Router Security for Working From Home
Your home router now guards work data too. Here is what the NSA, CISA and NIST tell remote workers to do.
Your home router now guards work data too. Here is what the NSA, CISA and NIST tell remote workers to do.
To work from home securely, lock down your router first: change default passwords, use WPA3 or WPA2, keep firmware updated and turn off outside administration. Then keep work devices apart from guests and smart devices, and connect to work through your employer’s VPN or another secure channel. That is the core of NSA, CISA and NIST telework guidance.
The NSA says your home network’s security affects not only your personal information but also your work information and networks when you telework.
NIST adds the reverse risk: if your telework device is compromised, anything else on your home network could be at risk too.
Keep them apart from less trusted devices. The NSA says home Wi-Fi should be split into at least primary, guest and IoT networks.
Keep your work laptop on the primary network, and move visitors and smart devices off it. See our guides to guest networks and smart home networks.
The NSA also warns against moving files between home and work systems by email or removable media. Ideally, it says, use equipment and accounts your organization provides.
Use your employer’s if it has one. NIST says to use your organization’s VPN on your telework device. The NSA says to always use a VPN or other secure channel to reach corporate networks.
A work VPN protects the connection to your employer. It does not secure your router. Our VPN guide explains the difference.
Working away from home? The NSA says to use a cellular connection or personal hotspot instead of public Wi-Fi when possible, and a trusted VPN if you must use public Wi-Fi.
The NSA says to replace routers that reach end of life. Work through our 10-minute checklist, then check your router’s grade to see if yours still gets updates.
It can be, if it is secured. NIST says home Wi-Fi should use WPA2 or WPA3 with a hard-to-guess password. CISA adds changing default passwords and disabling WEP and WPA.
Yes, if it has one. NIST says to use your organization’s VPN on your telework device, and the NSA says to always use a VPN or other secure channel to reach corporate networks.
Follow your employer’s policy. The NSA says it is best to use organization-provided equipment. If you use a personal device, use the security products your employer requires.
CISA’s telework toolkit recommends a protective DNS service, which blocks lookups of known malicious domains. If your employer sets DNS on your work device, leave it as is.
Not if yours still gets security updates and supports WPA2 or WPA3. The NSA says to replace routers when they reach end of life, so check your model’s support status.
Dates show when each source was published or when we checked it.
Check your router
Get its FCC status, CVEs, grade and an action plan.
Check a Router → Top 10 Safe Routers