If you hand out the regular WLAN password to visitors, their devices end up on the same network as your internal systems — printer, accounting computer, sometimes even a server. If one of those guest devices is infected with malware (something nobody can rule out for a device they don't manage), it potentially has direct access to your internal network.
The fix is simpler than it sounds
Practically every current router or business WLAN system offers a separate guest network feature — usually a few clicks away in the admin interface. The guest network gets its own password and stays completely isolated from the internal network, even when both run on the same hardware.
What a good guest WLAN should do
- Isolation from the main network — devices on the guest WLAN shouldn't be able to reach internal systems.
- Client isolation — ideally, guest devices can't even see each other, so an infected device can't attack other guests on the same network.
- Its own, regularly changeable password — separate from the internal WLAN, so changing it doesn't affect the whole team.
- Bandwidth limiting — optional, prevents a guest with a large download from slowing down your business connection.
Relevant for subcontractors too
Not just typical visitors — subcontractors or external service providers who are on-site temporarily should also generally use the guest network, even in a trusted working relationship. It's not about distrust of the person, it's about keeping control over unknown devices on your own network.
A guest WLAN is one of the best effort-to-security-gain ratios you can get.
Get network separation set up
From a simple guest WLAN to full segmentation of your entire network into multiple zones.
Get in touch