Your router is the one device every other device in your home depends on, and it is usually the least looked-after computer you own. Most are set up once, on the day they arrive, and never opened again. Meanwhile attackers scan the internet around the clock for routers with default passwords, old firmware and forgotten settings — not because they are after you personally, but because a hijacked home router is useful to them: to spy on traffic, to hide their own activity behind your address, or to attack others.
This checklist is ordered by impact. The first four steps close the gaps attackers actually use; the rest tighten things further. Set aside an hour, and do them in order.
Key Takeaway:
Most home-network break-ins use doors that were left open by default: a factory password, unpatched firmware, WPS, remote administration or UPnP. Closing those five takes under an hour and matters far more than any product you could buy.
Before You Start: Get Into Your Router
Every step below happens in your router’s admin page. To open it, type your router’s address into a browser. It is printed on the router’s label, and it is also the “Default Gateway” in your device’s network settings — usually something like 192.168.1.1 or 192.168.0.1. Public vs private IP addresses explains where that number comes from.
If your internet provider supplied the router, some settings may be locked or managed remotely by them. That is normal; change what you can, and check your provider’s help pages for the rest. Many providers also offer an app that exposes the same settings.
The Checklist at a Glance
| Step | Protects against | Priority |
|---|---|---|
| 1. Change the admin password | Anyone logging into your router with the factory login | Essential |
| 2. Update the firmware | Known, published security holes | Essential |
| 3. Use WPA3 or WPA2-AES with a long password | Neighbours and passers-by joining or reading your Wi-Fi | Essential |
| 4. Turn off WPS | A shortcut that lets attackers guess their way onto Wi-Fi | Essential |
| 5. Turn off remote management | Attacks on the router from the internet | High |
| 6. Turn off UPnP | Devices or malware opening holes in your firewall | High |
| 7. Check your open ports | Services exposed to the internet by mistake | High |
| 8. Put smart devices on a guest network | A weak gadget becoming a way into your laptop | Medium |
| 9. Choose your DNS | Your provider logging lookups; known-malicious domains | Medium |
| 10. Review connected devices | Unknown devices on your network | Ongoing |
1. Change the Router’s Admin Password
Your router has two passwords, and people often confuse them. The Wi-Fi password lets devices join your network. The admin password lets someone change the router’s settings — including turning off your security, or pointing all your traffic somewhere else.
Older routers shipped with the same admin login on every unit (“admin” / “admin” and similar), and those lists are public. Newer ones usually print a unique password on the label; in the UK, universal default passwords on connected devices have been banned since April 2024. Either way, change it to something long and unique, and store it in a password manager. The password tools can generate one.
2. Update the Firmware — and Know When to Replace the Router
Firmware is the software that runs your router. When researchers find a security hole, the manufacturer publishes a fix as a firmware update — and at the same moment, the hole becomes public knowledge. Routers that never update stay vulnerable to attacks anyone can look up.
- Look for “Firmware”, “Software update” or “Administration” in the admin page and install anything available.
- Switch on automatic updates if your router offers them.
- Check whether your model is still supported. Manufacturers stop releasing updates for older routers, and an end-of-life router will never be fixed again. Security agencies have repeatedly warned that unsupported routers are being hijacked in large numbers. If yours no longer receives updates, replacing it is the single biggest improvement you can make.
3. Use Strong Wi-Fi Encryption and a Long Password
In the wireless settings, choose the strongest option your devices support:
- WPA3 — the current standard. Use it if everything in your home supports it.
- WPA2/WPA3 mixed (transitional) — a good choice when some older devices only speak WPA2.
- WPA2-AES (sometimes “WPA2-PSK [AES]”) — still sound with a strong password.
- WPA or WEP, or anything mentioning TKIP — outdated and breakable. Never use them.
With WPA2, the strength of your Wi-Fi password matters a great deal: an attacker who captures your network’s handshake can try guesses offline, as fast as their hardware allows. A passphrase of four or five random words is long enough and easy to type on a TV remote.
4. Turn Off WPS
WPS (Wi-Fi Protected Setup) is the button-or-PIN shortcut for connecting devices without typing the password. The PIN version has a design flaw, published in 2011, that lets an attacker guess the PIN in a matter of hours and recover your Wi-Fi password — however strong it is. Some routers can’t fully disable the PIN mode even when you turn WPS “off” in one menu, so check every WPS setting you can find. You lose nothing important: typing the password once per device is all WPS saves you.
5. Turn Off Remote Management
Remote management (“Remote Access”, “Web Access from WAN”) lets the admin page be reached from the internet, not just from inside your home. Unless you truly need to change router settings while away, switch it off. It turns your router’s login page into something anyone on the internet can try. Some provider-supplied routers keep a separate management channel for the provider itself; that one is theirs to secure.
