Picture your office as a building with one front door and no interior walls. The receptionist, the accountant, the card reader, the security cameras and the break-room thermostat all sit in one open room. Anyone who gets through the front door can walk over to any of them.
That's what most small business Wi-Fi looks like. The guest's laptop, the payment terminal, the cameras, the owner's PC and the smart TV all share one network and one password, and they can all see each other. It feels tidy. It also means the cheapest, least-updated gadget you own is a back door to everything else.
Quick answer: what to do this week
- Change the router's admin password from the factory default to something long and unique.
- Turn on the guest network and give visitors that password, never the main one.
- Turn off WPS in the router settings.
- Use WPA3 (or WPA2 if that's all the router offers) and a long passphrase.
- Move cameras, smart TVs and other gadgets to their own network once your router supports it.
The rest of this post explains why each one matters and how to build proper separation without breaking printing.
How to tell if your network is flat
Open the Wi-Fi list on your phone at the office. If there's one network name (or one name for staff and the same password shared with guests), you're almost certainly flat. Two more signs:
- A visitor on your Wi-Fi can see your office printer when they go to print.
- Your phone's casting button shows the conference-room TV and the camera app finds the cameras without any special setup, using the same network your accounting PC is on.
Convenient, yes. It also means anything compromised on that network can see the same devices.
Why one weak device matters: lateral movement
Attackers rarely break in through the thing they want. They break in through the weakest thing on the network, then move sideways to the valuable thing. Security people call this lateral movement.
On a flat network it's easy. Compromise a $40 camera with an old firmware bug, and because it shares a network with your payment terminal and your accounting PC, the attacker can now reach both. The camera was never the target. It was the unlocked window.
These gadgets are called IoT (internet of things) devices: cameras, smart plugs, thermostats, printers, TVs, doorbells. They're cheap, they rarely get updates, and attackers know it. Zscaler's 2024 mobile, IoT and OT threat report, covering June 2023 to May 2024, found its cloud blocked 45% more IoT malware than the year before.
The cost when it goes wrong isn't small-business-sized either. IBM's Cost of a Data Breach Report puts the 2026 global average at $4.99 million. Your incident may be a fraction of that, but Verizon's breach research has repeatedly found that small and medium businesses get hit hard because they have weaker defenses and slower patching. You don't have to be a big target, just an easy one.
The fix: interior doors
Network segmentation means splitting one network into several smaller ones that can't freely talk to each other. The camera lives in one room, the payment terminal in another, and someone who takes over the camera is stuck in the camera room.
CISA calls segmentation one of the most effective defenses because it limits how far an attacker can move after one device falls. NIST wrote a whole white paper on segmentation for small manufacturers for the same reason.
Four terms your router's settings will use:
- SSID: the name of a Wi-Fi network, the one you pick from the list. One router can broadcast several.
- Guest network: a separate SSID that gives visitors internet only, walled off from your devices. Most routers have it; most businesses never turn it on.
- VLAN (virtual LAN): a way to split one physical network into several separate ones in software, so staff traffic and camera traffic can share cables and switches but never see each other.
- Firewall: the guard between networks that decides what traffic may pass from one room to another.
Lock the front door first
Interior doors don't help if the front door is propped open.
Pick the right Wi-Fi security setting
In the router's wireless settings you'll see WEP, WPA2 or WPA3.
WEP is broken and can be cracked in minutes. If anything still uses it, treat that network as having no password.
WPA2 is still common, but someone within range can capture the login handshake and guess your password offline for as long as they like. A weak password falls fast.
WPA3 fixes that with a newer key exchange (called SAE) that stops offline guessing, and it adds forward secrecy, so a password stolen later can't decrypt traffic recorded earlier. Turn it on if your router supports it. If it only does WPA2, use a long passphrase and put "WPA3 router" on the shopping list.
Your router has two passwords: the Wi-Fi password and the admin password for its settings. Factory admin passwords are published online for every model. Change it. Reused and stolen passwords are one of the top ways attackers get in, which is exactly why credential stuffing works so well.
