ClearSecurity VISION
EN / RO
← All articles

Hardening · 10 July 2026 · 4 min read

Router, Wi-Fi and remote access: the essential settings, step by step

The out-of-the-box router is a front door left unlocked. Admin password, firmware updates, a separate guest Wi-Fi, and remote access through VPN — not open ports.

ClearSecurity Vision

The company network almost always starts with a router installed in a hurry on moving day and untouched ever since. The admin password is the factory one, the firmware is three years old, and for “access from home” someone once opened a port to an office computer. Each of these is a door attackers try automatically, at industrial scale — you don’t need to be an interesting target to get found.

This guide covers the basic settings that close those doors — no new equipment, in a few hours.

What you need

  • Physical access to the router/firewall and the admin interface credentials (if they’re lost, a factory reset is a clean start)
  • The list of people who need remote access, and to what
  • 2–3 hours, ideally outside working hours — there will be short interruptions

Step 1: the admin interface

  1. Sign in to the router’s interface and change the admin password — long, unique, stored in a password manager. If the default user is “admin”, change that too where possible.
  2. Turn off administration from the internet (remote management / WAN access): the admin interface should be reachable only from the internal network. This is one of the most exploited settings in the world.
  3. Check for firmware updates and install them. Set a quarterly reminder — routers don’t update themselves, and their vulnerabilities are published regularly.

Step 2: the Wi-Fi

  1. Use WPA2 or WPA3 with a long passphrase — not the company name plus the year.
  2. Create a separate guest network, isolated from the internal one: visitors get internet, not access to the accounting server.
  3. Put on the guest network everything that doesn’t need internal access: TVs, cameras, sensors, the “smart” coffee machine — these devices rarely get updates and are easy targets.
  4. Disable WPS (the quick-connect button) — it’s a known weakness.

Step 3: remote access

The simple rule: no port opened straight to an office computer. Remote Desktop exposed to the internet is the classic way ransomware enters small companies.

  1. For working from home, use a VPN — most business routers have a built-in VPN server (WireGuard or OpenVPN on newer gear; L2TP/IPsec at minimum). Each user gets their own credentials.
  2. If the router doesn’t offer VPN, a “mesh VPN” product installed on the computers is a modern, simple alternative — with no open ports at all.
  3. Review the existing port forwarding list and delete everything nobody can explain anymore. If something genuinely must stay, record it in the inventory: which port, to what, who asked for it.
  4. Vendors’ remote access (the accountant, the ERP support team) follows the same rules: over VPN or their secured product — not through a port opened “temporarily” in 2022.

Verify the result

  1. From a connection outside the company (your phone on mobile data), try opening the admin interface on the company’s public address — it must not answer.
  2. Run an online port scanner (search “online port scan”) against your public address: the list of open ports should be short, and every entry explainable.
  3. Connected to the guest Wi-Fi, try reaching a computer on the internal network — it must not work.

Common mistakes

  • “We’ll change the router password next year, no time now.” It takes five minutes and it’s the most-knocked door.
  • “Temporary” port forwarding that became permanent. What gets opened for one troubleshooting session stays open for years. Cleaning schedule: at every quarterly firmware check, review the port list too.
  • One Wi-Fi for everyone and everything. The accountant’s laptop and the courier’s phone don’t belong on the same network.
  • A VPN with one shared password for the whole company. When an employee leaves it must be changed for everyone — so it never is. Individual, revocable credentials.

The natural next step once the network is in order is workstation protection — see BitLocker and automatic updates on Windows.


Under NIS2? Network security and access control are core areas of the law’s minimum measures.

newsletter

Get new articles by email.

NIS2 compliance, incident reporting and plain-language security — only when we publish something new. No spam, unsubscribe anytime.