Saliem Talash: Secure your home Wi-Fi router in one evening, the Cyber Centre's checklist in plain language

Most people set up their home router once, on the day the internet was installed, and never open its settings again. That box now carries the work laptop, the phones, the smart TV, the printer, the doorbell camera and, for a lot of people who run a small business from home, the invoices and the customer list.

The Canadian Centre for Cyber Security (the Cyber Centre) publishes a short guidance sheet, Routers cyber security best practices (ITSAP.80.019), that covers what to change. It is written for offices and homes. This post walks through it in plain language, setting by setting. I'm Saliem Talash, I build practical tools for small businesses in Toronto, and this is the evening job I suggest to anyone who works from home.

Why the router matters

The Cyber Centre explains that threat actors use tools that automatically scan for vulnerable hardware like routers, and that routers are vulnerable when they are "poorly or improperly configured." If one is compromised, the guidance lists what can happen, including:

  • stealing personal information from any device connected to the network;
  • capturing login details by redirecting you to fake websites;
  • monitoring or modifying traffic to and from your network;
  • turning the router into part of a botnet, a network of infected devices used to attack others.

None of that requires the attacker to touch your laptop. That is why the router is worth an evening.

Before you start

You need two things: the router's admin address and its admin password. Both are usually printed on a sticker on the router, or in the provider's app. Log in from a computer connected to your own network. Every router's menus are different, so the setting names below are the ones the Cyber Centre uses; your router may use slightly different words.

The basics, in order

The Cyber Centre says to start with the basics and add the extra measures over time. Here are the basics.

1. Change every default password. This means two passwords: the one for joining the Wi-Fi, and the one for logging in to the router's settings. The guidance recommends a passphrase where possible, or "a strong, unique, and complex password," to resist brute-force attacks that simply try passwords until one works.

2. Turn on WPA2 or WPA3. Wi-Fi Protected Access encrypts traffic between your devices and the router. The Cyber Centre names WPA2 or "the newer WPA3" as the options that provide strong encryption. If your router offers WPA3, use it, as long as your devices can still connect.

3. Change the network name. The default name often includes the router's brand or model. The guidance says changing it prevents attackers from easily identifying the make and model and checking whether that device has a known weakness. Pick something that says nothing about you, your address or your business.

4. Hide the network name, if you can live with it. The guidance also suggests disabling SSID broadcast so the network name is not easily visible to anyone scanning nearby. You will then have to type the name by hand when connecting a new device.

5. Turn off WPS. Wi-Fi Protected Setup is the button or PIN that lets a device join without the password. The Cyber Centre calls it convenient, but warns that someone within range can brute-force the PIN.

6. Update the firmware, and switch on automatic updates. Firmware is the router's own software. Updates fix known security holes. The guidance says to keep it current and to turn on automatic updates if your model has the feature.

7. Set up a guest network. Give visitors, and your smart devices, their own network. The Cyber Centre says this avoids sharing your main password and reduces the risk to your primary devices and information. For a home business, this is the single most useful separation: the work laptop on the main network, the smart speaker and the guests on the other.

8. Control physical access. The guidance says to make sure physical access to the router and Wi-Fi access points is restricted. A router in a shared hallway or a shop's front counter can be reset by anyone who reaches it.

The extra measures

Once the basics are done, the Cyber Centre lists further steps. Some are simple; others are for people comfortable in the settings.

  • Reboot on a schedule. Routine reboots clear the system memory and refresh connections, and the guidance notes that a reboot "may disrupt any potential malware."
  • Turn off remote management if possible, so nobody can reach the router's settings from the internet.
  • Turn off SNMP, a network management feature that can reveal basic information about your setup.
  • Give each administrator their own login, if more than one person manages the router.
  • Use MAC filtering to choose which trusted devices can connect.
  • Enable port filtering. The guidance cites the SANS Institute's list of outbound ports to block, such as UDP 69 (TFTP), UDP 161–162 (SNMP) and TCP 6660–6669 (IRC).
  • Turn on event logging and check it regularly.
  • Find out whether your router is end-of-life. The Cyber Centre suggests confirming with your provider whether the router still receives firmware updates or has known vulnerabilities. An unsupported router does not get fixes.

One more: UPnP

A separate Cyber Centre sheet (ITSAP.00.008) covers Universal Plug and Play, the feature that lets game consoles, smart TVs and other devices open connections automatically. Its advice is direct: "We therefore recommend disabling UPnP, especially on perimeter devices such as home routers." The reason is that UPnP can change settings such as port forwarding, which attackers can use to get around the firewall.

The guidance also warns that some devices need it, so check what your devices require before switching it off. If you keep it on, regularly review the router's security settings and port-forwarding rules. The usual place to find it is in an "advanced" or "NAT forwarding" section of the router's settings.

A one-evening plan

If you only have an hour, do these, in this order:

  1. Change the router's admin password.
  2. Change the Wi-Fi password and the network name.
  3. Check that WPA2 or WPA3 is on.
  4. Turn off WPS.
  5. Update the firmware and switch on automatic updates.
  6. Create a guest network and move smart devices and visitors onto it.
  7. Turn off UPnP, unless a device you rely on needs it.

Write the new passwords in your password manager, not on the router's sticker.

Then put a reminder in your calendar for three months from now to check for firmware updates and look at the list of connected devices. If something on that list is a mystery, find out what it is.

I keep simple routines like this on my own site, and longer explainers on ZELR. This is general guidance; your router's manual and your internet provider can tell you exactly where each setting lives on your model.

Sources

  • Canadian Centre for Cyber Security: Routers cyber security best practices (ITSAP.80.019)
  • Canadian Centre for Cyber Security: Universal plug and play (ITSAP.00.008)

Drafted with AI assistance.

More from Saliem Talash: saliemtalash.vercel.app · ZELR · YouTube

Comments

Popular posts from this blog

Saliem Talash: A worked website handoff for a fictional flower shop

Saliem Talash: Why I made a website project workbook that works offline

Saliem Talash: How to use Toronto 311 and actually get the pothole fixed