Responsibility usually sits with the employee for configuration and daily use, even when the internet service provider supplies the hardware. The provider may maintain the connection, but the user must change default passwords, enable security settings, and keep firmware current. For organisations, that makes home router hygiene a shared human risk issue, not just a personal matter.
Who actually owns home router security for work use
The practical answer is shared, but not evenly shared. The employee is usually responsible for how the router is used and configured at home, while the provider or employer may control only a narrow slice of the environment, such as supplied hardware guidance or support. For work traffic, the home router becomes part of the organisation’s access boundary, so basic hygiene matters.
That means the security question is not “who owns the box,” but “who can change the settings that affect work access.” Default credentials, remote administration, firmware updates, Wi-Fi encryption, and guest-network separation are all controls that affect whether a home network can safely carry business traffic. Where those settings are left unchanged, the organisation inherits avoidable exposure.
What changes when a personal router carries corporate work traffic
Once work devices rely on a home router, the router is no longer just consumer infrastructure. It becomes a control point for confidentiality, availability, and trust. A weak home router can expose work sessions to interception, make endpoints easier to reach from the local network, or allow an attacker to persist by abusing outdated firmware or permissive management settings. Home networks are not managed like enterprise networks, so the margin for error is much smaller.
That also changes accountability. The employee can often fix the most important issues immediately, such as changing the admin password, enabling WPA2 or WPA3, disabling remote admin, and applying firmware updates. The organisation, meanwhile, should set a policy baseline and decide which work scenarios are acceptable on unmanaged home networks. If a router cannot be made reasonably current and locked down, the work pattern, not just the device, may need to change.
For a broader identity and access lens, the home router is part of the path that protects authenticated work sessions and remote access. Good router hygiene reduces the chance that credentials, sessions, or device trust are undermined by a weak local network. NHIMG’s Ultimate Guide to Non-Human Identities is also useful background where work access depends on credential lifecycle discipline and secret protection, even though the home-router problem itself is broader than identity alone.
Risk and Threat Considerations
Home routers create a real exposure point because they are often unmanaged, shared, and left on default settings for long periods. The main risk is not that every home router is actively attacked, but that a small configuration gap can expose work devices, work credentials, or remote sessions to local compromise or network abuse.
Failure mechanism: Attackers or opportunistic malware exploit weak admin passwords, outdated firmware, exposed management interfaces, or insecure Wi-Fi settings to gain local network access, intercept traffic, or alter router behavior.
Impact: The result can be session theft, device compromise, loss of confidentiality for work traffic, and a larger attack surface for the organisation because the home network is now part of the work environment.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, CIS Controls v8, NIST SP 800-63 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-1 — Identity Management, Authentication and Access Control | Home-router security protects access paths used for work sessions. |
| PR.PT-3 — Resilience and Protection Processes | Router firmware, Wi-Fi settings, and admin exposure affect protective technology strength. | |
| Recommendation — Require strong authentication and access controls for work connections over home networks. Harden and maintain home-network protections that support remote work. | ||
| CIS Controls v8 | 4 — Secure Configuration of Enterprise Assets and Software | Router defaults, firmware, and management settings are configuration controls that affect exposure. |
| 6 — Access Control Management | Default passwords and remote admin exposure are access-control failures on the home router. | |
| Recommendation — Apply secure configuration baselines and keep router firmware current. Remove default credentials and restrict administrative access to the router. | ||
| NIST SP 800-63 | IAL — Identity Assurance Level | Work access depends on trustworthy authenticated sessions over the home network. |
| Recommendation — Set identity assurance expectations for work access that traverses unmanaged home networks. | ||
| NIST Zero Trust (SP 800-207) | SC-3 — Continuous Verification | A home router is part of the trusted path that Zero Trust must continuously assess. |
| Recommendation — Continuously verify device and network trust before allowing access over home connections. | ||
Practitioner Guidance
What to verify: Confirm that the router admin password is unique, remote management is off unless explicitly required, firmware is current, and the work network is not sharing a flat trust zone with untrusted devices. If those basics cannot be verified, treat the connection as higher risk than a standard managed endpoint.
Decision rule: If the employee can change the setting themselves, they should do it immediately; if the router is ISP-managed or locked down, the organisation should decide whether the work use case needs compensating controls, such as stronger endpoint protections or a different access method.
Practitioner takeaway: The right ownership model is operational, not legal: the person using the home router usually owns the settings that make work safe, while the organisation owns the policy decision on whether that home environment is acceptable for business access.
Related resources from NHI Mgmt Group
- How should security teams reduce remote-work identity risk for employees using home offices?
- Who should own policy enforcement when AI is used in daily work?
- Who is responsible for securing cloud workloads in a shared responsibility model?
- How should organisations govern mobile devices used for remote work?