Secure the whole product, not just the Wi-Fi password
A home network includes the router, modem or fiber gateway, vendor cloud account, management app, phones, computers, televisions, cameras, speakers, appliances, game systems, printers, and sometimes medical or work devices. A strong Wi-Fi password is useful, but it cannot compensate for an unsupported router, exposed remote-management page, compromised vendor account, or device that never receives security updates.
AI can help criminals write convincing messages and adapt known attack techniques, but households should not respond by buying an “AI security” subscription first. CISA’s current consumer priorities remain phishing recognition, strong unique passwords, MFA, and prompt software updates. Apply those controls systematically, beginning with the router and accounts that manage other devices.
This is general U.S. household guidance, not a guarantee against intrusion or individualized cybersecurity advice. Do not change a router used for medical monitoring, alarm service, accessibility, remote work, or building management without understanding the service requirements. If you face stalking, domestic abuse, or a targeted compromise, use a safe device and seek qualified help before making changes that could alert the attacker.
Inventory what is connected
Open the router’s device list or management app from a trusted device. Create a simple inventory: device name, owner, purpose, connection type, vendor account, automatic-update status, and expected support end date. Unknown entries are not automatically intruders—devices often use obscure names or randomized addresses—but investigate them. Turn off a suspect device or disconnect it temporarily and see what disappears.
Remove equipment no longer used. A connected product with an abandoned app or expired support still expands the network. Before buying a new device, ask whether it supports automatic updates, unique credentials, MFA for its cloud account, vulnerability reporting, and a stated support period. NIST’s consumer IoT baseline focuses on the product’s full ecosystem, including apps and back-end services, not only the physical device.
Configure the router deliberately
Use the vendor or internet provider’s documented method to reach the router; do not follow a login link in an unsolicited message. Then:
- Install current firmware and enable automatic security updates if supported.
- Replace the default administrator credential with a unique password stored in a password manager.
- Protect the vendor cloud account with MFA or a passkey where available.
- Disable internet-facing remote administration unless there is a specific, secured need.
- Use WPA3-Personal when all essential devices support it; otherwise use WPA2-AES. Avoid obsolete WEP and WPA modes.
- Disable Wi-Fi Protected Setup PIN features if not needed.
- Rename the network so it does not reveal a surname, apartment, address, or router model.
- Save a secure backup of settings if the product supports it, and know how to reset and recover the router.
NIST’s consumer-grade router profile treats secure configuration, updates, access control, data protection, interface security, and product documentation as connected requirements. If a router no longer receives fixes, replacement may be more useful than adding another security appliance.
Write down who owns the internet-provider account and how to contact the provider without using the home internet. Provider-supplied gateways may restrict settings or update automatically; confirm rather than assuming. Changing DNS, firewall, or bridge settings without understanding them can disrupt service and is not required for a reasonable household baseline.
Segment devices when the router supports it
Place visitor devices on a guest network. If the router offers an isolated IoT network, use it for lower-trust smart devices such as televisions, speakers, plugs, appliances, and cameras, while keeping computers and phones that access sensitive records on the primary network. Confirm that “guest” or “IoT” isolation actually prevents those devices from reaching the primary network; product implementations vary.
Segmentation is not a cure. Many smart products communicate through the vendor’s cloud, and a compromised cloud account can affect a device regardless of local network placement. Some devices need local communication with a phone, hub, printer, or accessibility controller, so test household functions after moving them.
Do not place employer-managed equipment on an improvised configuration that violates work policy. Follow the employer’s VPN, update, and incident-reporting rules. If the router supports a separate work network and the employer permits it, that can reduce interaction with personal and IoT devices.
Keep every endpoint supportable
Enable automatic operating-system, browser, application, and security updates. Restart devices as required to complete them. Remove unused browser extensions and apps; each can hold permissions or credentials. Use standard user accounts for everyday computer use when practical rather than an administrator account.
Phones and tablets should have a nontrivial unlock code, encryption, automatic updates, and a configured locate/lock function. Back up irreplaceable data and test that recovery works. A backup continuously attached to one computer can be affected by malware or accidental deletion, so keep an additional version isolated or use a service with version history.
Printers, network storage, cameras, and home automation hubs deserve the same attention as laptops. Change default credentials, update them, disable services you do not use, and avoid exposing their interfaces directly to the internet. If a product requires port forwarding to function, understand exactly which service becomes reachable and seek vendor or professional guidance.
Secure smart cameras, speakers, and medical devices
Treat indoor cameras and microphones as sensitive. Limit where they are placed, who can view them, how clips are retained, and whether third-party integrations are necessary. Use separate household logins instead of one shared administrator when the service offers roles. Remove former residents, guests, installers, and obsolete devices promptly.
For connected health or medical devices, availability can matter as much as confidentiality. Follow the clinician’s, manufacturer’s, and provider’s instructions. Do not block cloud access, factory-reset a monitor, or move it between networks during care without confirming the consequences. NIST’s work on telehealth and smart-home integration emphasizes that consumer smart-home components add privacy and cybersecurity dependencies to home-based care.
Make phishing resistance part of network security
An attacker does not need to exploit the router if a household member installs remote-access software, approves a malicious login, or discloses a code. Ignore the old “bad grammar” test. Verify the sender and the requested action.
Do not click a router, antivirus, streaming, or utility “renewal” link from an unexpected message. Open the known app or type the service address. Never provide a one-time login code to a caller. Do not install a screen-sharing tool because a pop-up claims the computer is infected. If a support call is necessary, initiate it through a verified number.
Use a password manager and unique credentials for the router, internet provider, email, device vendors, and streaming accounts. Prefer passkeys or hardware security keys where available. See Digital Identity Hardening for recovery and backup-authenticator details.
Monitor without becoming your own security operations center
Turn on notifications for new administrator logins, password changes, new devices, and disabled security features. Review the router’s connected-device list and vendor-account sessions a few times a year. Excessive logs and alerts that nobody reads are not protection; choose signals tied to an action.
Warning signs include settings changing without explanation, repeated MFA prompts, a new administrator, cameras moving or activating unexpectedly, unrecognized port forwards, unexplained data use, or devices redirecting to unusual pages. Slow internet alone is not proof of compromise.
If compromise is plausible, disconnect the affected device from the network without destroying evidence. Use another trusted device to secure primary email, password-manager, router, and vendor accounts; revoke sessions; contact the ISP or manufacturer; and document what occurred. A factory reset may remove useful evidence and does not fix a stolen cloud credential, so do not make it the automatic first response. For material loss or crime, report through IC3.gov and appropriate local channels.
A practical maintenance cycle
This week: update router firmware, change its administrator credential, secure the provider and vendor accounts, enable automatic endpoint updates, and create a guest network.
This month: inventory devices, remove unused products and accounts, separate compatible IoT devices, review cameras and microphones, and test backups.
Twice a year: verify firmware support, account members, recovery methods, connected devices, port forwards, and backup restoration. Replace unsupported equipment on a planned schedule.
The goal is not a perfect fortress. It is a network whose devices are known, supported, updated, minimally exposed, and recoverable—plus a household that will not grant access simply because a polished message or realistic voice asks for it.