Skip to content
SYNTHESISCYBER

Hardening

Wi-Fi & Router Security Hardening

Step-by-step router configuration guides: WPA3 personal/enterprise, DNS-over-HTTPS (DoH), isolated guest networks, and WPS disabling.

Wireless Router & Perimeter Hardening
Defense-in-depth perimeter settings to prevent drive-by wardriving and lateral network exploitation
WPA3-SAE Encryption Protocol
Critical

Mandate WPA3-Personal or WPA2/WPA3 Mixed mode with protected management frames.

Disable Wi-Fi Protected Setup (WPS)
Critical

WPS PINs can be brute-forced within hours using Reaver or PixieWps.

Segment IoT Devices onto Isolated Guest VLAN

Prevents compromised smart thermostats or cameras from pivoting to laptops.

Encrypted DNS (DoH / DoT)

Configure Quad9 (9.9.9.9) or Cloudflare (1.1.1.2 malware-blocking) upstream.

Disable Remote WAN Admin Management
Critical

Router administration interface should never be accessible from the public internet.

Disable Universal Plug and Play (UPnP)
Critical

Prevents malware inside the LAN from autonomously opening inbound firewall ports.

How it works

This module is guided content rather than a processing tool. It walks you through steps on the systems you already use, and nothing about your setup is sent to us.

What this cannot do

No single tool makes an account or a device secure. This module reduces one specific category of risk. It does not detect malware already running on your device, it cannot recover data you lose the key to, and it does not replace keeping software updated and using unique credentials everywhere.

If your device itself is compromised, anything you type into any tool — including this one — can be observed. Treat device hygiene as the foundation everything else sits on.