To set up a secure home network, start with a router that still gets security updates. Change its admin password, install the latest firmware with automatic updates on, and encrypt the Wi-Fi with WPA3 or WPA2-AES. Turn off WPS, UPnP and remote management, add a guest network, check the firewall and write every setting down.
This guide is the day-one checklist for a new router, or one you have just reset to factory settings. It follows the NSA's Best Practices for Securing Your Home Network (February 2023), CISA's home Wi-Fi router guide and the UK NCSC's advice, and gives the reason for each step so you can judge the ones that depend on your home. Wi-Fi encryption in depth, hardening a network that is already running and improving coverage are separate jobs, so each gets one line here.
The day-one router security checklist
Work through the list in order. The first six steps deal with what is unsafe out of the box, so finish them before you move your devices onto the new network.
- Choose a router that is still supported. A router past its end of support never gets another security fix.
- Place it out of reach and set it up from inside the home. Anyone who can press the reset button can use the default login on the label.
- Change the admin password, and secure the maker's app account if there is one. Default logins are published online.
- Give the Wi-Fi a new name (SSID). The default name tells an attacker which make and model to look up.
- Install the latest firmware and turn on automatic updates. Routers are attacked through known flaws that already have fixes.
- Set Wi-Fi security to WPA3-Personal, or WPA2/WPA3 for older devices, with a long passphrase. Weak or missing encryption lets anyone in range join or read traffic.
- Turn off WPS. Its PIN can be guessed by someone within Wi-Fi range.
- Turn off UPnP and remote management. One lets any device open holes in the firewall; the other puts the admin page on the internet.
- Create a guest network for visitors and smart devices. A compromised device there cannot reach your computers and phones.
- Confirm the firewall is on, IPv6 included, and choose your DNS resolver. Some firewall features ship switched off, and a filtering resolver blocks known-bad domains.
- Write down what you set. You can then spot a change, restore the settings after a reset and hand them to whoever helps you.
The sections below explain each step, and a table of the usual setting names follows them.
Choose a router that will keep getting security updates
The router is the gateway into your home network. The NSA's guidance is direct about what follows: a router without patches is more likely to be compromised, which can lead to the compromise of the devices behind it, so it should be updated, preferably automatically, and replaced when it reaches end of life (EOL).
The risk is real. In a May 2025 public service announcement, the FBI reported that end-of-life routers, some with remote administration turned on, had been infected with a new variant of TheMoon malware and turned into proxies that criminals use to hide their identity. The FBI notes that routers from 2010 or earlier likely no longer receive updates, and its first recommendation is to replace an end-of-life router.
Before you buy, find the support end date:
- In the UK, the product security regime has applied since 29 April 2024 to consumer products that can connect to the internet or a network. Its exceptions are short (electric vehicle charge points, medical devices, smart meters, and computers and tablets without a cellular connection), and routers are not among them. The regulations require the maker to publish the defined support period, the minimum time it will provide security updates, and a maker that shortens it after publishing no longer meets the requirement. The NCSC suggests treating the support date as a "use by" date for the device.
- In the EU, the Cyber Resilience Act applies from 11 December 2027. It requires a support period of at least five years unless the product is expected to be used for less, says devices such as routers that stay in use longer should get longer support, and requires the end date, at least the month and year, to be clear at the time of purchase.
- Elsewhere, look for the maker's published support or end-of-life policy for the exact model. A model with no published date is a model you cannot plan around.
While you compare models, check for WPA3 and an automatic update option. The NSA recommends that any new device you buy be WPA3-Personal certified.
Your ISP's router or your own?
Both can be secure. The difference is who does the maintenance:
| Question | Router from your ISP | Router you buy |
|---|---|---|
| Who installs updates | Often the provider: the NCSC notes that routers issued by major ISPs may update automatically once a patch is out | You, through automatic updates if the model has them |
| How much you can change | Depends on the provider | Everything the firmware offers |
| When it is too old | Ask the provider for a replacement | You replace it at the support end date |
| Best for | Households that want little maintenance | Households that want control of Wi-Fi, guest networks and DNS |
The NSA suggests connecting a personally owned router to the ISP's modem or router when you want full administrative control. CISA draws one firm line: if the router you have only offers WEP, WPA or WPA2 with TKIP, ask the provider for a newer one or buy your own.
