Giving visitors the same Wi-Fi as printers and servers risks their laptop scanning your LAN. Use a guest SSID/VLAN with internet-only egress and keep corporate devices on managed access.
Enable client / AP isolation on guest SSIDs so visitors cannot see each other — useful at events where devices are untrusted.
WPA2-PSK vs. 802.1X
WPA2-PSK for all staff beats nothing, but larger teams benefit from 802.1X so you can revoke access centrally when someone leaves without rotating a shared passphrase on every AP.
WPA3 improves resilience against offline handshake attacks where hardware supports it; guest networks often combine a simple passphrase with captive portal vouchers.
Practical rules
- Guest Wi-Fi without a path to internal apps; captive portal with short-lived codes when possible.
- Manage APs from a management VLAN, not from the guest network; strong passwords, not defaults.
- Patch AP firmware — outdated access points are common entry points via public CVEs.
Home office: even on one router, an isolated guest subnet reduces risk when visitors bring unknown devices.