To set up a secure home network, start with a router that still gets security updates. Change its admin password, install the latest firmware with automatic updates on, and encrypt the Wi-Fi with WPA3 or WPA2-AES. Turn off WPS, UPnP and remote management, add a guest network, check the firewall and write every setting down.

This guide is the day-one checklist for a new router, or one you have just reset to factory settings. It follows the NSA's Best Practices for Securing Your Home Network (February 2023), CISA's home Wi-Fi router guide and the UK NCSC's advice, and gives the reason for each step so you can judge the ones that depend on your home. Wi-Fi encryption in depth, hardening a network that is already running and improving coverage are separate jobs, so each gets one line here.

The day-one router security checklist

Work through the list in order. The first six steps deal with what is unsafe out of the box, so finish them before you move your devices onto the new network.

  1. Choose a router that is still supported. A router past its end of support never gets another security fix.
  2. Place it out of reach and set it up from inside the home. Anyone who can press the reset button can use the default login on the label.
  3. Change the admin password, and secure the maker's app account if there is one. Default logins are published online.
  4. Give the Wi-Fi a new name (SSID). The default name tells an attacker which make and model to look up.
  5. Install the latest firmware and turn on automatic updates. Routers are attacked through known flaws that already have fixes.
  6. Set Wi-Fi security to WPA3-Personal, or WPA2/WPA3 for older devices, with a long passphrase. Weak or missing encryption lets anyone in range join or read traffic.
  7. Turn off WPS. Its PIN can be guessed by someone within Wi-Fi range.
  8. Turn off UPnP and remote management. One lets any device open holes in the firewall; the other puts the admin page on the internet.
  9. Create a guest network for visitors and smart devices. A compromised device there cannot reach your computers and phones.
  10. Confirm the firewall is on, IPv6 included, and choose your DNS resolver. Some firewall features ship switched off, and a filtering resolver blocks known-bad domains.
  11. Write down what you set. You can then spot a change, restore the settings after a reset and hand them to whoever helps you.

The sections below explain each step, and a table of the usual setting names follows them.

Choose a router that will keep getting security updates

The router is the gateway into your home network. The NSA's guidance is direct about what follows: a router without patches is more likely to be compromised, which can lead to the compromise of the devices behind it, so it should be updated, preferably automatically, and replaced when it reaches end of life (EOL).

The risk is real. In a May 2025 public service announcement, the FBI reported that end-of-life routers, some with remote administration turned on, had been infected with a new variant of TheMoon malware and turned into proxies that criminals use to hide their identity. The FBI notes that routers from 2010 or earlier likely no longer receive updates, and its first recommendation is to replace an end-of-life router.

Before you buy, find the support end date:

  • In the UK, the product security regime has applied since 29 April 2024 to consumer products that can connect to the internet or a network. Its exceptions are short (electric vehicle charge points, medical devices, smart meters, and computers and tablets without a cellular connection), and routers are not among them. The regulations require the maker to publish the defined support period, the minimum time it will provide security updates, and a maker that shortens it after publishing no longer meets the requirement. The NCSC suggests treating the support date as a "use by" date for the device.
  • In the EU, the Cyber Resilience Act applies from 11 December 2027. It requires a support period of at least five years unless the product is expected to be used for less, says devices such as routers that stay in use longer should get longer support, and requires the end date, at least the month and year, to be clear at the time of purchase.
  • Elsewhere, look for the maker's published support or end-of-life policy for the exact model. A model with no published date is a model you cannot plan around.

While you compare models, check for WPA3 and an automatic update option. The NSA recommends that any new device you buy be WPA3-Personal certified.

Your ISP's router or your own?

Both can be secure. The difference is who does the maintenance:

QuestionRouter from your ISPRouter you buy
Who installs updatesOften the provider: the NCSC notes that routers issued by major ISPs may update automatically once a patch is outYou, through automatic updates if the model has them
How much you can changeDepends on the providerEverything the firmware offers
When it is too oldAsk the provider for a replacementYou replace it at the support end date
Best forHouseholds that want little maintenanceHouseholds that want control of Wi-Fi, guest networks and DNS

The NSA suggests connecting a personally owned router to the ISP's modem or router when you want full administrative control. CISA draws one firm line: if the router you have only offers WEP, WPA or WPA2 with TKIP, ask the provider for a newer one or buy your own.