Place the router and make the first connection
Put the router somewhere visitors cannot reach it. CISA's guide points out that anyone with physical access can factory reset it and then log in with the default details printed on it. Placement for the best signal is a coverage question.
The label usually shows the router's admin address, default network name (SSID), Wi-Fi key, MAC address and admin account name. To connect for the first time:
- Connect a computer to one of the router's LAN ports with an Ethernet cable, or join the setup Wi-Fi network named on the label.
- Open the admin address in a browser. It is a local name given in the manual or an IP address, normally from one of the private ranges that RFC 1918 sets aside for local networks, such as 192.168.x.x or 10.x.x.x.
- If the maker's setup uses a phone app and an online account instead, that account now controls your router. Give it a unique password and turn on two-step verification (2SV), as the NCSC advises for any smart device or app that offers it.
- Make every change from inside the home. The NSA's advice is to limit router administration to the internal network only.
Change the admin password and the network name
Every router ships with a login for its settings, and CISA warns that default credentials may be published online or printed on the device itself. That is how the Mirai botnet grew in 2016: it tried a list of 62 common default usernames and passwords and took over mostly home routers, network cameras and video recorders, which then powered DDoS attacks.
UK law now bans universal default and easily guessable passwords on new connectable products, so a router bought recently may carry a unique password on its label. Change it anyway: the label is readable by anyone who can reach the router. For the new admin password:
- Make it long and random. The FBI recommends unique, random passwords of 16 to 64 characters.
- Use it nowhere else, and keep it different from the Wi-Fi password, which you will share with family and guests.
- Keep it in a password manager. The NSA recommends one, so you never have to remember or write down the password itself.
- Change the admin username too, if the router allows it, as CISA suggests.
Then rename the network. The default SSID often names the maker or model, and CISA notes it can point an attacker to known vulnerabilities in that router. Choose a name that does not identify you, your flat number or your address. Do not hide the SSID: the NSA says hiding it adds no security and may cause compatibility problems.
Update the firmware and turn on automatic updates
Firmware is the router's own software, and a flaw in it is a flaw in the one device every other device trusts. The NCSC's April 2026 advisory on APT28 shows the pattern. The Russian group exploited small office and home routers, among them the TP-Link WR841N, most likely through a public flaw, CVE-2023-50224, that lets an unauthenticated attacker obtain the login credentials. It then changed the routers' DNS settings, which the laptops and phones behind them inherited, and sent lookups for email and login pages to its own servers to try to steal passwords and access tokens in an adversary-in-the-middle attack.
To update:
- In the admin page, find the firmware section (often under System, Administration or Advanced) and run the online check, or download the file for your exact model from the maker's support site.
- Install it, and do not switch the router off while it runs; TP-Link's manual, for example, warns against turning the router off during a firmware upgrade.
- Turn on automatic updates if the router has the option. CISA notes that some routers do, and automatic updates are what the NSA recommends.
- If there is no automatic option, check for new firmware on a schedule. The NSA's general advice for devices that cannot update themselves is to install updates monthly.
- If the router offers a reboot schedule, set it to weekly. The NSA recommends weekly reboots of routers because some router malware does not survive a restart.
Install firmware only from the maker's own site or the router's built-in update. On an ISP router, the provider pushes updates, so confirm in the admin page that the firmware date is recent.
Important
A router past its support end date cannot be fixed by this step. If no update has appeared for years and the maker lists the model as end of life, replace it.
