Home  /  Blog  /  Digital discretion
Founder’s analysis · Part 5 of the series

A secure home network starts with the router and good housekeeping

  ·  6 min read  ·  9 min listen
Robert Václavík — Bodyguard Group ®
Listen to the articleaudio version0:00 / 8:38

When I protect a household, I look at more than the locks on the doors. I apply the same logic to the home network: whatever belongs in the main part of the house, I keep apart from the smart devices, and whatever should be locked, I genuinely lock. In network security, the biggest mistake is usually relaxing once the initial set-up is done and no longer treating the network as something that lives and changes.

I treat a home network like a house with a front door and a service entrance

Whenever I look at a home network, I picture it as a house. Computers, phones and work devices belong in the living quarters. Cameras, doorbells, televisions, voice assistants and other smart devices are more like a service entrance, one that should give access only to the places they genuinely need to reach. It is a simple picture, and it helps people who have no wish to get lost in technical detail.

A common mistake is to lump everything together. As soon as a camera or some other cheap component sits on the same network as your online banking, a work laptop and the family’s phones, you have given one weak point access to the whole house. That is why I talk about separation, not a cosmetic change to the Wi-Fi name.

The same principle applies in physical protection. You do not want everyone who comes in through the side door to walk straight into the living room. A network is no different. What matters is not just that a device works, but exactly what it can reach and what it can connect to on its own.

First, lock whatever comes unlocked out of the box

The first and most important step is to change the router’s default admin password and the default Wi-Fi password. The default credentials for millions of identical devices are public knowledge, which makes them exactly the kind of key nobody should leave under the doormat. Leave a router on its factory settings and you make an attacker’s job needlessly easy.

Straight after that, I switch on WPA3 if the device supports it. On newer routers it is the right choice, and if some devices in the household cannot handle WPA3 yet, the WPA2/WPA3 transition mode makes sense. The goal is simple: the strongest encryption available without needlessly disrupting how the household runs.

At the same time, I switch off WPS. It is a classic example of a feature designed to make connecting easier, and in a secure set-up it is best left alone. I also consider it essential to keep the router’s firmware up to date and not to keep a device running once its support has ended. An unpatched router is a permanent hole in the wall.

I keep IoT devices as strictly separate as the service areas of a house

IoT devices belong on a separate network. In practice, a main network, a guest network and a network for smart devices are all you need. If the router supports VLANs, I use them. If not, I at least put the smart devices on a separate guest Wi-Fi network. Wherever devices have no need to talk to each other, I switch on client isolation, accepting that they will then be controlled through the manufacturer’s cloud rather than over the local network. Without that, the separation exists only in the settings menu and does not actually work.

On that network, cameras, doorbells, televisions, voice assistants and smart appliances sit together, but there is no route from them into the main part of the house. If one cheap smart bulb or one poorly secured doorbell is compromised, the problem usually stays in that part of the house, and reaching a work computer or a banking app becomes much harder. That is exactly the difference between a closed door and an open corridor.

Where the router allows it, I also add a firewall rule: the IoT network may not initiate connections into the main network, while the main network may still control the IoT devices. That keeps the convenience of control without turning a smart plug into a passageway through the entire household.

A secure home network starts with the router and good housekeeping
A secure home network rests on layers of protection, not on one magic switch.

UPnP, remote management and cameras: where people most often let their guard down

CISA recommends disabling UPnP, and I agree without reservation. UPnP is convenient, but malware inside the network can abuse it to open ports to the internet and get round the router’s protection. It only makes sense where a specific application needs ports opened automatically, and even then I enable it only temporarily, check exactly what it has opened and switch it off again when I am done.

I also disable remote management of the router from the internet. With it switched off, the router does not expose its login page to the internet at all. When it comes to smart cameras and video recorders, I am doubly careful. Cheap models are often the main attack vector, because attacks frequently target default or weak passwords.

The Mirai botnet built part of its strength on exactly these credentials, and similar variants still rely on them. So after installing cameras, I change the default password, keep an eye on updates and do not expose the cameras directly to the internet without good reason. For remote access I prefer a VPN; if the manufacturer’s cloud app is the only option left, I first check that manufacturer’s security reputation, support and account settings. Never through an open port.

Encrypted DNS follows the same logic. DNS over HTTPS (DoH) or DNS over TLS (DoT) hides the domains you visit from anyone watching the network, and often from your internet service provider too. It does not make your traffic invisible, though: the destination IP addresses, and often the server name via TLS SNI, remain visible.

When a technician visits, I keep control of accounts and access

Serious risk does not only come from the internet. I think of the case of a technician at the security company ADT who added himself as a user to customers’ accounts during installations. By his own guilty plea, he then repeatedly logged into cameras in roughly two hundred homes over several years. It shows that the threat is not always an anonymous outsider; it can also be a contractor with legitimate access.

So whenever I have cameras, an alarm or another external service installed, I insist that the technician is left with no permanent access once the job is finished. After installation, I check the list of users and their permissions. If someone needed access to the system only to fit it, they should not remain in it simply because nobody could be bothered to deal with it.

I apply the same regime within the family. When someone sets up the network, a camera or the alarm, it must be clear who has admin rights, who has ordinary access and what is genuinely needed for day-to-day use. This is not mistrust. It is the same basic discipline I would apply to physical keys.

Conclusion: a secure home network is a routine, not a one-off fix

In short, I protect a home network the same way I protect a house. I lock the default entry points, keep the service area apart from the living quarters, switch off features that are needlessly open and keep an eye on updates. That reduces the chance of one weak part becoming a problem for the whole household.

If you would like your router, smart devices and access rights properly in order, we can go through them in a no-obligation consultation, calmly and to the point. I do not sell fear. I help set up a network that is practical, easy to keep track of and less vulnerable.

“A home network is a boundary. I let through only what I trust, and even inside it I keep every device in its own lane.” — Robert Václavík

Part of the digital discretion series

Step by step, we are looking in depth at everything raised in the opening Digital Exposure test. Published so far:

Did you find the article useful?Share it
Share on Facebook

Would you like to discuss your digital discretion face to face?

For yourself, your family or your company, discreetly and tailored to your situation. The first consultation is confidential and without obligation.