6. Turn Off UPnP (Mostly)
UPnP lets devices on your network ask the router to open ports to the internet automatically, with no password and no notice to you. It exists for convenience — games consoles, video calls and some smart devices use it — but it also means any compromised device, or malware on a laptop, can quietly open a door from the internet into your home.
Turn it off and see what breaks. If a games console then complains about its “NAT type” and you play online a lot, you can open just the ports it needs yourself with port forwarding — a deliberate, visible rule instead of an automatic one.
7. Check Which Ports Are Open
After steps 5 and 6, check the result from the outside. The port scanner tests your own public IP address for common open ports. On a typical home connection you want to see nothing open at all.
If something is open, find out why before closing it. Ones to worry about most: 23 (Telnet, an old unencrypted login that should never face the internet), 3389 (Windows Remote Desktop, heavily attacked), 22 (SSH — only if you set it up deliberately, with key-based login), and 445 (Windows file sharing). How to check open ports covers the method from inside your network too.
8. Put Smart Devices and Guests on a Separate Network
Smart plugs, cameras, TVs and speakers are often the weakest devices you own: cheap to make, rarely updated, and sometimes abandoned by their manufacturers. On the same network as your laptop, a compromised gadget can see and reach everything else.
Most routers can run a guest network: a second Wi-Fi name with its own password, kept apart from your main devices. Put visitors and smart devices there, and keep your computers, phones and storage on the main network. Check the guest settings for an option like “allow guests to see each other / access local network” and make sure it is off. Are smart home devices spying on you? covers what these devices collect.
9. Choose Your DNS
Your router tells every device which DNS server to use for looking up websites — by default, your provider’s. Setting a different one on the router changes it for the whole household at once. Quad9 (9.9.9.9) blocks domains known to host malware and phishing, which adds a cheap layer of protection for every device, including ones you can’t install anything on.
Be aware that most routers still send those lookups unencrypted, so your provider can read them in transit. Encrypted DNS is usually a browser or device setting instead. DNS over HTTPS explains the difference, and how to check your DNS settings confirms which server is really in use.
10. Review Connected Devices Now and Then
The router’s device list (“Attached devices”, “DHCP clients”) shows everything connected. Every few months, look through it. Unknown names are usually something harmless — a smart plug, a printer, a relative’s phone — so identify them before panicking. If you truly can’t account for a device, change the Wi-Fi password: everything, including the stranger, will be disconnected, and only devices you reconnect will return.
What About the Router’s Firewall and a VPN?
The firewall is normally already on. Your router’s address sharing (NAT) also blocks unsolicited connections from the internet as a side effect — what a NAT firewall is explains how, and why IPv6 needs the real firewall switched on to get the same protection. Check it hasn’t been turned off, and leave it on.
A VPN doesn’t secure your network against attackers; it hides your browsing from your provider and changes the address websites see. It can run on each device, or on the router to cover everything at once. How to set up a VPN on your router covers the trade-offs, and if you want one, PureVPN is the provider this site works with.
✅ Quick Checklist
- Admin password changed from the default and saved in a password manager
- Firmware up to date, automatic updates on, and the model still supported
- WPA3, or WPA2-AES, with a long Wi-Fi passphrase
- WPS switched off
- Remote management switched off
- UPnP switched off, with port forwarding only where you chose it
- Port scan from outside shows nothing open that you didn’t intend
- Smart devices and visitors on the guest network
- Device list checked, and nothing unexplained
If you’d rather work through all of this as a single guided session, with timings for each task, it is the subject of the ExamineIP book Secure Your Home Network in One Evening, listed on the books page.
Frequently Asked Questions
Should I hide my Wi-Fi network name?
It doesn’t add real security. Hidden networks are still easy to detect with common tools, and your devices end up broadcasting the hidden name as they search for it everywhere you go. A strong password and WPA2/WPA3 are what protect you.
Is MAC address filtering worth using?
Not as a security measure. Device hardware addresses are sent unencrypted and are easy to copy, and modern phones use random ones by default, which makes the filter a nuisance to maintain.
Is my provider’s router good enough?
Often, yes — especially recent ones that update automatically. The main reason to buy your own is control: more settings, a proper guest network, and knowing when updates arrive. Router vs modem explains how the two boxes fit together if you want to add your own router.
How often should I check these settings?
After setting them once, a quick look every few months is enough: confirm firmware is current, glance at the device list, and re-run the port scan. Check again after your provider replaces or resets the router, since a reset brings the factory settings back.
Do I still need antivirus if my network is secure?
A secure router protects the doorway, not what you let in yourself. Malicious downloads, phishing links and infected USB sticks bypass the router completely, so keep your devices updated and their built-in protection switched on.