Place the router and make the first connection

Put the router somewhere visitors cannot reach it. CISA's guide points out that anyone with physical access can factory reset it and then log in with the default details printed on it. Placement for the best signal is a coverage question.

The label usually shows the router's admin address, default network name (SSID), Wi-Fi key, MAC address and admin account name. To connect for the first time:

  1. Connect a computer to one of the router's LAN ports with an Ethernet cable, or join the setup Wi-Fi network named on the label.
  2. Open the admin address in a browser. It is a local name given in the manual or an IP address, normally from one of the private ranges that RFC 1918 sets aside for local networks, such as 192.168.x.x or 10.x.x.x.
  3. If the maker's setup uses a phone app and an online account instead, that account now controls your router. Give it a unique password and turn on two-step verification (2SV), as the NCSC advises for any smart device or app that offers it.
  4. Make every change from inside the home. The NSA's advice is to limit router administration to the internal network only.

Change the admin password and the network name

Every router ships with a login for its settings, and CISA warns that default credentials may be published online or printed on the device itself. That is how the Mirai botnet grew in 2016: it tried a list of 62 common default usernames and passwords and took over mostly home routers, network cameras and video recorders, which then powered DDoS attacks.

UK law now bans universal default and easily guessable passwords on new connectable products, so a router bought recently may carry a unique password on its label. Change it anyway: the label is readable by anyone who can reach the router. For the new admin password:

  • Make it long and random. The FBI recommends unique, random passwords of 16 to 64 characters.
  • Use it nowhere else, and keep it different from the Wi-Fi password, which you will share with family and guests.
  • Keep it in a password manager. The NSA recommends one, so you never have to remember or write down the password itself.
  • Change the admin username too, if the router allows it, as CISA suggests.

Then rename the network. The default SSID often names the maker or model, and CISA notes it can point an attacker to known vulnerabilities in that router. Choose a name that does not identify you, your flat number or your address. Do not hide the SSID: the NSA says hiding it adds no security and may cause compatibility problems.

Update the firmware and turn on automatic updates

Firmware is the router's own software, and a flaw in it is a flaw in the one device every other device trusts. The NCSC's April 2026 advisory on APT28 shows the pattern. The Russian group exploited small office and home routers, among them the TP-Link WR841N, most likely through a public flaw, CVE-2023-50224, that lets an unauthenticated attacker obtain the login credentials. It then changed the routers' DNS settings, which the laptops and phones behind them inherited, and sent lookups for email and login pages to its own servers to try to steal passwords and access tokens in an adversary-in-the-middle attack.

To update:

  1. In the admin page, find the firmware section (often under System, Administration or Advanced) and run the online check, or download the file for your exact model from the maker's support site.
  2. Install it, and do not switch the router off while it runs; TP-Link's manual, for example, warns against turning the router off during a firmware upgrade.
  3. Turn on automatic updates if the router has the option. CISA notes that some routers do, and automatic updates are what the NSA recommends.
  4. If there is no automatic option, check for new firmware on a schedule. The NSA's general advice for devices that cannot update themselves is to install updates monthly.
  5. If the router offers a reboot schedule, set it to weekly. The NSA recommends weekly reboots of routers because some router malware does not survive a restart.

Install firmware only from the maker's own site or the router's built-in update. On an ISP router, the provider pushes updates, so confirm in the admin page that the firmware date is recent.

Important

A router past its support end date cannot be fixed by this step. If no update has appeared for years and the maker lists the model as end of life, replace it.

Turn on WPA3 or WPA2-AES

Set the Wi-Fi security mode to WPA3-Personal. If some devices cannot join, use the mixed WPA2/WPA3 mode, which the NSA suggests so that newer devices use WPA3 while older ones connect over WPA2, and turn on protected management frames where the option exists. CISA counts only WPA3-Personal and WPA2 with AES, often shown as WPA2-PSK, as safe, and says a router that offers only WEP, WPA or WPA2-TKIP should be upgraded or replaced. Use a long passphrase that you use nowhere else; the NSA suggests at least 20 characters. Open or weakly encrypted Wi-Fi lets anyone in range join your network or read what it carries, which is where many snooping attacks start. The finer Wi-Fi choices are a separate topic from this setup list.

