In many small businesses, every device sits on one network. The till, the receipt printer, security cameras, office computers, and guest Wi-Fi all share the same router.
As long as nothing happens, the arrangement feels fine. The problem appears when there's one curious guest, or one infected device.
What can happen
Devices on the same network can see each other. Anyone connected to the guest Wi-Fi can scan the network and find everything on it.
What they typically find:
- Security cameras with default passwords that were never changed
- Printers with web interfaces open without authentication
- Storage devices holding business files
- The router's admin page
- Point-of-sale computers with file sharing enabled
Beyond security, there's stability. A guest network saturated at peak hours can leave the card terminal unable to process transactions. That's a directly felt loss, and it happens far more often than hacking.
Three levels of separation
Pick according to your scale and budget. All three are better than no separation at all.
Level 1, The router's built-in guest network
Nearly every modern router has this. You create a second SSID with its own password, and the router prevents it reaching the main network.
What to make sure is enabled:
- Isolation from the main network: usually on by default
- Client isolation: so guests can't see each other
- Per-device speed limits: where available
Suits a small shop, salon, or office with fewer than ten operational devices.
Level 2, Two separate routers
One internet connection split across two routers: one serving operations, one serving guests. Neither connects to the other.
The arrangement:
- The provider's modem runs in bridge mode
- A simple switch splits the connection
- Router A handles the till, CCTV, and office computers
- Router B handles guest Wi-Fi
The separation is genuinely physical, so no configuration error can bring them together. The drawback: bandwidth can't be shared intelligently, and management happens in two places.
Suits a small café wanting firm separation without learning VLANs.
Level 3, VLANs
VLANs separate networks logically over the same physical equipment. One switch and one set of access points can serve several mutually isolated networks.
A common split for business premises:
| VLAN | Contents | Internet access | Inter-VLAN access |
|---|---|---|---|
| 10, Operations | Till, office computers, printers | Yes | Limited |
| 20, Surveillance | CCTV, recorders | Limited | No |
| 30, Guest | Visitor Wi-Fi | Yes | No |
| 40, Smart devices | Lights, air conditioning, speakers | Limited | No |
What you need: a VLAN-capable router, a managed switch, and access points that can map SSIDs to VLANs. Entry-level equipment from several networking brands already does this at a price reasonable for a small business.
A special note on CCTV
Security cameras deserve the strictest treatment, for three reasons:
- Their firmware is rarely updated, and often no longer supported by the manufacturer
- Many of their default passwords circulate openly on the internet
- Their contents are sensitive, footage of business premises and visitors' faces
Ideally, cameras should only talk to their recorder and have no internet access at all. If you need to view them remotely, that access should go through a VPN into the business network rather than opening camera ports to the internet.
CCTV footage is personal data. Visitors' recorded faces fall within the scope of Law No. 27 of 2022. Post visible notice that the area is under camera surveillance, set a retention period for footage, and limit who can access it.
Adding a captive portal
Once the guest network is separated, you can add a portal page in front of it. Beyond brand identity, a portal gives you somewhere to display terms of use and a privacy policy.
If the portal collects visitor data, data protection obligations apply. Ask only for what you need, separate marketing consent from usage consent, and provide a way to withdraw it. How portals work is in the captive portal guide, while the compliance side is covered in the guide to the Personal Data Protection Law.
Steps you can take this week
If everything is currently combined, these three steps close most of the risk without buying new equipment:
- Enable the guest network on your existing router, with client isolation on.
- Move all guest devices to it, and change the main network password so no guest still holds it.
- Change the default passwords on security cameras, printers, and the router's admin page.
The third step is the one most often skipped, and the one with the biggest impact. Network separation doesn't help much when the devices inside still use the password printed in the manual.
Frequently asked questions
Is the "guest network" feature on a home router enough?
For a very small business with few operational devices, usually yes. It separates guests from the main network and normally includes client isolation. Its limits are the router's capacity and the absence of finer control.
What is client isolation and why does it matter?
Client isolation stops guest devices seeing each other within the same network. Without it, someone could scan for other guest devices and try to access them. This feature should be enabled on any guest network.
Do VLANs require expensive equipment?
Not necessarily. Several entry-level business-class access points already support multiple SSIDs on different VLANs. What you additionally need is a VLAN-capable switch and a router that can route between VLANs.
Does CCTV really need separating?
Yes. Security cameras are among the devices with the least frequently updated firmware and the most commonly untouched default passwords. Putting them on the same network as guests means opening your footage to anyone sitting in your café.