Also take the router off the default IP. It's a step that can be defeated with an IPCONFIG command, but if I was hacking into a router and saw that the user knew how to change the default IP from 192.168.x.x I would assume they also know how to change the default password and move along to the next one.