Turn off WPS, UPnP and remote management

These three features trade security for convenience, and some routers ship with them on.

Wi-Fi Protected Setup (WPS)

WPS lets a device join with a button press or an eight-digit PIN instead of the Wi-Fi password. The PIN method has a design flaw that CERT/CC published in December 2011: the router reveals when the first half of the PIN is right, and the last digit is only a checksum, so an attacker needs at most 11,000 guesses instead of 100 million. Many routers did not lock out repeated guesses, so someone within range may be able to recover the Wi-Fi password or change the router's configuration. Turn WPS off entirely, as CISA advises. The menu may call it WPS, Wi-Fi Protected Setup, router PIN or external registrar.

Universal Plug and Play (UPnP)

UPnP lets an app or device on your network ask the router to open ports to the internet by itself. On the TP-Link Archer AX6000, for example, UPnP is enabled by default and serves online gaming, peer-to-peer apps and voice calls. Any device on the network can make that request, and CISA warns that malware inside the network can use UPnP to get around the router's firewall, take remote control of devices and spread. The NSA and CISA both advise turning it off unless you have a specific need. If a smart device needs UPnP only to join the network, CISA suggests switching it on for setup and off again afterwards.

A smart camera inside a home asks the router to open a port, and a dashed arrow from the internet passes through an orange opening in the router's firewall wall straight to the camera.
Fig. 1 UPnP lets any device inside open a door in the firewall, and malware on that device can use the same door.

If a games console reports a strict connection type with UPnP off, one port-forwarding rule for that console, taken from the console maker's documentation, opens only the ports it needs.

Remote management

Remote management, also called remote administration or remote access, makes the router's admin page reachable from the internet. Turn it off. The NSA says to disable remote administration and make changes only from inside the network, the NCSC's APT28 advisory says management interfaces should never be exposed to the internet, and the FBI's end-of-life warning names routers with remote administration turned on. With it off, CISA explains, an attacker has to connect to your network first, by Wi-Fi or by cable, before they can change anything.

A laptop inside the home reaches the router's settings gear over a cable, while a dashed arrow from a laptop out on the internet stops at an orange padlock on the router's internet side.
Fig. 2 With remote management off, the settings page answers only devices that are already inside your network.

Set up a guest network for visitors and smart devices

A guest network is a second Wi-Fi network, with its own name and password, whose devices reach the internet but not your computers, phones or storage. The NSA recommends at least three segments: primary Wi-Fi, guest Wi-Fi and a network for Internet of Things (IoT) devices, so less secure devices cannot talk directly to your trusted ones. If your router offers only one guest network, it can serve both visitors and smart devices:

  • Give it a long, random password of its own, not a variation of the main one.
  • Use it for anyone who does not connect routinely, and for smart devices that only need the internet. CISA notes this stops those devices discovering your other devices or reaching the router's settings.
  • Check the isolation options. On TP-Link routers, for example, the guest network settings include two checkboxes, Allow guests to see each other and Allow guests to access my local network; leave the second one unticked.

Some devices must reach others to work, such as a speaker that casts to a TV or a shared printer. Those have to share a network, or need a router that can control traffic between segments, which belongs to hardening a network rather than day one. For choosing and setting up smart devices themselves, see how smart home devices work and how to secure them.

Check the firewall and choose your DNS resolver

The router's firewall

Most wireless routers include a built-in firewall, but CISA notes that some firewall features, even the firewall itself, may be turned off by default. Open the security or firewall page and confirm it is on. On TP-Link's Archer AX6000 it is the SPI (stateful packet inspection) firewall, enabled by default. The NSA adds two checks: the router should use network address translation (NAT), which keeps internal devices from being scanned from outside, and if your ISP supports IPv6, the router's IPv6 firewall must be on as well.

