A guest network, strong encryption, a separate network for cameras and a new router admin password — simple changes that make your office network much more secure.
Office Wi-Fi is often configured exactly as it was on the day it was bought: a factory password and one network for everyone — employees, guests, cameras and printers. That means anyone who knows the Wi-Fi password may be able to “see” your server, files and cameras.
1. Change the router admin password
The factory password of the router and access point management panel (admin/admin) is the easiest “door” in. Change it to a strong, unique password and, if possible, disable access to the management panel from the internet.
💡 Store the admin password in a password manager (e.g. ICOMP Pass), not on a sticky note behind the router. Send it to your IT company or installer with a one-time link instead of a messenger.
2. Use WPA2 or WPA3 encryption
Your Wi-Fi settings should say WPA2-AES or WPA3. The old WEP and WPA are easy to crack. The network password should be at least 12 characters.
3. A separate network for guests
Give guests, clients and employees’ personal phones a Guest Wi-Fi that is isolated from the internal network: the internet works, but the server, printers and cameras are not visible.
4. Cameras and “smart” devices — in a separate VLAN
IP cameras, TVs and smart bulbs are often poorly protected. Network segmentation (VLAN) means that if one device is compromised, the attacker can’t move across the whole network.
5. Turn off WPS
WPS (connecting with a button or PIN) is convenient but has known vulnerabilities. An office network doesn’t need it.
6. Update the firmware
Router and access point manufacturers regularly fix security flaws. Updating firmware is just as essential as updating your computers.
💡 Bonus: Change the Wi-Fi password when an employee leaves the company — or better yet, use enterprise authentication, where every employee has their own account.