Guest WiFi Security for South African Venues
For café, restaurant and guest house owners: what really goes wrong on venue WiFi, and the fixes you can do yourself this week for nothing.
Most guest WiFi in South African venues was set up once, on the day the line was installed, by whoever happened to be holding the router. It has worked ever since, in the sense that guests get online and nobody complains. So nobody touches it.
This is a guide to what is quietly wrong with that arrangement, written for the person who runs the venue rather than for an IT person. Most of the fixes cost nothing and do not involve buying anything from us. We have put those first on purpose.
What actually goes wrong
Forget hackers in hoodies. The real problems are ordinary and boring, which is exactly why they last for years.
One flat network
On a standard router there is one network, and everything joins it: the card machine, the point-of-sale terminal, the office PC with the accounting software on it, the camera recorder, the printer, and every guest phone that walks through the door. All of it sits together on one network. Nobody planned it that way. It is simply the default, and defaults stick.
The risk is not that a guest decides to attack you. It is that somebody’s phone or laptop is already infected, and the software on it looks around the network on its own, finds a device that still has its factory password, and settles in. That is how small businesses end up locked out of their own systems.
The password walks out
A WiFi password on a chalkboard or a laminated card at the till never changes, because changing it means re-telling every regular in the suburb. So it gets photographed, forwarded, saved permanently on hundreds of phones, and remembered by every person who has ever worked a shift for you. After a year or two it is effectively public.
No record of anything
If a guest complains, or the Information Regulator asks how you handle personal information, you need to be able to say what a guest was shown and what they agreed to. With a shared password there is nothing: no terms, no consent, no session record. You are still processing personal information the moment a device joins your network, you just have no paperwork for it. Our POPIA guide goes through what that actually requires.
One device flattens the line
Without a limit per device, one long download or one afternoon of high-definition video takes the whole connection. The owner phones the internet provider, the provider tests the line and finds nothing wrong, and everyone is annoyed.
Somebody borrows your name
Anyone can broadcast a WiFi network named after your venue from a phone in the corner of the room, and hope people join it. No venue can stop that from happening, and anyone who tells you they can detect it for a small monthly fee is selling you something. What helps is much simpler: if your guests always see the same branded login page, a screen that looks wrong is easier for them to notice.
What you can do yourself, this week, for nothing
Work down this list in order. If you only do the first two, you have removed most of the real risk.
1. Get the till off the guest network
This is the single most valuable thing on the page. Your card machine, point-of-sale terminal, office PC and camera recorder should be on a different network from the one you hand to the public. Most business routers can do this: a second network name for guests, kept apart from the business one, with a rule that stops traffic crossing between them.
A quick test you can run yourself: join the guest WiFi on your own phone, then try to open your camera recorder or your office printer from it. If it opens, the two networks are not separated.
2. Change the router’s default password
Routers, camera recorders and network printers arrive with a factory login that is printed in the manual and known to everyone. If nobody has changed yours since installation, change it now, and use something long that is not the venue name. Store it in a password manager or somewhere sensible, not on a sticky note on the router.
While you are there, do the same for the camera recorder. It is the device most often forgotten and the one holding the most sensitive material.
3. Never give customers the business WiFi password
The password your staff use for the till and the office is not the password you write on a chalkboard. If those are currently the same, you do not have a guest network at all. Separate them, and treat the guest network as a public space from then on.
4. Tell staff the guest network is public
A guest network is a public space, in your venue exactly as at an airport or a shopping centre. That is why nothing belonging to the business should sit on it. A staff laptop that “just needed WiFi for five minutes” is how a business device ends up on the public side.
5. Keep the router’s software up to date
The software running on your router receives security updates. If nobody has logged in since installation, it is running whatever it shipped with. Ask whoever installed it to check it, or make it a task for whoever looks after your equipment.
6. Write down your privacy notice
If you collect names, email addresses or cell numbers from guests, you need to tell them what you collect it for, get their agreement before you collect it, and keep only what you actually use. A short, honest privacy notice on your website and a tick box at sign-up covers most of what a small venue needs.
Where a managed portal fits
Everything above is worth doing whether or not you ever pay anyone. A managed captive portal takes some of it off your desk permanently, and it is honest to be specific about which parts.
- It removes the shared password. Guests connect through a login page instead, so there is nothing written on the wall to leak, and you change the rules without re-telling every regular.
- It builds the guest side separately. The standard network we build puts guests on their own network, kept separate from the network we install for you.
- It gives you a record. Your terms and a POPIA-aware consent line sit on the login step, with a session record behind it: which device, when, and how much data.
- It sets a limit per guest. Time and bandwidth limits per access tier, enforced at the router, so one table cannot flatten the room.
- It puts your name on the screen. Which is the part most owners actually enjoy, and the part that makes an imitation easier for a regular to spot.
And two things it does not do, because you should hear them from us rather than from a competitor. The guest network has no WiFi password, on purpose, so that the login page can appear at all. That means guest traffic is not encrypted at the WiFi layer, the same as at any public hotspot, while the sites your guests use over HTTPS stay encrypted end to end. And we do not inspect or block what guests look at. We log connection details, not content, which is a deliberate privacy position and is written into our acceptable usage policy.
The short version
- The biggest risk in a venue is one flat network with the till and the guests on it. Split it.
- The second biggest is a factory password nobody has changed. Change it.
- A chalkboard password is public within a year, and gives you no record of what anyone agreed to.
- Nobody can stop a stranger imitating your network name, but a login page your regulars recognise helps.
- A managed portal is the tidy version of all of this, and worth it for the guest list and the branding as much as for the safety.
Want a second opinion on your venue’s setup? We will walk through it with you and tell you what we find, with nothing to sign. Talk to us. Support runs Monday to Friday, 08:00 to 17:00 SAST.