Support desk — Monday to Friday, 08:30 to 17:30Client AreaGet help now →

Is Your Office Wi-Fi Actually Secure?

Office Wi-Fi is usually set up once, on the day the broadband was installed, by whoever happened to be holding the router. It then runs untouched for years, quietly accumulating everyone who has ever needed it.

It is also, in a lot of buildings, the softest way into an otherwise well-defended network.

The shared password problem

Most small offices run one Wi-Fi key that everyone knows. Staff, contractors, the person who came to service the boiler, and everyone who has left in the last five years.

That key is effectively public. It cannot be rotated without telling everyone, so it never is. And because it grants access to the same network the servers and printers sit on, anyone within range of the building has a route in.

The fix is separation, and it costs nothing but configuration.

Three networks, not one

Staff. Ideally with individual credentials tied to each person’s account, so access ends when employment does. On business-grade equipment this is straightforward; on consumer kit it usually is not, which is itself an argument about the equipment.

Guests. Internet only, with no route to anything internal. A visitor should be able to reach the web and nothing else. Rotate the key periodically, and do not print it on a laminated card that outlives three receptionists.

Devices. Printers, cameras, door entry, sensors, the smart TV in the meeting room. These rarely receive updates and are frequently the least secure things in the building. They belong on their own segment, unable to reach anything they do not need.

Separation matters more than any other single change here, because it limits what a compromise can reach. A guest laptop carrying malware is an irritation on a guest network and an incident on a flat one.

Self-check

Office Wi-Fi, honestly assessed

Tick what is true of your office network right now.

0 of 8

Encryption, briefly

Use WPA3 where the hardware supports it, WPA2 with a long key where it does not. WEP and original WPA are broken and should not be in use anywhere. If a device is too old to manage WPA2, it is old enough to be a liability in several other ways as well.

The things people forget

The admin password on the access points. Default credentials for every common model are published. This takes two minutes and is skipped remarkably often.

Firmware. Network hardware is explicitly in scope for Cyber Essentials patching requirements, and it is the category most often overlooked because nobody sees an update prompt. High-risk firmware updates are subject to the same fourteen-day window as everything else.

WPS. If it is still enabled, turn it off. It exists for convenience and undermines a good password.

Range. Wi-Fi does not respect walls. In a shared building or a high street office, your network is available in the car park. That is not a reason for alarm, but it is a reason to configure as though outsiders can see it — because they can.

Hiding the network name does not help

A common piece of advice, and not a useful one. A hidden network is trivially discoverable with free tools, and hiding it makes client devices behave worse — they broadcast requests for it, which is marginally worse for the people using it.

Spend the effort on separation and credentials instead.

A sensible afternoon’s work

Find out how many networks you actually have and what each can reach. Change the guest key. Check the access point admin passwords. Check firmware. Put the printers somewhere sensible.

None of that requires new equipment in most offices, and the improvement is substantial. If it turns out the equipment cannot do what you need, that is worth knowing too — business-grade access points are inexpensive and the difference in what they allow you to configure is significant.

If you would like your setup reviewed, it is a quick visit and the findings are usually more about configuration than spending.

Found this useful?

We write these because the same questions keep coming up. If one of them is yours, the answer is usually a short conversation away.

Keep reading