The router is the most security-relevant device in most homes and the least attended to. It is installed by somebody else, works, and is never opened again.

Here is what is worth doing, in order of how much difference it makes.

Change the administrative password

First and most important, and it is not the wireless password.

The administrative password controls the router's settings. Many devices ship with a default that is either universal to the model or printed on a label, and lists of defaults are freely available.

An attacker who reaches the administrative interface can redirect all your traffic by changing the name resolution settings, which is a serious compromise and is difficult to notice.

Providers have improved on this, with unique per-device passwords now common, and older equipment frequently still has a default.

Update the firmware

Second, and it is the thing that addresses known vulnerabilities.

Routers run software with security flaws like anything else, and vulnerabilities in consumer routers are found regularly and exploited at scale.

Many modern devices update automatically, which is worth confirming rather than assuming.

The related point is that a router which no longer receives updates should be replaced. Manufacturers support consumer equipment for a limited period, frequently shorter than people keep the hardware, and an unsupported router accumulates known and unpatched vulnerabilities.

Checking whether your model is still supported takes two minutes and is the check almost nobody performs.

Disable remote administration

Third, and it eliminates a whole class of attack.

Remote management allows the settings interface to be reached from the internet. Unless you specifically need it, it should be off, and on many devices it is on by default.

The same applies to older remote management protocols intended for provider use, which have had significant vulnerabilities historically.

Use current wireless encryption

Fourth.

The current standard is meaningfully better than its predecessor, particularly against offline attacks on captured traffic.

Older standards should not be used at all, and one of them is broken to the point of being equivalent to no encryption.

Most devices offer a mixed mode for compatibility with older equipment, which is a reasonable compromise if you have something that needs it and worth avoiding otherwise.

The wireless password itself should be long. Length is what resists offline attack, and a passphrase of several words is both stronger and easier to give to visitors than a short complex string.

Set up a guest network

Fifth, and more useful than it sounds.

A guest network isolates devices on it from the rest of your network. Visitors get internet access without being able to reach your file shares, printers or cameras.

The more valuable use is for connected devices generally. Anything cheap, connected and rarely updated — which describes most of the smart home category — is a reasonable candidate for isolation, since a compromised device on an isolated network can do considerably less.

Turn off features you do not use

Sixth, and it reduces the surface.

Automatic port forwarding protocols, which allow devices on your network to open ports to the internet without asking. Convenient and a genuine risk, since a compromised device can expose itself.

Simplified wireless setup mechanisms, some of which have known weaknesses.

And any file sharing or media serving built into the router, which is frequently poorly maintained relative to the main firmware.

What is not worth bothering with

Hiding the network name, which provides no meaningful protection and causes connection problems. The name is transmitted by clients anyway.

Filtering by device hardware address, which is trivially bypassed since those addresses can be changed freely, and which makes adding devices tedious.

Both appear on old advice lists and neither does anything against an attacker capable enough to matter.

The whole exercise

Twenty minutes, once, plus a firmware check every few months.

The single highest-value item is the administrative password, followed by keeping firmware current and replacing hardware that no longer receives updates.

Everything else is worth doing and secondary, and doing only the first three puts you ahead of most households.

Name resolution settings

One further item worth checking, since it is a common target.

The router tells every device on the network which servers to use for translating names into addresses. An attacker who changes that setting can redirect traffic without touching any individual device.

Checking that the configured servers are what you expect — your provider's, or a public resolver you chose — takes a moment and would reveal a compromise that is otherwise close to invisible.

It is also the setting to change if you want filtering at the network level, which is a straightforward way to block a category of malicious domains for every device at once.

Provider-supplied equipment

A final consideration for anybody using the router their internet provider supplied.

These are frequently locked down, with limited access to settings and firmware controlled entirely by the provider.

That has an advantage — updates are handled — and a disadvantage, in that you cannot verify or change what you cannot see.

Replacing it with your own equipment is possible on most connection types and gives full control, at the cost of being responsible for it and losing provider support for connection problems.

For most households the supplied unit with the administrative password changed is a reasonable position.