WiFi security checklist for small teams: the office router nobody has logged into since install day
Almost every small office runs on a router that one person set up on day one and nobody has opened since. The admin password is still admin or a sticker value, the firmware is from the year the business opened, the guest network broadcasts the same password as the office network because separating them "seemed complicated", and the WPS button is still enabled because it was never anyone's job to turn it off. None of this is a technical failure. It is an ownership failure — and the fix is one hour, once, followed by a ten-minute quarterly pass. This checklist is that hour.
1. Log in to the router and write down what you find
- Find the admin address and actually log in. Usually
192.168.1.1or192.168.0.1, printed on the router or in the ISP handbook. If the default admin password still works, that is your first finding and you are not done until it is changed. - Screenshot the status page: firmware version, SSIDs in use, connected device count. This becomes your baseline. Every later audit starts with "is the count still explainable?" — the same inventory instinct as the annual security review.
- Write the date and who did it on a sticky note inside the IT drawer. The point is not ceremony; it is that the next person knows there is a baseline and when it was taken.
2. Fix the admin plane first — it outranks the WiFi password
- Change the admin password to a unique value in the password manager. The WiFi password gets shared with every visitor's laptop; the admin password must never leave the manager. Two different credentials, always.
- Turn off remote administration and UPnP unless something genuinely needs them. "Allow admin from the internet" is how routers end up in botnets. If a monitoring tool needs UPnP, log the exception with an owner and a review date — same discipline as the server hardening checklist.
- Disable WPS. The push-button pairing feature has known attacks and exists only to save typing a password once. Nothing in a small office needs it.
- Check for firmware updates and enable auto-update if the router offers it. Router firmware is a vendor product like any other: check the vendor's advisories the same way you review any supplier — the questions are in the vendor security review.
3. Use WPA3 if the devices allow it, WPA2-AES if they do not
- Set the strongest mode your oldest work device supports. WPA3 everywhere is ideal; WPA2-AES is acceptable; WEP or the "mixed" TKIP modes are not. If a five-year-old printer forces you backward, that printer belongs in the guest/IoT network, not the office one.
- Make the WiFi passphrase long, not clever. Six random words beats a memorable symbol-swapped phrase. Length is the only property that scales; the math on that lives with the password manager rollout.
- Never reuse the office WiFi password on any account. People type WiFi passwords into captive portals and hotel-style pages. A shared passphrase is a shared secret the moment it leaves the building.
4. Split the network: staff, guests, everything else
- Put guests on the guest SSID and say so out loud. One SSID for visitors, isolated from the office network, with a password you can hand to a courier without thinking. If your router cannot isolate guests, say "we will connect you to a hotspot instead" — that is a normal sentence.
- Move printers, cameras, thermostats and door locks to the guest or IoT network. Smart devices are computers with terrible patch records; the honest treatment of them is in the IoT device checklist. A compromised camera must not be able to reach the accounting laptop.
- Test the separation once. Join the guest network from a phone and try to reach a shared drive or the printer admin page. Whatever you can reach from guest WiFi is what a visitor can reach. If the answer is "the file server", you have found this month's fix.
5. Plan the shared-password rotation before you need it
- Decide the trigger, not just the interval. Rotate the office WiFi password when someone with the password leaves, when a device is lost, or every six months — whichever comes first. The offboarding moment is the one that bites; pair it with the access request and offboarding checklist.
- Make rotation cheap enough to actually happen. Update the router, print the new passphrase, walk the office in ten minutes. If rotation takes an afternoon, it will never happen, and a password nobody rotates is a password everyone's cousin's babysitter may hold.
- Keep the guest password separate and rotate it freely. Nobody has to coordinate a hotdesking day to change the guest network. Cheap rotation on the throwaway network trains the habit.
6. The devices on the network matter more than the password on it
- Turn off auto-join for open networks on every work laptop. An evil-twin access point named "Airport_Free_WiFi" wins the moment a laptop connects automatically. Manual join plus the always-on VPN habit from the remote work checklist closes the airport and cafe versions of this.
- Count the devices against the router's list quarterly. The router knows how many clients are connected. Fifteen clients for a nine-person office is a conversation, not a crisis — but it is a conversation worth having, because the extra four have owners who forgot them.
- Retire devices, not just people. The printer that left the building in March is still on the WiFi list if nobody removed it. Dead clients on the list are how forgotten devices keep a foothold after hardware goes to e-waste.
7. The quarterly ten-minute walk test
- Walk the carpark and the cafe next door with a phone. If your office SSID is full bars from the street, strangers can attempt your passphrase at leisure. Long passphrases survive attempts; short ones do not. If the signal bleeds badly, reduce transmit power or move the router inward.
- Re-read the router's client list and admin log. New clients, unfamiliar MACs, admin logins at 3am — the router keeps this history whether anyone reads it or not.
- Write three lines: firmware date, client count, changes made. It feeds the annual review and answers the insurance-renewal and customer-questionnaire question "how is office network access controlled?" in one sentence.
WiFi security for a small team is one owned hour: log into the router once, fix the admin password, firmware, WPS and remote admin, split staff from guests and IoT, set the rotation trigger, then run a ten-minute quarterly walk test that reads the client list before the coffee goes cold. When the clients are not in the office at all, the travel security checklist picks up where this one ends. The Ops Starter Kit ($14) turns the device inventory and the review cadence into fill-in-the-blank sheets, and the Automation Starter Pack ($19) schedules the recurring checks so the quarterly pass happens without anyone remembering to remember.