Put customers on a separate guest network with its own password, isolated from your own devices. Most routers support it as a single setting, and without it every visitor shares a network with your till.

What sharing a network means

Devices on the same network can generally see and reach each other.

Which means a customer's phone is on the same network as your till, your office computer, your network storage, and anything else connected.

That is not a problem with most customers, who are checking their email. It is a problem with anybody who is not, and with any device that is already infected without its owner knowing.

The risk is not somebody deliberately attacking you from your own café. It is an infected phone doing automatically what infected devices do, on a network containing your business.

What a guest network changes

The third is worth mentioning because it is a genuine benefit to your customers rather than only to you.

Most routers made in the last several years support this, and it is usually a single checkbox plus a name and a password.

A worked example

A café offering free wireless, one network, the same password since the router was installed.

The password was on a card on every table, and had been for four years.

Their card terminal, back-office computer and a network drive with several years of records were all on the same network.

Nothing bad happened, which is why nobody had thought about it.

When they replaced the router, the installer set up a guest network as a matter of course. It took no extra time and the password on the tables changed to a new one.

The useful part was not the isolation on its own. It was that the guest password could now be changed periodically without anybody having to reconfigure the till.

Previously changing the password meant reconnecting every business device, so it never happened.

The password on the wall

Worth thinking about even with a guest network.

A password printed on a card and displayed publicly is not a secret, which is fine for a guest network and would be serious for your own.

It also means anybody who has ever visited retains access from the car park, indefinitely, unless it changes.

Changing it periodically is reasonable, and it is only practical when your own devices are on a different network, which is the argument for separation restated.

Some routers can display a rotating password or issue vouchers, which is more than most small businesses need.

Your own network

The half that gets less attention and matters more.

A different password from the guest one, not written on anything public, and changed when somebody with access leaves.

The router's own administrator password changed from the default, which is one of the most commonly skipped steps anywhere in small business technology.

And the router's firmware updated, which most people have never done and which fixes genuine vulnerabilities.

Those three take twenty minutes once and they matter more than the guest network arrangement.

The counter-case

Where this is not worth the effort.

A business with no customer wireless at all, where the question does not arise, though the router password and firmware points still apply.

A one-person operation where the only devices are your own and nobody else connects.

And any situation where the connection is provided and managed by somebody else, such as a landlord or a shared building, where you may not control the configuration at all.

In that last case the right response is the opposite one: assume the shared network is untrusted and treat your own devices accordingly.

Devices you forgot are connected

A category that has grown quietly.

Card terminals, printers, cameras, thermostats, digital signage, a music system, and anything else installed by a supplier who set it up and left.

Each is a device on your network, frequently with a default password, frequently never updated, and frequently forgotten entirely.

Cameras are the notable one, because a poorly configured camera is both a security hole and a privacy problem in a business with customers.

Worth listing what is actually connected, which most people find surprising, and checking that each one has a password somebody deliberately chose.

What you are responsible for

A question that occurs to people once they think about it, and the answer is reassuring.

A business offering customer wireless is not generally responsible for policing what people do on it, in the way an internet provider is not responsible for its subscribers.

What is worth having is a short acceptable use notice on the connection page or the card, saying the connection is provided as a convenience and is not to be used unlawfully.

Keeping basic records of when the network was in use is sensible, and anything more elaborate is beyond what a small business needs.

If you are genuinely concerned, the practical measures are content filtering at the router, which most support, and not offering the service overnight.

What customers expect

A commercial point rather than a security one.

Free wireless is expected in some businesses and irrelevant in others, and offering it badly is worse than not offering it.

Slow, unreliable wireless with a password nobody can find produces complaints that a business without wireless never receives.

So the decision is worth making deliberately: offer it properly, on a separate network, with the password visible, or do not offer it.

The middle position, where it technically exists and works poorly, is the one that actively costs goodwill.

Setting it up

  1. Log into the router, which requires the administrator password.
  2. Change that password if it is still the default.
  3. Enable the guest network and give it a clear name.
  4. Turn on client isolation if the option exists.
  5. Set a separate password and display it.
  6. Update the firmware while you are in there.

The second and sixth are worth doing whether or not you offer customer wireless at all, and they are the two that never get done.

The wider question of what else is quietly running is covered in updating things without breaking them.


Frequently asked questions

What does sharing a network mean?

Devices on the same network can generally reach each other, so a customer's phone is on the same network as your till and office computer.

What is the actual risk?

Not somebody attacking you deliberately from your café. An already-infected phone doing automatically what infected devices do, on a network containing your business.

What does a guest network change?

A separate password that can be shared freely, isolation from your own devices, often isolation between guests, and the ability to turn it off out of hours.

Is a password on a card a problem?

Not for a guest network, where it is not a secret. It does mean anybody who has visited retains access unless it is changed periodically.

What matters more than the guest network?

Changing the router's administrator password from the default and updating its firmware. Both take minutes and almost nobody does either.

What devices am I forgetting?

Card terminals, printers, cameras, thermostats and signage, installed by suppliers and never updated. Cameras are the notable risk.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Same wireless password since the router was installed?

Separating customers from your till is one setting, and it makes changing that password possible.

Start a Conversation