Most home network security advice is either too vague ("use a strong password") or too technical (assumes you already know what VLANs are). This is a checklist built the other way — ten specific, concrete things to check, in the order that matters most, each doable in a few minutes with tools you already have or a free scan.
1. Know every device that's actually connected
You can't secure what you don't know exists. Start with a full device discovery scan rather than trusting your router's built-in client list — see why the router's list usually isn't complete.
2. Check for default or reused credentials on IoT devices
Every smart plug, camera, thermostat, and speaker ships with a default admin password. Manufacturers rarely force a change. If you've never explicitly set a password on a device, assume it's still the default — that's the single most exploited weakness in home networks.
3. Scan for open ports on anything IoT
Cameras, DVRs, and cheap smart-home hubs are the most likely devices to have an unnecessary service exposed. See our full breakdown of what open ports mean and which ones matter.
4. Verify your router isn't using its default admin password
This is the highest-leverage single fix on this list. Your router is the one device that, if compromised, gives an attacker visibility into everything else. If you've never changed the admin login from what was printed on the box or sticker, do this first, before anything else here.
5. Turn off WPS
WiFi Protected Setup is convenient and has a long history of PIN-brute-force vulnerabilities. Unless you specifically need it for a one-time device pairing, it's worth leaving off by default.
6. Confirm you're on WPA3 (or WPA2 at minimum)
WEP and open networks are both still surprisingly common on older router configurations that were never revisited after initial setup. Check your WiFi security setting directly in the router admin panel — don't assume it was configured correctly at purchase.
7. Separate IoT devices onto a guest network
Most consumer routers support a second SSID ("guest network") that isolates connected devices from your main LAN. Putting smart-home gadgets on it means that if one of them is compromised, it can't directly reach your laptop or phone.
8. Check what's actually port-forwarded on your router
Open your router's Port Forwarding / Virtual Server settings and review every entry. It's common for a rule added years ago for a game console or a camera app to still be active long after you stopped using the service — each one is a door left open to the internet, not just your LAN.
9. Review cameras specifically
Cameras deserve their own pass because they combine the two riskiest properties — always-on network exposure and genuinely sensitive footage. See our dedicated IP camera exposure check.
10. Re-scan on a schedule, not just once
New devices join, firmware updates reset settings, and forgotten port-forwarding rules accumulate. A network that was clean when you last checked isn't guaranteed to still be clean. Treat this checklist as something to re-run every couple of months, not a one-time setup task.
The fast way to run most of this list: ProbeShield combines device discovery, port scanning, and manufacturer identification into one scan with a five-tier risk score per device, entirely on-device — no cloud account, no data leaving your phone.