Factory defaults favour easy setup support calls — not your long-term safety on a loud residential ISP network.
Whether you use a Bell Home Hub, Rogers gateway, Telus combo or a retail mesh node, out-of-box settings often leave WPS on, admin passwords predictable and remote management one checkbox away from the wider internet. Spend thirty focused minutes on day one and you skip months of quiet risk.
Change the admin password first
The sticker password is better than « admin/admin, » yet it sits on a card in a drawer anyone can read. Set a long unique admin passphrase in your password manager. Do not reuse the Wi-Fi password as the admin password.
Wi-Fi names and encryption
- Rename SSIDs to something non-identifying — avoid your full name, address or « SmithFamily. »
- Use WPA3 if all devices support it; otherwise WPA2-AES. Avoid WEP and TKIP legacy modes.
- Create a guest network for visitors; enable client isolation if available.
Risk reduction if fixed on day one (editorial)
Turn off the dangerous conveniences
WPS push-button pairing remains a weak spot — disable it. Remote management / WAN admin should stay off unless you truly need ISP-style remote help and understand the exposure. UPnP can punch holes for games; disable on routers that also host work devices, or limit it carefully.
Firmware and automatic updates
Enable auto-updates when the vendor is reputable. Otherwise calendar a manual check. Day-one hardening without patching is incomplete. Replace routers that no longer receive security builds.
DNS and filtering choices
Consider reputable filtered DNS for kids' networks while leaving the office SSID flexible. Document custom DNS so an ISP reset does not silently revert you. Avoid random « free speed boost » DNS apps.
Fifteen-minute checklist
- New admin password saved in the vault.
- WPA2/WPA3 Wi-Fi with new SSID.
- Guest network on; WPS off; WAN admin off.
- Firmware current.
- Screenshot of settings stored securely.
- Old default SSIDs forgotten from family devices and re-joined cleanly.
Defaults are for first boot. Your second act is turning the router into a boring, hardened appliance — then leaving it alone except for updates.