While you are there, look for forwarding rules you did not create. TP-Link's manual lists four kinds (virtual servers, port triggering, UPnP and DMZ); on a new setup, leave them empty unless you know which device needs a rule and why.

DNS: your ISP's resolver or a filtering one

Your router tells every device which DNS resolver to use, the service that turns names like example.com into addresses. By default that is your ISP's. You can point the router at a resolver that refuses to look up known malicious domains instead:

ServiceDNS servers to enter in the routerWhat it blocks
Quad99.9.9.9 and 149.112.112.112Malware domains, with DNSSEC validation
Cloudflare 1.1.1.1 for Families1.1.1.2 and 1.0.0.2Malware and phishing
Cloudflare 1.1.1.1 for Families1.1.1.3 and 1.0.0.3Malware, phishing and adult content
CIRA Canadian ShieldFrom CIRA's home router setup guideMalicious websites

When a domain is classed as malicious, Cloudflare answers with the address 0.0.0.0, so the device cannot connect.

A laptop and a phone send lookups through the router to a resolver with an orange shield, which lets one through to a normal web page and stops the other before a page marked with a bug.
Fig. 3 A filtering resolver turns away lookups for known-bad domains for every device that uses the router's DNS settings.

Filtering works on names only, so it is one layer, not a substitute for updates. A browser or device set to use its own encrypted DNS ignores the router's choice, and a site blocked by mistake can be reported to the provider. Whichever resolver you choose, note the addresses down: on the routers APT28 compromised, this is exactly the setting that was changed without the owners knowing.

Router settings to look for, and their usual names

Menus differ by maker and firmware version, but the settings are much the same everywhere. Search the admin page for these names:

SettingSet it toOften labelled
Admin passwordLong, random, unique; kept in a password managerAdministration, Admin password, Router login
FirmwareLatest version, automatic updates onFirmware upgrade, Online upgrade, Automatic updates
Network nameA new name with no personal details, not hiddenSSID, Network name, Wi-Fi name
Wi-Fi securityWPA3-Personal, or WPA2/WPA3 for older devicesSecurity mode, WPA3-Personal, WPA2-PSK (AES), WPA2/WPA3
Protected management framesOn, where offeredPMF, Protected management frames
WPSOffWPS, Wi-Fi Protected Setup, Router PIN, External registrar
UPnPOff, unless a device needs itUPnP, Universal Plug and Play (often under NAT forwarding)
Remote managementOffRemote management, Remote administration, Remote access
Guest networkOn, with no access to the local networkGuest network, Guest Wi-Fi, Allow guests to access my local network
FirewallOn, for IPv4 and IPv6Firewall, SPI firewall, IPv6 firewall
Forwarding rulesEmpty unless you need onePort forwarding, Virtual servers, Port triggering, DMZ
DNS serversYour ISP's, or a filtering resolverDNS server, Primary DNS, Secondary DNS
Reboot scheduleWeeklyReboot schedule, Scheduled reboot

Write the settings down

Record what you set on the day you set it, and keep the record in your password manager or with your household papers:

  • The router model, its firmware version and the date you updated it.
  • The support end date from the maker.
  • The admin username. The password itself stays in the password manager.
  • The names of the main and guest networks, and the Wi-Fi security mode.
  • The features you turned off: WPS, UPnP and remote management.
  • The DNS servers and any forwarding rules.

CIRA gives the same advice for DNS: write down the existing addresses before you change them, so you can restore them. Many routers can also export a configuration backup; TP-Link documents it under Backup & Restore. Store that file where you keep the admin password, not in a shared folder.

With the record you can spot a setting that changed without you, as the DNS settings did on the routers APT28 compromised, rebuild the setup after a factory reset, and give anyone who helps you facts rather than guesses.

What to do after day one

Setup is the start. Keep automatic updates on, look at the admin page every few months to confirm the firmware date is recent and your settings are unchanged, and replace the router at its support end date. Checking which devices are connected and separating smart devices further belong to hardening an existing network; placement, channels and mesh systems belong to improving Wi-Fi coverage.

If the network is a small office rather than a home, or your team works from home on company laptops, our IT support service covers device management, patching and the security basics for teams, and security scanning checks from the outside which services and open ports a business exposes to the internet.