An insecurely configured WLAN is an open door into your company network — literally, since unlike a network cable, nobody needs to be physically inside the building for it. A few of the most common mistakes I keep running into:

Mistake 1: The default password stays put

Many routers ship with a preset WLAN password, either printed on a sticker on the device or, worse, a known default password from the manufacturer. Both should be changed during initial setup — a long, unique password takes just a few minutes to set.

Mistake 2: One network for everything

Printer, POS system, employees' personal phones, and the server that holds accounting data — all on the same WLAN. If a single device is compromised (an infected personal phone is sometimes all it takes), an attacker potentially has access to the entire network. Splitting the network into segments (VLANs) ensures a problem in one area doesn't automatically become a problem everywhere.

Mistake 3: No separate guest WLAN

Customers, subcontractors, or visitors get the regular WLAN password — with full access to the same network as your accounting system. A separate guest WLAN takes just a few clicks to set up on most current routers and keeps guests cleanly separated from your internal network. (See our dedicated article on that.)

Mistake 4: Outdated encryption

WEP and older WPA are long considered insecure and can be cracked with freely available tools in a short time. Current routers support WPA2 or WPA3 — worth checking in the settings and switching over if needed.

Mistake 5: The range doesn't stop at your property line

A WLAN signal that reaches well beyond your own building invites people to try their luck from outside. Transmission power can be reduced on most devices — a simple, often overlooked step.

Setting a WLAN password is the first step, not the last.

Get your network checked

A WLAN and network setup that matches the size of your business — from segmentation to guest access.

Get in touch