realistically faces. Here they are in priority order.

The six settings, in order of importance

1. Use WPA3 encryption, or WPA2 at minimum. In your router's wireless security settings, choose WPA3 if offered, or WPA2 (AES) if not. The mixed WPA2/WPA3 transition mode is fine and keeps older devices working. What you are eliminating: WEP and the original WPA, both of which can be cracked in minutes with free tools, and open networks with no password at all. If your router only offers WEP or WPA, it is old enough that replacing it is the security fix.

2. Set a strong, unique WiFi password. Twelve characters minimum, and not your address, phone number, or anything printed on the router. A short passphrase of a few random words beats a complicated eight-character string, and it is easier to type into a TV remote. Change it from whatever the installer or the label set, since default password patterns for major ISP routers are documented all over the internet.

3. Change the router's admin password. This is the one people miss. The WiFi password and the router's administration password are different things, and the admin login is what controls every setting on this list. Default admin credentials (admin/admin, admin/password) are the first thing any intruder tries. Set it to something unique when you are in the settings making the other changes.

4. Turn off WPS. The push-button pairing feature has a PIN mode with a design flaw that lets an attacker brute-force it in hours regardless of how strong your actual password is. Nearly every router has a setting to disable WPS entirely, and nothing you use day-to-day depends on it.

5. Keep the router's firmware updated. Router vulnerabilities get discovered and patched regularly, and unpatched home routers are actively scanned for and conscripted into botnets. Newer routers update themselves; check that auto-update is on. Older ones need a manual check in the admin panel once or twice a year. If your router has not received a firmware update from its manufacturer in years, it is unsupported, and replacement is the honest recommendation.

6. Put smart-home gadgets and visitors on the guest network. Almost every modern router can broadcast a separate guest network. Use it for two things: visitors, and the cheap smart devices, plugs, bulbs, cameras, that receive the fewest security updates of anything in your house. If one of them is ever compromised, the guest network keeps it walled off from the laptops and phones where your real data lives.

What you can skip

Two pieces of advice that circulate endlessly and do little: hiding your network name (your devices then broadcast it everywhere they go, and any scanner sees the network anyway) and MAC address filtering (trivially bypassed, and a maintenance headache every time you get a new device). The six settings above do the real work; these two mostly generate false confidence.

Signs someone is already on your network

Most routers or their apps show a list of connected devices. Unrecognized devices, internet that slows at odd hours, or router settings that changed without you are all worth taking seriously. The response is the list above, executed in order: new WiFi password, new admin password, WPS off, firmware current, and every unknown device drops off the moment the password changes. If a computer on the network was acting strange before you locked things down, popups, redirected searches, or new toolbars, that machine deserves its own checkup, since a compromised device inside the network is a different problem from an intruder on the WiFi. That is bench work, and our $75 diagnostic (credited toward the repair) sorts out whether a machine is infected or just misbehaving.

For business owners, the stakes and the checklist are both bigger: separate staff and customer networks, business-grade access points, and card-reader isolation are on-site work we do for business clients through our IT consulting services across Somerset, Middlesex, Hunterdon, and Mercer counties.

A device acting compromised, or a business network to lock down?

Call 908-428-9558 or stop by 75 N Bridge St, Somerville. Infected machines cleaned at the bench, on-site network security for business clients. Serving Somerset, Middlesex, Hunterdon, and Mercer counties since 2011.

Frequently asked questions

What is the most important setting for securing home WiFi?
Encryption type. WPA3, or WPA2 with AES at minimum, with a strong unique password. Everything else on the checklist matters, but a network running WEP or no encryption is open regardless of what else you do.

Should I hide my WiFi network name?
It adds little. Scanning tools see hidden networks anyway, and your own devices end up broadcasting the name wherever they go looking for it. Strong encryption and a strong password do the real work.

How do I know if someone is using my WiFi?
Check the connected devices list in your router's app or admin page and look for anything you cannot account for. Changing the WiFi password immediately disconnects every device, which is the fastest way to reset the roster to only what is yours.

Is my old router a security risk?
If it no longer receives firmware updates, or only supports WEP or WPA encryption, yes. Router vulnerabilities are actively exploited, and an unsupported router cannot be patched. Replacement is the fix, and modern routers also handle updates automatically.

📞 Call Dave's — (908) 681-8254