NETWORK AND WIFI SECURITY CyberArtical Editorial Team

The home Wi-Fi settings worth an hour of your evening

Overhead power and telephone cables strung between utility poles above suburban rooftops

Home network advice is usually delivered as a long list with no indication of what came from where. This is the shorter version: everything the FTC and CISA actually list for securing a home network, in an order you can work through in one sitting, with the three well-known measures that appear in neither agency’s guidance flagged separately so you can decide about them knowingly.

The two official lists

  • FTC: WPA3 or WPA2 Personal encryption; unique admin username, password and network name; firmware updates; remote management off; WPS and UPnP off; router firewall on; log out of the admin account; guest network.
  • CISA: WPA3 Personal or WPA2 AES/PSK; a router password that is "long, random, and unique"; routine firmware updates; guest Wi-Fi for IoT devices; WPS disabled.
  • FTC: don’t use "login names or passwords with your name, address, or router brand."
  • CISA on WPS: it "increases the likelihood that a threat actor could gain unauthorized access to your Wi-Fi network."
  • Neither list includes SSID hiding, MAC address filtering, or periodic Wi-Fi password changes.

If you have not opened the router since it was installed

Anyone who has never opened their router’s settings, or who last did it when it was installed. It assumes no networking knowledge and one hour.

It is written for a single router in a home. If you have mesh nodes or a separate modem, the settings live in whichever device runs the wireless network; the list is otherwise the same.

The list, in the order the agencies give it

  1. Log in properly. The admin address and default credentials are usually on a label on the router. Use a wired connection or your own Wi-Fi, not a guest device.
  2. Change the administrator username and password. CISA wants it long, random and unique. The FTC adds that it should not contain your name, address or the router brand. Store it in your password manager — you will not be typing it often.
  3. Set encryption. WPA3 Personal if offered, otherwise WPA2 AES/PSK. If only WEP, WPA or WPA2 TKIP are available, the router needs replacing — and if it came from your internet provider, that is their job.
  4. Change the network name. Something that does not identify you or the router model.
  5. Update the firmware. Apply what is available now, and turn on automatic updates if the router supports them. CISA notes some do; the FTC suggests registering the router to receive update notices, because routers often do not update themselves.
  6. Disable remote management. The FTC’s reason is that it "allows you to change settings over the internet" — convenient for you and for anyone else who gets the password.
  7. Disable WPS. CISA is unambiguous about the risk.
  8. Disable UPnP. On the FTC’s list, and worth doing even though some devices ask for it.
  9. Enable the router firewall if it is not already on.
  10. Set up the guest network with its own strong password, and move your smart home devices onto it.
  11. Log out of the administrator account when you are finished. The FTC lists this explicitly.

Three measures neither agency lists

These appear in most home network articles. Neither the FTC’s list nor CISA’s includes them, which is worth knowing before you spend time on them.

  • Hiding the network name. It stops the name appearing in the ordinary list of nearby networks and makes joining more awkward for you and your visitors. It does not conceal the network from anyone equipped to look for it.
  • Filtering by device address. It creates a list you must maintain every time anything new arrives, and hardware addresses can be changed by whoever wants to get past it.
  • Changing the Wi-Fi password on a schedule. Neither agency asks for this. Both emphasise setting the defaults once to something long, random and unique, and using a guest network so fewer people hold the primary password at all. Change it when it has actually circulated, not on a timer.

How to check it took

  1. Reconnect a device to the main network and confirm it still works.
  2. From a guest-network device, try to reach the router’s admin page and a printer or shared drive on the main network. Both should fail.
  3. Look at the main network’s connected-device list and confirm the smart devices have moved off it.
  4. Try reaching the admin interface from outside your home network. It should not respond, which confirms remote management is off.
  5. Note the firmware version somewhere, so you can tell later whether updates have been happening.

When to come back to this

Twice a year is generous for most of it. Firmware is the exception: if the router cannot update itself, check quarterly, because CISA’s point is that routine updates protect against known vulnerabilities.

The other triggers are events rather than dates — a new router, a change of internet provider, someone moving out, or a period when a lot of people have had the guest password. All of those are reasons to revisit specific items rather than the whole list.

What the router cannot protect you from

Everything that arrives through a connection you initiated. A perfectly configured network will faithfully carry you to a fraudulent site and deliver a phishing email intact.

It also cannot help with devices taken outside it. Your phone spends most of its day on other networks, which is why device-level controls — automatic updates, a screen lock, strong authentication — do more for you overall than anything in this list.

If you do think the network itself has been interfered with, the FBI’s IC3 handles network intrusion and unauthorised access, CISA takes incident reports, and the FTC takes reports of fraud that followed.

Sources: FTC — How to secure your home Wi-Fi network · CISA Project Upskill, Module 5 · NIST IR 8425A — Requirements for consumer-grade router products · FBI Internet Crime Complaint Center · CISA — Report a cyber incident

Reviewed 27 August 2026 by the CyberArtical editorial team against primary guidance from the FTC, CISA, NIST and the FBI. Security guidance changes over time; where our earlier version of this page said something different, we say so in the article rather than editing it out quietly.

More Stories