Turn on WPA3 or WPA2-AES
Set the Wi-Fi security mode to WPA3-Personal. If some devices cannot join, use the mixed WPA2/WPA3 mode, which the NSA suggests so that newer devices use WPA3 while older ones connect over WPA2, and turn on protected management frames where the option exists. CISA counts only WPA3-Personal and WPA2 with AES, often shown as WPA2-PSK, as safe, and says a router that offers only WEP, WPA or WPA2-TKIP should be upgraded or replaced. Use a long passphrase that you use nowhere else; the NSA suggests at least 20 characters. Open or weakly encrypted Wi-Fi lets anyone in range join your network or read what it carries, which is where many snooping attacks start. The finer Wi-Fi choices are a separate topic from this setup list.
Turn off WPS, UPnP and remote management
These three features trade security for convenience, and some routers ship with them on.
Wi-Fi Protected Setup (WPS)
WPS lets a device join with a button press or an eight-digit PIN instead of the Wi-Fi password. The PIN method has a design flaw that CERT/CC published in December 2011: the router reveals when the first half of the PIN is right, and the last digit is only a checksum, so an attacker needs at most 11,000 guesses instead of 100 million. Many routers did not lock out repeated guesses, so someone within range may be able to recover the Wi-Fi password or change the router's configuration. Turn WPS off entirely, as CISA advises. The menu may call it WPS, Wi-Fi Protected Setup, router PIN or external registrar.
Universal Plug and Play (UPnP)
UPnP lets an app or device on your network ask the router to open ports to the internet by itself. On the TP-Link Archer AX6000, for example, UPnP is enabled by default and serves online gaming, peer-to-peer apps and voice calls. Any device on the network can make that request, and CISA warns that malware inside the network can use UPnP to get around the router's firewall, take remote control of devices and spread. The NSA and CISA both advise turning it off unless you have a specific need. If a smart device needs UPnP only to join the network, CISA suggests switching it on for setup and off again afterwards.

If a games console reports a strict connection type with UPnP off, one port-forwarding rule for that console, taken from the console maker's documentation, opens only the ports it needs.
Remote management
Remote management, also called remote administration or remote access, makes the router's admin page reachable from the internet. Turn it off. The NSA says to disable remote administration and make changes only from inside the network, the NCSC's APT28 advisory says management interfaces should never be exposed to the internet, and the FBI's end-of-life warning names routers with remote administration turned on. With it off, CISA explains, an attacker has to connect to your network first, by Wi-Fi or by cable, before they can change anything.

Set up a guest network for visitors and smart devices
A guest network is a second Wi-Fi network, with its own name and password, whose devices reach the internet but not your computers, phones or storage. The NSA recommends at least three segments: primary Wi-Fi, guest Wi-Fi and a network for Internet of Things (IoT) devices, so less secure devices cannot talk directly to your trusted ones. If your router offers only one guest network, it can serve both visitors and smart devices:
- Give it a long, random password of its own, not a variation of the main one.
- Use it for anyone who does not connect routinely, and for smart devices that only need the internet. CISA notes this stops those devices discovering your other devices or reaching the router's settings.
- Check the isolation options. On TP-Link routers, for example, the guest network settings include two checkboxes, Allow guests to see each other and Allow guests to access my local network; leave the second one unticked.
Some devices must reach others to work, such as a speaker that casts to a TV or a shared printer. Those have to share a network, or need a router that can control traffic between segments, which belongs to hardening a network rather than day one. For choosing and setting up smart devices themselves, see how smart home devices work and how to secure them.
Check the firewall and choose your DNS resolver
The router's firewall
Most wireless routers include a built-in firewall, but CISA notes that some firewall features, even the firewall itself, may be turned off by default. Open the security or firewall page and confirm it is on. On TP-Link's Archer AX6000 it is the SPI (stateful packet inspection) firewall, enabled by default. The NSA adds two checks: the router should use network address translation (NAT), which keeps internal devices from being scanned from outside, and if your ISP supports IPv6, the router's IPv6 firewall must be on as well.
While you are there, look for forwarding rules you did not create. TP-Link's manual lists four kinds (virtual servers, port triggering, UPnP and DMZ); on a new setup, leave them empty unless you know which device needs a rule and why.
