Just over one in four Canadian businesses had written cyber security policies in place in 2023, the same share as two years earlier, according to Statistics Canada. A guest Wi-Fi policy for Langley small businesses is usually part of what is missing, even in offices where the network itself was built properly.
The gap is rarely technical. The equipment in most Langley offices already separates visitor traffic from the systems that matter. What goes unmanaged is the human side: who gets the password, how long they keep it, and who is supposed to notice.
The network was set up correctly. Then four years happened.
Most offices did the sensible thing when the current router went in. Someone created a separate guest network, chose a password, and wrote it on a card for the front desk. That was the right call, and it has not been revisited since.
Everything around that decision changed. Staff came and went. Trades worked on site for a month at a time. The password migrated from a card to a whiteboard to a sticky note on the reception monitor, and it never rotated.
A guest network is an access-control system whether you manage it as one or not. The hardware keeps doing precisely what it was configured to do. The open question is who holds the credential today, and in most offices nobody owns that question.
Who is on your guest network right now
- Clients and vendors waiting in reception
- Trades and contractors from a project that wrapped last spring
- Candidates who interviewed and were not hired
- Personal phones, tablets, and smartwatches belonging to staff
- Delivery and service reps who asked once and never forgot
- Former employees whose devices still have the credential saved
None of those people were vetted for network access, and most were never meant to keep it. Wi-Fi does not respect your lease line either. The signal reaches the parking lot, the unit next door, and the sidewalk out front.
Separating the network is a setup task. Managing access is not.
The Canadian Centre for Cyber Security treats guest networks as a genuine protection for your primary network, not a courtesy for visitors. Its guidance is specific, and most of it belongs to the installation:
- Give the guest network a password of its own, changed from the factory default
- Isolate guest traffic so it cannot interact with devices on the primary network
- Run WPA2 or WPA3 encryption on the wireless connection
- Keep the router and anything sitting on the guest network patched
- Apply web filtering to control what the connection can reach
Most local providers handle the bulk of that list during setup, and a competent installation covers it without being asked. These are configuration items, done once and rarely touched again.
Two further recommendations from the Cyber Centre get skipped almost everywhere. Monitor which devices are connected to the guest network. Limit the period that guest credentials stay usable, with a defined start and end for new devices.
Neither of those is a setting you switch on and forget. Both need a person, a schedule, and a rule about who decides. That is the work a guest Wi-Fi policy for Langley small businesses exists to carry.
What the policy actually has to answer
A single page covers it. The value is not the document itself but the decisions it forces, because each one is currently being made by whoever happens to be at the front desk that afternoon.
- Who can grant guest access, and who approves anything unusual
- How long a credential stays valid before it is rotated
- Where the credential may be displayed, and where it may not
- Whether staff personal devices belong on guest, on the corporate network, or on neither
- What gets logged, how long it is kept, and who reviews it
- Who covers the process when the usual person is on holiday
Training matters as much as the rules. Only 22 percent of Canadian businesses provided formal cyber security training to their non-technical employees in 2023. A policy that lives in a binder and never reaches reception is not a control, since reception is where every access decision is made.
The devices you stopped noticing are guests too
Guest networks are not only for people. The Cyber Centre recommends connecting internet-connected devices such as smart displays and sensors to a guest network, keeping them away from the systems that hold your files. Many of these devices need the internet to function but have no business touching your file server.
Think about what has quietly joined your network since the router went in. A boardroom display. Security cameras. A smart thermostat.
There may be a shipping scale in the back and a label printer nobody has updated since it arrived. Devices that no longer receive patches belong on the separated network, where a compromise stays contained.
There is a related risk worth naming. When coverage is poor in one corner of the office, someone eventually plugs in their own wireless access point to fix it. The Cyber Centre flags these unsanctioned access points as a real exposure, because they are configured without oversight and can open a path straight into the corporate network.
Handing out access without handing over the office
Rotation is where most policies die. Changing the guest password means telling everyone the new one, and that friction is why the old one survives for years. The way around it is to stop treating the credential as something people memorize.
- A printed card at reception, replaced on a set date, so the current credential has one home
- A QR code guests scan, reprinted whenever the passphrase changes
- A captive portal that issues time-limited access and expires it automatically
- Separate day codes for trades and contractors working on site
- A short standing item on a monthly checklist so rotation is somebody's job
Most business-grade equipment already supports at least one of these. The barrier is rarely the hardware. It is that no one has decided which approach fits the office, and a guest Wi-Fi policy for Langley small businesses is where that decision gets recorded and kept.
Contractor access deserves its own line in the policy. Construction and trades firms across the Fraser Valley host site crews, inspectors, and subtrades for weeks at a time. Those visitors need connectivity, and they should not still have it in November.
Privacy obligations do not stop at the reception desk
Under PIPEDA, personal information must be protected by safeguards appropriate to how sensitive it is. The Office of the Privacy Commissioner lists developing and implementing a security policy as the first step in meeting that responsibility. Limiting access, training staff, and reviewing safeguards regularly appear on the same list.
That language lands differently once you picture your own environment. A law firm in Langley holds client files. An accounting practice holds financial records. A construction company holds employee information, subcontractor agreements, and drawings covered by client confidentiality terms.
If guest traffic is properly isolated, none of that is within reach of a visitor's laptop. If it is not, the separation protecting that information is a shared word that half the Fraser Valley has typed at some point. Regulators assess what you had in place beforehand, not what you intended to get around to.
Statistics Canada found that 59 percent of businesses carried out activities to identify cyber security risks in 2023, a figure that has barely moved since 2019. Guest access is one of the easier risks to identify and one of the cheapest to close.
What to check this quarter
None of this requires new hardware in most offices. It requires an hour and a decision, and it is the kind of review that should run on a schedule rather than after an incident.
- Confirm guest traffic cannot reach servers, shared printers, or staff workstations
- Change the guest credential now and set a rotation interval you will keep
- Remove the password from anything visible through a window or across a lobby counter
- Review the list of connected devices and clear anything you do not recognize
- Walk the office and look for wireless access points nobody authorized
Half of Canadian businesses reported having cyber security employees in 2023, down from 61 percent in 2021. Among those without them, 47 percent said they rely on consultants or contractors to monitor cyber security instead. If that describes your office, guest network hygiene is a fair thing to raise at your next review, because it tends to fall between the provider's scope and the front desk's.
The unglamorous control
Guest Wi-Fi never makes anyone's list of pressing technology concerns. It is not new, it is not sophisticated, and it has none of the urgency attached to ransomware headlines. That is exactly why it sits untouched for years while every other control gets attention.
The fix costs nothing but attention. A guest Wi-Fi policy for Langley small businesses comes down to four decisions: who gets access, how long it lasts, where it is written down, and when it is checked. The offices that do this are not more security-conscious than their neighbours. They simply assigned the question to someone.
Sources:
- Statistics Canada, Impact of cybercrime on Canadian businesses, 2023 (The Daily, released October 21, 2024)
- Canadian Centre for Cyber Security, Guest Wi-Fi (ITSAP.80.023)
- Canadian Centre for Cyber Security, Protecting your organization while using Wi-Fi (ITSAP.80.009)
- Office of the Privacy Commissioner of Canada, PIPEDA Fair Information Principle 7 – Safeguards