Hardening · 10 July 2026 · 4 min read
Router, Wi-Fi and remote access: the essential settings, step by step
The out-of-the-box router is a front door left unlocked. Admin password, firmware updates, a separate guest Wi-Fi, and remote access through VPN — not open ports.
ClearSecurity Vision
The company network almost always starts with a router installed in a hurry on moving day and untouched ever since. The admin password is the factory one, the firmware is three years old, and for “access from home” someone once opened a port to an office computer. Each of these is a door attackers try automatically, at industrial scale — you don’t need to be an interesting target to get found.
This guide covers the basic settings that close those doors — no new equipment, in a few hours.
What you need
- Physical access to the router/firewall and the admin interface credentials (if they’re lost, a factory reset is a clean start)
- The list of people who need remote access, and to what
- 2–3 hours, ideally outside working hours — there will be short interruptions
Step 1: the admin interface
- Sign in to the router’s interface and change the admin password — long, unique, stored in a password manager. If the default user is “admin”, change that too where possible.
- Turn off administration from the internet (remote management / WAN access): the admin interface should be reachable only from the internal network. This is one of the most exploited settings in the world.
- Check for firmware updates and install them. Set a quarterly reminder — routers don’t update themselves, and their vulnerabilities are published regularly.
Step 2: the Wi-Fi
- Use WPA2 or WPA3 with a long passphrase — not the company name plus the year.
- Create a separate guest network, isolated from the internal one: visitors get internet, not access to the accounting server.
- Put on the guest network everything that doesn’t need internal access: TVs, cameras, sensors, the “smart” coffee machine — these devices rarely get updates and are easy targets.
- Disable WPS (the quick-connect button) — it’s a known weakness.
Step 3: remote access
The simple rule: no port opened straight to an office computer. Remote Desktop exposed to the internet is the classic way ransomware enters small companies.
- For working from home, use a VPN — most business routers have a built-in VPN server (WireGuard or OpenVPN on newer gear; L2TP/IPsec at minimum). Each user gets their own credentials.
- If the router doesn’t offer VPN, a “mesh VPN” product installed on the computers is a modern, simple alternative — with no open ports at all.
- Review the existing port forwarding list and delete everything nobody can explain anymore. If something genuinely must stay, record it in the inventory: which port, to what, who asked for it.
- Vendors’ remote access (the accountant, the ERP support team) follows the same rules: over VPN or their secured product — not through a port opened “temporarily” in 2022.
Verify the result
- From a connection outside the company (your phone on mobile data), try opening the admin interface on the company’s public address — it must not answer.
- Run an online port scanner (search “online port scan”) against your public address: the list of open ports should be short, and every entry explainable.
- Connected to the guest Wi-Fi, try reaching a computer on the internal network — it must not work.
Common mistakes
- “We’ll change the router password next year, no time now.” It takes five minutes and it’s the most-knocked door.
- “Temporary” port forwarding that became permanent. What gets opened for one troubleshooting session stays open for years. Cleaning schedule: at every quarterly firmware check, review the port list too.
- One Wi-Fi for everyone and everything. The accountant’s laptop and the courier’s phone don’t belong on the same network.
- A VPN with one shared password for the whole company. When an employee leaves it must be changed for everyone — so it never is. Individual, revocable credentials.
The natural next step once the network is in order is workstation protection — see BitLocker and automatic updates on Windows.
Under NIS2? Network security and access control are core areas of the law’s minimum measures.
One step done. See the full picture.
Answer a few questions across the 8 essential areas — from passwords and backups to suppliers — and get a report by email with your weak spots and next steps.
Start the self-assessment →
newsletter
Get new articles by email.
NIS2 compliance, incident reporting and plain-language security — only when we publish something new. No spam, unsubscribe anytime.