DNS: your ISP's resolver or a filtering one
Your router tells every device which DNS resolver to use, the service that turns names like example.com into addresses. By default that is your ISP's. You can point the router at a resolver that refuses to look up known malicious domains instead:
| Service | DNS servers to enter in the router | What it blocks |
|---|---|---|
| Quad9 | 9.9.9.9 and 149.112.112.112 | Malware domains, with DNSSEC validation |
| Cloudflare 1.1.1.1 for Families | 1.1.1.2 and 1.0.0.2 | Malware and phishing |
| Cloudflare 1.1.1.1 for Families | 1.1.1.3 and 1.0.0.3 | Malware, phishing and adult content |
| CIRA Canadian Shield | From CIRA's home router setup guide | Malicious websites |
When a domain is classed as malicious, Cloudflare answers with the address 0.0.0.0, so the device cannot connect.

Filtering works on names only, so it is one layer, not a substitute for updates. A browser or device set to use its own encrypted DNS ignores the router's choice, and a site blocked by mistake can be reported to the provider. Whichever resolver you choose, note the addresses down: on the routers APT28 compromised, this is exactly the setting that was changed without the owners knowing.
Router settings to look for, and their usual names
Menus differ by maker and firmware version, but the settings are much the same everywhere. Search the admin page for these names:
| Setting | Set it to | Often labelled |
|---|---|---|
| Admin password | Long, random, unique; kept in a password manager | Administration, Admin password, Router login |
| Firmware | Latest version, automatic updates on | Firmware upgrade, Online upgrade, Automatic updates |
| Network name | A new name with no personal details, not hidden | SSID, Network name, Wi-Fi name |
| Wi-Fi security | WPA3-Personal, or WPA2/WPA3 for older devices | Security mode, WPA3-Personal, WPA2-PSK (AES), WPA2/WPA3 |
| Protected management frames | On, where offered | PMF, Protected management frames |
| WPS | Off | WPS, Wi-Fi Protected Setup, Router PIN, External registrar |
| UPnP | Off, unless a device needs it | UPnP, Universal Plug and Play (often under NAT forwarding) |
| Remote management | Off | Remote management, Remote administration, Remote access |
| Guest network | On, with no access to the local network | Guest network, Guest Wi-Fi, Allow guests to access my local network |
| Firewall | On, for IPv4 and IPv6 | Firewall, SPI firewall, IPv6 firewall |
| Forwarding rules | Empty unless you need one | Port forwarding, Virtual servers, Port triggering, DMZ |
| DNS servers | Your ISP's, or a filtering resolver | DNS server, Primary DNS, Secondary DNS |
| Reboot schedule | Weekly | Reboot schedule, Scheduled reboot |
Write the settings down
Record what you set on the day you set it, and keep the record in your password manager or with your household papers:
- The router model, its firmware version and the date you updated it.
- The support end date from the maker.
- The admin username. The password itself stays in the password manager.
- The names of the main and guest networks, and the Wi-Fi security mode.
- The features you turned off: WPS, UPnP and remote management.
- The DNS servers and any forwarding rules.
CIRA gives the same advice for DNS: write down the existing addresses before you change them, so you can restore them. Many routers can also export a configuration backup; TP-Link documents it under Backup & Restore. Store that file where you keep the admin password, not in a shared folder.
With the record you can spot a setting that changed without you, as the DNS settings did on the routers APT28 compromised, rebuild the setup after a factory reset, and give anyone who helps you facts rather than guesses.
What to do after day one
Setup is the start. Keep automatic updates on, look at the admin page every few months to confirm the firmware date is recent and your settings are unchanged, and replace the router at its support end date. Checking which devices are connected and separating smart devices further belong to hardening an existing network; placement, channels and mesh systems belong to improving Wi-Fi coverage.
If the network is a small office rather than a home, or your team works from home on company laptops, our IT support service covers device management, patching and the security basics for teams, and security scanning checks from the outside which services and open ports a business exposes to the internet.


