WiFi security checklist for small teams: the office router nobody has logged into since install day

Almost every small office runs on a router that one person set up on day one and nobody has opened since. The admin password is still admin or a sticker value, the firmware is from the year the business opened, the guest network broadcasts the same password as the office network because separating them "seemed complicated", and the WPS button is still enabled because it was never anyone's job to turn it off. None of this is a technical failure. It is an ownership failure — and the fix is one hour, once, followed by a ten-minute quarterly pass. This checklist is that hour.

1. Log in to the router and write down what you find

2. Fix the admin plane first — it outranks the WiFi password

3. Use WPA3 if the devices allow it, WPA2-AES if they do not

4. Split the network: staff, guests, everything else

5. Plan the shared-password rotation before you need it

6. The devices on the network matter more than the password on it

7. The quarterly ten-minute walk test

WiFi security for a small team is one owned hour: log into the router once, fix the admin password, firmware, WPS and remote admin, split staff from guests and IoT, set the rotation trigger, then run a ten-minute quarterly walk test that reads the client list before the coffee goes cold. When the clients are not in the office at all, the travel security checklist picks up where this one ends. The Ops Starter Kit ($14) turns the device inventory and the review cadence into fill-in-the-blank sheets, and the Automation Starter Pack ($19) schedules the recurring checks so the quarterly pass happens without anyone remembering to remember.