Prefer WPA3 where compatible
WPA3 is the newer Wi‑Fi security generation. If all required devices support it, WPA3-Personal is generally preferred. Mixed/transition modes may be needed where older devices remain, but they can inherit compatibility tradeoffs.
Avoid obsolete security modes
WEP and old WPA/TKIP-era configurations should not be used for a modern home network. If a legacy device requires obsolete Wi‑Fi security, replacing or isolating that device is usually a better long-term choice.
Protect router administration
Use a unique administrator password, do not expose the administration interface to the public internet unless there is a well-understood need and secure design, and review which remote-management features are enabled.
Keep supported firmware updated
Router firmware fixes security and reliability issues. Use vendor-supported update mechanisms and replace devices that are no longer receiving security support when practical.
Guest and IoT separation
A guest network can keep visitors away from trusted local devices. Some routers also provide separate IoT networks. Whether those networks are truly isolated depends on the product configuration.
WPS and convenience features
Convenience features can increase attack surface. If you do not need WPS or remote cloud administration, consider disabling them according to the router's current documentation.