Turn off WPS
WPS is the "push a button or type an 8-digit PIN to connect" feature. In 2012 CISA warned that the WPS PIN can be brute-forced: because of how the PIN is checked, an attacker only needs to try about 11,000 combinations, not 100 million. Crack the PIN and they get your Wi-Fi password, however strong it is. Turn WPS off.
Keep firmware updated
Firmware is the software inside your router and gadgets. Turn on automatic updates where the device offers them and check by hand where it doesn't. A device that no longer gets updates should be replaced, not trusted.
A segmentation plan for a small office
Build four networks, each with its own SSID and VLAN, and a firewall rule that stops them starting connections to each other:
- Staff: owner and employee PCs and laptops, the file server, work phones. Never reachable from guest or IoT.
- Guest: visitors' phones and laptops. Internet only.
- Payments: card readers, payment terminals, the register PC. Isolate it hard (see the PCI section below).
- IoT: cameras, smart plugs, thermostats, TVs, sensors. The weakest devices, quarantined so a compromise stays contained.
A typical consumer router gives you a guest network and not much else. For VLANs and rules between networks you need a business-grade router or firewall. It's the one piece of hardware worth spending on here.
The catch: printing and screen casting
Separation works in both directions, and that surprises people. Devices on different networks can't see each other, so two everyday things break unless you plan for them:
- Printers. Put the printer on the IoT network and staff PCs stop finding it. Either keep printers on the staff network (they're usually managed and updated more than a smart plug), or add one firewall rule that lets the staff network reach the printer's address for printing only.
- Casting to a TV. AirPlay, Chromecast and similar "find the screen" features rely on discovery messages that don't cross from one network to another. If the conference-room TV sits on the IoT network, staff laptops won't see it. Business routers usually have a setting for this (often called mDNS, Bonjour gateway or multicast DNS repeater) that passes discovery between the networks you choose. Turn it on for staff-to-IoT only, never guest-to-staff.
Also check whether your guest network has client isolation turned on. That stops guests' devices from seeing each other, which is what you want, but it also means a guest can't cast to your waiting-room TV unless that TV is on the guest network.
Test printing and casting from a staff laptop right after you make the change, not the next morning when someone needs a document.
An example
A dental office has a smart TV in the waiting room, Wi-Fi cameras, check-in tablets, the front-desk PC that runs scheduling and billing, and a card reader. One network, password shared with patients.
The TV picks up malware through an unpatched bug and starts scanning. On the flat network it finds the billing PC and card reader in seconds. On a segmented one, the TV is on IoT, patients are on guest, the tablets and billing PC are on staff, and the card reader is on its own payments network. The TV scans and finds only other TVs. The damage went from "the whole practice" to "one television."
If you take card payments
Any business that accepts cards is covered by PCI DSS, the card brands' security rules. PCI DSS doesn't strictly require segmentation, but the PCI Security Standards Council's scoping and segmentation guidance makes clear it's the practical way to shrink the set of systems the rules apply to.
Without segmentation, your whole office network is in scope, thermostat included. Put payment devices on their own isolated network and only that small slice is. It's safer, and much simpler to stay compliant.
Your action plan
- Sign in to the router's admin page and change the default admin password. This is the most important step and the most often skipped.
- Check the encryption setting. WPA3 if available, WPA2 at minimum. Fix any WEP today.
- Set a long, unique Wi-Fi passphrase for each network, several random words rather than "Business2026".
- Disable WPS.
- Turn on automatic firmware updates for the router and every gadget that supports them, and note which devices no longer get updates.
- Turn on the guest network so visitors never touch your systems.
- List your devices and sort each into staff, guest, payments or IoT.
- If you take cards, isolate the payment devices first.
- Move to a business-grade router or firewall and build the four networks, with rules that block cross-network traffic and the printer and casting exceptions above.
- Add DNS filtering so a device that does get compromised has a harder time reaching malicious servers. Segmentation contains the inside; DNS security guards the way out.
When to call someone
- Your router doesn't support VLANs or multiple SSIDs and you're not sure what to replace it with.
- You take card payments and aren't sure your payment devices are separated.
- After segmenting, printing, casting or a line-of-business app stopped working and the fix isn't obvious.
Steps 8 and 9 are where a second pair of hands helps most. If you want one, that's part of what our cybersecurity team does.




