DEVICE SECURITY CyberArtical Editorial Team

Putting your smart devices on their own Wi-Fi

A security app screen offering a quick scan of the most vulnerable areas of a device, with a Scan button

Smart plugs, cameras, doorbells, televisions and thermostats have one thing in common — they are computers you do not administer. You cannot audit their software, you often cannot tell when they were last updated, and several of them will outlive their manufacturer’s interest. CISA’s answer is not to avoid them but to put them somewhere they cannot see the rest of your network. Your router almost certainly already supports this.

What you are setting up

  • CISA: ‘Connect any smart home and other IOT devices to your Guest Wi-Fi if internet access is the only thing they require.’
  • FTC’s two reasons for a guest network: fewer people hold your primary password, and malware on a guest device will not infect the primary network.
  • CISA: acceptable encryption is ‘WPA3 Personal or WPA2 AES’ — WEP, WPA, or WPA2 TKIP means the router must be replaced or upgraded.
  • CISA: ‘Disable Wi-Fi Protected Setup (WPS)’, which ‘increases the likelihood that a threat actor could gain unauthorized access to your Wi-Fi network.’
  • CISA on firmware: ‘Routine updates will protect you against known vulnerabilities. Some routers even allow you to set up automatic updates.’

What the separation prevents

On a single network, every device can discover and reach every other device. Your laptop’s shared folders, your network storage, your printer’s web interface — all visible from a camera you bought for forty pounds and have never updated.

Moving internet-only devices to the guest network removes that visibility. CISA gives device discovery as the explicit reason for the instruction. The smart plug still reaches its manufacturer’s servers, which is all it needs, and it no longer reaches your work laptop.

The FTC’s framing adds the second benefit: your primary Wi-Fi password stays known to fewer people and fewer devices, and malware on anything connected to the guest side does not cross over.

Find your way into the router

Find out how to reach your router’s settings. That is usually a web address printed on the router itself or an app from the provider. You will need the administrator password, which is not the Wi-Fi password.

Check what encryption the router is offering. CISA’s acceptable options are WPA3 Personal or WPA2 AES, also written as WPA2 Pre-Shared Key. If WEP, WPA, or WPA2 with TKIP is all that is on offer, the router needs replacing or upgrading by your provider, and that is the first job rather than this one.

Make a list of which devices only need the internet. Most smart home hardware qualifies. The exceptions are devices that must talk to something else on your network — a printer you print to directly, a media server, network storage.

The steps

  1. Sign in to the router as administrator. If it is still using the default credentials, change them now to something long, random and unique — CISA notes default credentials may be publicly available, and the FTC adds that you should not use your name, address or the router’s brand in the name or password.
  2. Change the network name too, if it still identifies the manufacturer or model.
  3. Enable the guest Wi-Fi feature and give it its own strong password, distinct from the main network’s.
  4. Set the encryption on both networks to WPA3 Personal, or WPA2 AES if WPA3 is unavailable.
  5. Reconnect each internet-only smart device to the guest network. This means re-running each device’s setup, which is the tedious part; do it in one sitting.
  6. Disable Wi-Fi Protected Setup and UPnP, turn off remote management, and confirm the router’s firewall is enabled.
  7. Turn on automatic firmware updates if the router offers them. If not, register the router with the manufacturer and sign up for update notifications, as the FTC advises, because routers often do not update themselves.
  8. Log out of the router’s administrator account when you have finished.

Checking it worked

  • Open your router’s list of connected devices and confirm the smart devices now appear on the guest network rather than the main one.
  • Test that each device still works — the app still shows the camera, the plug still switches.
  • From a laptop on the main network, confirm you can still reach the things that genuinely need to be reachable, such as a printer you deliberately left on the primary side.
  • Confirm the router administration page is not reachable from the guest network, if your router offers that option.
  • Check that remote management is off and stays off after a firmware update, since updates sometimes restore defaults.

Where a guest network stops helping

It does not fix the device itself. A camera with an unpatched flaw is still an unpatched camera, and it still holds an account with your credentials on the manufacturer’s servers. Segmentation limits the blast radius; it does not repair the device.

It does nothing about accounts. The app that controls your smart home is protected by a password and whatever second factor it offers, and that account is reachable from anywhere. Give it a long unique password and the strongest second factor available.

And note what is not on any of these lists. Neither the FTC nor CISA recommends hiding your network name or filtering by MAC address as home Wi-Fi controls. Both are commonly repeated, neither appears in the current guidance, and both cost you time that the items above deserve instead.

Sources: CISA Project Upskill, Module 5 · FTC — how to secure your home Wi-Fi network · CISA — update software

Reviewed 27 August 2026 by the CyberArtical editorial team against primary guidance from CISA and the FTC. Security guidance changes over time; where our earlier version of this page said something different, we say so in the article rather than editing it out quietly.

More Stories