NETWORK AND WIFI SECURITY CyberArtical Editorial Team

There is no network scenario where WEP is the right choice

A Netgear wireless router on a wooden floor with white network cables coiled beside it

Router security dropdowns present WEP, WPA, WPA2 and WPA3 as a list of alternatives, which invites the reasonable-sounding question of which one suits your circumstances. The answer from both the FTC and CISA is that this is not a menu of trade-offs. WEP is in the category of settings that mean your router needs replacing. If an article offers you a framework for deciding between WPA3 and WEP, it has invented a decision that does not exist.

The acceptable list, in full

  • FTC: "update your router settings to either WPA3 Personal or WPA2 Personal. WPA3 is the newer — and best — encryption available."
  • FTC: routers offering only WPA or WEP are "outdated and not secure" and should be replaced.
  • CISA: acceptable options are "WPA3 Personal or WPA2 AES (also referred to as WPA2 Pre-Shared Key [PSK])".
  • CISA: WEP, WPA, or WPA2 TKIP means the router must be replaced or upgraded by the ISP.
  • That is the whole list. There is no scenario, guest network, or legacy-device exception in either agency’s guidance.

The question as it usually gets asked

It arrives in a few forms. Which encryption suits an older network? Is WEP acceptable for a guest network, or for a printer that will not connect to anything newer? Does it matter for a device that only talks to the internet?

All of them share an assumption: that the options sit on a spectrum of strength, and that a weaker one might be proportionate to a lower-value network. That is not how the guidance is written. The FTC and CISA both draw a line rather than a scale, and WEP is on the far side of it along with original WPA and WPA2 with TKIP.

What the agencies actually specify

The FTC’s instruction is to set the router to WPA3 Personal or WPA2 Personal, and it names WPA3 as the newer and best encryption available. Two acceptable answers, in a stated order of preference.

CISA is more exact about the second option. Its acceptable list is WPA3 Personal or WPA2 AES — the same thing as WPA2 Pre-Shared Key, WPA2-PSK. Anything else, including WPA2 running TKIP, falls into a category CISA describes as requiring the router to be replaced or upgraded by the internet provider.

Neither list has a third tier for less important networks. There is no reduced setting for the guest network, the garage, or the device you do not care about.

What to do if WEP is all your router offers

The FTC answers this directly: a router that offers only WPA or WEP is outdated and not secure, and should be replaced. CISA’s version adds a route that saves money — if the router came from your internet provider, the replacement or upgrade is theirs to supply, and it is worth asking before buying anything.

Two practical notes. First, a router that offers WPA3 or WPA2-AES somewhere in its menu but is currently set to WEP does not need replacing; it needs the setting changed. Check before you buy. Second, if a single legacy device is the reason WEP is selected, replace the device rather than the network’s encryption. One printer is not a reason to weaken every connection in the house.

The variant trap: WPA2 is not one setting

This is the part that catches people who have already done the obvious thing. Selecting WPA2 in the dropdown may leave you on TKIP, which CISA places in the same replace-or-upgrade category as WEP.

So the check has two parts: the protocol, and the cipher. WPA2 with AES, or WPA2-PSK, is acceptable. WPA2 with TKIP is not. Some routers offer a mixed WPA/WPA2 mode for compatibility, which keeps the older option available — if the choice exists, take the one that does not.

WPA3 avoids the question altogether, which is part of why the FTC puts it first.

Why WEP is still in the dropdown at all

Backwards compatibility, and firmware that nobody revisits. Router interfaces accumulate options the way old software accumulates menus, and removing one risks breaking somebody’s installation. Its presence is a fact about product management, not a signal that it remains a reasonable choice.

It is a useful reminder that a settings menu is not a recommendation. The same router will let you turn on WPS, which CISA says increases the likelihood of unauthorised access, leave remote management enabled, and keep the default administrator password. All of those are offered too.

The rest of the list, while you are logged in

  1. Set encryption to WPA3 Personal, or WPA2 AES/PSK if WPA3 is unavailable.
  2. Change the default administrative username, password and network name. CISA wants the login password long, random and unique; the FTC says not to use your name, address or the router brand.
  3. Disable WPS and UPnP, and disable remote management.
  4. Enable the router’s firewall and log out of the administrator account when you are finished.
  5. Check for firmware updates and turn on automatic updates if offered. The FTC also suggests registering the router so you receive update notices.

Sources: FTC — How to secure your home Wi-Fi network · CISA Project Upskill, Module 5 · NIST IR 8425A — Requirements for consumer-grade router products

Reviewed 27 August 2026 by the CyberArtical editorial team against primary guidance from the FTC, CISA and NIST. Security guidance changes over time; where our earlier version of this page said something different, we say so in the article rather than editing it out quietly.

More Stories