Sharing your wifi password safely with guests or colleagues
The wifi password paradox
Wifi passwords occupy an odd position in most people's mental model of security. They know passwords should be kept private, but a wifi password feels different — it's for a network you're inviting people onto, so surely it's fine to just tell everyone.
In a home context, this is mostly true. In a business context, it's more complicated. And in both contexts, how you share the password matters.
Why the business wifi password deserves more thought
Your office or workplace network may connect to more than just the internet. Internal servers, network-attached storage, printers, IoT devices, and other networked assets may be accessible from the local network. A guest on your wifi network is, depending on your network configuration, potentially a guest on your entire internal network.
Many small businesses and even larger ones run a flat network where all devices — staff laptops, the server in the corner, the network printer — are on the same subnet. A visitor with your wifi password and basic network scanning skills can see all of those devices. This is not necessarily a catastrophic risk, but it's a risk that deserves management.
Guest network vs. staff network
The most important step is separation: a dedicated guest network that has internet access but is isolated from internal resources, and a separate staff network that connects to internal systems. Most modern routers and access points support this configuration.
With a guest network, you can share the password freely — guests can only reach the internet. The staff network password should be treated like any other organisational credential.
How to share wifi passwords securely
For guests (coffee shop, office visitors, clients) A guest network password can be shared via a QR code (most modern phones can join a network by scanning a QR code), a printed card in the meeting room, or — if it needs to be sent digitally — a one-time link via PassTransfer. The latter is particularly useful if you want to ensure the password isn't forwarded or stored in multiple places.
For new staff joining the network Treat the staff wifi credential like any other onboarding credential. Send it via a secure one-time link, not in a welcome email. If the network password changes periodically (good practice), use the same secure delivery method for the updated credential.
For remote sites or contractors who need temporary access Consider creating a temporary network key that you can revoke after use, rather than giving out the permanent staff password. If your router doesn't support this, share the real password via a one-time link and rotate it after the temporary access period ends.
Rotating wifi passwords
How often you should change your wifi password depends on your risk profile, but common triggers include:
- When someone who knew the password leaves the organisation
- After a security incident on the network
- When you discover a device you don't recognise connected to the network
- As part of a regular rotation cycle (annually at minimum for staff networks)
When you rotate, notify current staff via a secure channel — a one-time link works well here too.
The overlooked risk: written passwords
The most common way wifi passwords are shared in offices is the sticky note on the router, the whiteboard in the meeting room, or the laminated card on the reception desk. These work fine for a guest network. They're a poor choice for a staff network, because they're visible to anyone who walks past — delivery personnel, building maintenance, visitors.
Conclusion
Wifi passwords deserve more thought than they typically get in a business context. Separation of guest and staff networks reduces risk significantly. For any network that connects to internal resources, treat the password as a proper credential — share it via a secure one-time link, track who has it, and rotate it regularly.