Mon–Sat 10:00–18:00 London · UK
Remote & on-site ☎ 0207 096 0936
← Guides
How-To

Guest Wi-Fi for Business: How to Set It Up Safely

Handing visitors the staff Wi-Fi password puts unknown laptops next to your server, printers and card terminal. Here's how to give guests internet without giving them your network.

Ask a small business who is on its Wi-Fi right now and you’ll get a confident answer. It’s usually wrong. The real list includes the accountant who visited in March, the plumber who bled the radiators, the two candidates who interviewed on Tuesday, and everyone those people have since passed the password to. In most offices there is one Wi-Fi password, it lives on a whiteboard by reception, and it hasn’t changed in three years.

That matters more than it sounds. When a visitor joins your staff Wi-Fi, their laptop arrives on the same network as your file server, your printers, your cameras and — in plenty of shops, clinics and salons — the card terminal. You have no idea what’s running on that laptop. Guest Wi-Fi done properly isn’t generosity with your broadband. It’s keeping unknown devices away from the things that run your business.

A separate name is not a separate network

The first thing most people do is create a second Wi-Fi name called something like “OfficeGuest”. Good instinct, but on its own it achieves little. Two network names can sit on the same underlying network, which means a guest device can still find your NAS, still reach the printer’s admin page, still scan for anything else that answers.

What you want is separation underneath the name. On business kit that’s a VLAN — a separate network with its own address range and a firewall rule saying “internet only, nothing internal”. On smaller routers it’s a tick-box marked “guest network isolation” or “AP isolation”, and the quality varies. Some genuinely wall the traffic off. Some only stop guests seeing the staff network name in the list.

So test it. Join your own guest network on a phone, then try to open your printer’s web page by its IP address, or browse to a shared folder. If either works, you have a guest name, not a guest network. That’s the single check worth doing before anything else, and it’s the foundation of any business Wi-Fi setup meant to be safe rather than convenient.

Stop guests seeing each other, too

Client isolation is the second setting, and it’s often left off. Without it, every device on your guest network can see every other device on it. Two unrelated visitors in your waiting area are effectively sharing a home network — and if one is carrying something nasty, the other is the nearest target.

Turn client isolation on. Nobody on guest Wi-Fi needs to reach anyone else on it.

Put a ceiling on how much they can take

Guest bandwidth is the quiet killer of video calls. One visitor syncing a phone backup or streaming a match in the corner can take a large slice of your line, and the first anyone notices is your own team’s Teams call breaking up.

Set a per-client speed limit, and cap the guest network as a whole if your kit allows it. Guests should get enough to check email and tether a laptop — not enough to flatten your connection. If your line already struggles before any of this, that’s a separate problem, and our guide to why office Wi-Fi runs slowly covers the causes worth ruling out first.

Passwords, portals, and which one you need

A fixed guest password that never changes has the same flaw as the staff one: it spreads. Three sensible options, and the right one depends on how many strangers pass through.

A rotating password suits an office with occasional visitors. Change it monthly, or whenever a contract ends. Some business access points generate a voucher that expires after a set number of hours, which is neater still — the visitor gets access for the afternoon and it dies on its own.

A captive portal — the splash page you accept terms on before you get online — earns its place when visitors are frequent and unmanaged: a waiting room, a café, a treatment room, a shared workspace. It gives you somewhere to state acceptable use, a way to time-limit sessions, and a record that someone agreed to something.

No password at all is defensible only on an isolated guest network with a portal in front of it, and even then it invites passers-by. For most offices, don’t.

The trap is treating the portal as security. It isn’t. A portal controls who gets past the front page; separation is what stops them reaching your systems. You need both, and separation matters more.

The coffee machine belongs on the guest side as well

While you’re separating networks, look at everything that isn’t a work computer. Smart TVs in the meeting room. Wireless cameras. The coffee machine that asked for Wi-Fi during setup. Any of these may be running software the manufacturer stopped updating years ago, and each sits permanently on your network waiting to be found.

None of that gear needs to reach your file server. Give it its own network — the guest one, or better, a third network for devices. It’s the same instinct behind sensible cyber security for small businesses: assume something will eventually be compromised, and make sure it can’t reach anything valuable when it is.

If customers use it, it’s a service, not a courtesy

For hospitality, retail, clinics and salons, guest Wi-Fi stops being an IT setting and becomes part of the customer experience. People notice when it’s slow or the login is awkward.

That means coverage where customers actually sit, a login that works on a phone in three taps, and no portal that fights with the browser on an iPhone. Worth designing rather than improvising — the same discipline we’d apply to IT for restaurants and hospitality, where the card terminal and the tablets on the pass must stay clear of whatever customers bring through the door.

About collecting customer data through the portal

Portals can capture an email address or a mobile number, and vendors will sell you that as a marketing feature. Be honest with yourself about it. If you collect personal data you need a lawful basis, a clear notice explaining what you’re doing with it, and a real intention to use it. Harvesting addresses into a list nobody ever touches gives you an obligation, a risk and no benefit. If you’re not going to run a genuine mailing list, ask for nothing.

Check what you already own first

Before buying hardware, open your router or access point admin page and look for four things: whether a guest network exists, whether it can be isolated from the main network, whether client isolation is available, and whether you can rate-limit guests. Plenty of business kit already installed does all four, and nobody ever switched them on.

If the answer is no — common with a broadband provider’s own box — you’re replacing access points, not broadband. That’s the point at which it’s worth planning business networks and Wi-Fi as one design instead of adding another box to the pile.

Get the separation right once and it keeps working quietly. Visitors get internet. Your server, printers and payment kit stay out of reach. And the password on the whiteboard stops mattering, because it no longer opens anything worth having.

Frequently asked questions

Is the "guest network" tick-box on a home router good enough for an office?

For a two-person studio with nothing shared on the network, it is better than nothing. For a real office it usually isn't, because consumer guest modes vary wildly in what they actually block — some genuinely separate the traffic, others only hide the staff Wi-Fi name. Test it rather than trusting the label. Join the guest network, then try to reach your file server, a printer's web page and another device on the same guest network. If any of those open, the separation isn't real.

Should staff phones go on the guest Wi-Fi?

Usually yes, and it is one of the easiest wins available. Personal phones don't need to reach your server or printers, they carry apps nobody has vetted, and they are the devices most likely to be lost or handed down. Put them on the guest side, keep company laptops and managed devices on the staff network, and your main network gets quieter and safer at the same time.

Do I have to keep a record of who uses my guest Wi-Fi?

There is no blanket UK rule forcing a small business to log guest usage, and most offices don't need to. Some regulated settings and some landlords in shared buildings impose their own requirements, so check your lease or your sector's guidance rather than assuming. If you do log anything, treat it as personal data — say so in a notice, keep it only as long as you have a reason to, and don't quietly repurpose it for marketing.

Related services

Free · no obligation

Want a hand with any of this?

Tell us what you're trying to sort out and we'll come back with a clear, no-obligation plan and price.