Every time you connect to the internet – whether at home through your router or on the go through a mobile hotspot – you are opening a door to the digital world. The key question is: who else can walk through that door? Most people set up their router once and forget about it, and use mobile hotspots without a second thought. Yet these two access points are among the most common targets for cybercriminals. Understanding how to lock them down is not a matter of being tech-savvy – it is a matter of basic digital hygiene that everyone using the internet today needs to practice.
Table of Contents
- Router security: why it matters more than you think
- Change the default admin password immediately
- Understanding the SSID and why it needs your attention
- Use strong encryption: WPA2 or WPA3
- Disable risky router features
- Keep your router’s firmware updated
- Mobile hotspot safety: precautions you cannot skip
- Set a strong, unique password and change the SSID
- Limit the number of connected devices
- Turn off the hotspot when not in use
- Avoid public Wi-Fi as a habit
- Protecting mobile devices when using Wi-Fi hotspots
- Keep software and apps updated
- Use only trusted app stores and review app permissions
- Use a VPN for an added layer of protection
- Disable unused connections and enable remote wipe
- Putting it all together
Router security: why it matters more than you think
Your router is the central hub for every device in your home or classroom – laptops, smartphones, smart TVs, printers, and even smart appliances. If you do not secure your home Wi-Fi network, cyber threat actors can gain access to your network and read any unencrypted data that you send over the network. The threat is very real. A 2024 Broadband Genie router security survey found that over half of respondents (52%) admitted they have never adjusted their router’s factory settings, and 86% have never changed their router administrator password. Leaving default settings in place is the digital equivalent of using a lock that thousands of other people own the key to.
Hackers can use a tool such as the popular Shodan, which locates devices connected to the internet including routers, and if your router has a default, easy-to-guess password, they can use brute force to gain access – trying common username and password combinations like “admin” and “12345678” until one of them works. Once inside, they can intercept your communications, redirect you to fake websites, or hijack your devices entirely.
Change the default admin password immediately
The very first thing you should do with any router is change the administrator password – the one you use to log into the router’s settings panel. The router’s admin password remains the same for routers across the same manufacturer, so changing the default password prevents anyone connected to the network from taking control of the router. Choose a long, unique password that is not used anywhere else.
Understanding the SSID and why it needs your attention
The SSID, or Service Set Identifier, is simply the name of your Wi-Fi network – the one you see when you scan for available networks on your phone. It may seem harmless, but it carries real security implications. The default SSID name is often traceable to the make and model of the Wi-Fi router, which makes it an easy target since some routers have known vulnerabilities. In other words, your default network name is essentially advertising to nearby hackers exactly what type of router you are using.
Rather than changing the name to something that can be linked to you, such as “De Leon Family WiFi,” you should instead give it a more generic name, because choosing a personal SSID can make it easier for hackers to carry out hyper-personalised phishing attacks designed to steal your personal information. Keep it neutral – something recognisable to you but meaningless to anyone else.
According to the Canadian Centre for Cyber Security, you can also disable the SSID broadcast entirely, so your wireless network name will not be visible to threat actors scanning networks in the vicinity. While this is not a complete security solution on its own, it does reduce your network’s visibility to casual snoopers.
Use strong encryption: WPA2 or WPA3
Encryption is what scrambles your data so that even if someone intercepts it, they cannot read it. Using WPA2 or WPA3 in your router settings enables that encryption, with WPA3 being the newest and best option. If WPA3 is not available, WPA2 AES (sometimes also labelled WPA2 PSK or WPA2) provides a strong alternative. Never use the outdated WEP or WPA standards – these can be cracked quickly with freely available tools.
Disable risky router features
Several default router features create unnecessary security vulnerabilities and should be turned off unless you have a specific reason to use them.
- Remote management: This setting allows you to log in to your router over the internet to make changes – disabling it can prevent threat actors from making changes to your router without connecting to your network first.
- WPS (Wi-Fi Protected Setup): WPS is a convenient feature to simplify the process of connecting devices to your Wi-Fi router, but a threat actor within range can brute-force the PIN authentication method.
- UPnP (Universal Plug and Play): UPnP allows you to easily connect smart devices to your Wi-Fi network, but threat actors can use it to spread malware to devices in your network and control them remotely.
Keep your router’s firmware updated
Router manufacturers release firmware updates to patch security flaws and enhance performance – check your router’s admin panel regularly for updates, or enable automatic updates if supported. This is one of the most overlooked but critical security practices. An overwhelming 89% of users have never updated their router’s firmware, and many Linux routers – particularly dedicated and purpose-built devices – are set up once and never updated. An unpatched router is a known vulnerability waiting to be exploited.
