Guest Wi-Fi is still your network
The visitor network gets set up in ten minutes and forgotten for five years. Meanwhile contractors, personal phones and the odd device nobody can identify end up on it, and it is often closer to the business systems than anyone realises.
Every business has a guest network, and in most of them it was the fastest piece of networking ever done. A second wireless name, a password on a card at reception, and it works. Then it is left alone, because nobody complains about the guest Wi-Fi until it stops.
The trouble is that “guest” describes who it was built for, not who uses it.
Who is actually on it
Staff personal phones. Nearly all of them, because the guest password is easier to get than the corporate one.
Contractors. Including the ones who are on site for months, plugging in laptops that belong to another company and are managed by nobody you know.
Devices somebody needed working. The smart TV in the meeting room, the coffee machine that reports its maintenance, the building controller the HVAC firm installed. These tend to arrive on the guest network because it was the one without friction, and then stay there permanently.
Occasionally, a laptop that belongs on the corporate network. Moved across during an outage as a temporary fix, and never moved back.
None of that is malicious. All of it means the network you think of as untrusted and separate is carrying more than you intended.
Where it goes wrong
It is not actually separate. A different wireless name is not a separate network. If the guest traffic lands in the same address range as the office, or the firewall between them allows more than internet access, a guest can reach things they should never see: printers, file shares, the camera recorder, management pages for network equipment.
Devices can see each other. On a well built guest network, one guest device cannot talk to another. On most default setups, they can, which is how one compromised phone becomes a scan of every other device on the network.
The password never changes. It has been printed, photographed and shared for years. Former staff, former contractors and the business next door may all still have it.
Nobody can say what is connected. Ask for a list of devices on the guest network right now and most businesses cannot produce one, let alone explain each entry.
What a sensible setup looks like
Genuinely isolated. Guest traffic in its own segment, allowed out to the internet and nowhere else. Test it rather than trusting the configuration screen: join as a guest and try to reach something internal.
Client isolation turned on, so guest devices cannot see each other.
A separate network for devices. The TV, the coffee machine and the building controller are not guests. They are equipment you do not fully control, and they belong on their own segment with only the access they need.
Contractors treated deliberately. Short term visitors can use guest access. Contractors who need internal systems should get specific, time limited access that is removed when the work ends, not the guest password plus a favour.
A rotating password, or better, individual codes that expire, so access ends when the visit does.
Sensible limits. Bandwidth caps so one large download does not affect the business, and basic filtering if your brand is attached to what happens on the network.
Why we do both
Networks and security are usually sold separately and treated separately, and the guest network is where that shows. It is a networking job to build, and a security question about whether it does what everyone assumes. A short review usually settles it: what is connected, what it can reach, and whether the separation holds when you actually test it.