Mobile hotspot safety: precautions you cannot skip
A mobile hotspot turns your smartphone into a portable Wi-Fi router, sharing your cellular data with nearby devices like laptops or tablets. It is extremely convenient – but if left unsecured, anyone nearby can log on to your hotspot, which obviously puts your data at risk. The threats are not theoretical. If your hotspot has a weak password or no password at all, strangers can connect to your network, use up your mobile data, and slow down your connections.
Set a strong, unique password and change the SSID
Databases exist that contain the passwords for Android, iPhone, and portable hotspot devices, and these passwords are keyed to the default SSID – naming your network and setting a strong unique password will help prevent anyone from using one of these databases to access your network. Treat your hotspot password with the same seriousness as your online banking password.
Limit the number of connected devices
Most smartphones allow you to set a maximum number of devices that can connect to your hotspot at any one time. Keep this number as low as possible – ideally only the devices you are actively using. When multiple devices share a single connection, the potential for unauthorised access increases, and you need to be aware of risks such as having your data intercepted or your connection accessed by unwanted users. Regularly check your hotspot’s connected device list and remove anything you do not recognise.
Turn off the hotspot when not in use
Leaving your hotspot on when you are not using it is not just a drain on your battery and data – it is also a security risk, because when enabled, your phone is visible to anyone nearby, making it more vulnerable to threat actors. Make it a habit to switch off your hotspot the moment you are done using it.
Avoid public Wi-Fi as a habit
Threat actors can create fake hotspots to trick users into connecting and launch a man-in-the-middle (MITM) attack, so you should be wary of networks with generic names like “Free Wi-Fi” or “Public Wi-Fi.” Public Wi-Fi is often unencrypted and widely considered unsafe for sensitive activities like banking or accessing personally identifiable information. Using your own secured mobile hotspot is almost always safer than connecting to an unknown public network.
Protecting mobile devices when using Wi-Fi hotspots
Securing the hotspot itself is only half the equation. The devices that connect to it – your phone, tablet, or laptop – also need to be hardened against threats. Malware infections are a serious risk: if any device on the network is infected, it can spread to other devices on the same network, and if a threat actor manages to join your hotspot, they could attempt to install malware on your device to steal data, spy on you, or lock down your files with ransomware.
Keep software and apps updated
Software updates are not just about new features – they patch known security vulnerabilities that hackers actively exploit. You should install security software such as mobile threat defence tools to protect against malware, and use only trusted chargers and cables, since a malicious charger or PC can load malware onto smartphones that may circumvent protections and take control of them. The CISA Mobile Device Cybersecurity Checklist recommends enabling automatic operating system and app updates so you are always running the most current security patches.
Use only trusted app stores and review app permissions
Disabling third-party app stores is important, as these can be vectors for the spread of malware. You should also periodically review and delete apps that are unused or no longer needed, and set app privileges to minimise access to personally identifiable information. An app that asks for access to your camera, microphone, or location when it has no obvious need for these is a red flag.
Use a VPN for an added layer of protection
A Virtual Private Network (VPN) encrypts all traffic between your device and the internet, making your data unreadable even if someone intercepts it. While WPA2 encryption and a strong password are a good start for mobile hotspot security, a VPN can add another crucial layer of security, especially for users connecting to enterprise systems or handling sensitive data. This is especially important when using public Wi-Fi or hotspots in crowded locations like airports, cafes, or hotels.
Disable unused connections and enable remote wipe
You should disable unneeded network radios such as Bluetooth, NFC, Wi-Fi, and GPS when they are not in use, since every connection is a potential point of attack. Additionally, you should configure settings to automatically wipe your device’s data after a certain number of incorrect login attempts, and enable the option to remotely wipe your device in case it is lost or stolen. These measures ensure that even if your physical device ends up in the wrong hands, your data stays protected.
Putting it all together
Router security and mobile device protection are not one-time tasks – they are ongoing responsibilities. Changing default passwords, customising your SSID, enabling strong encryption, keeping firmware and apps updated, and turning off unused connections are all straightforward steps that dramatically reduce your exposure to cyber threats. By keeping software up to date, using strong passwords, turning off remote management, and enabling encryption, you can stop hackers in their tracks. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Canadian Centre for Cyber Security both provide freely available checklists and guidance that anyone – student, teacher, or everyday user – can follow to stay safe online. Staying secure is less about having special technical knowledge and more about building consistent, careful habits every time you connect.
What do you think? When did you last check who is connected to your home Wi-Fi network – and do you know what steps you would take if you found an unauthorised device? If you use a mobile hotspot in public, how confident are you that it is properly secured against the threats discussed here?
Leave a Reply