

A router provided by an ISP is not your hardware, thus any network behind it is by definition not controlled by you. There have been numerous cases where they have backdoors or known admin passwords. In cases where there is a wire type transition (for example incoming over coax or fiber) it might be necessary to use it though. Same if it is necessary due to your contract.
In my cases I always turn off the wireless antennas and switch it to bridge mode, then place my own router/firewall device behind it.
Edit: still learning to spell.
We all go our own ways. Over the later years I’ve added features and with it the inevitable complexity. Self-hosting my own data has made my care more about what goes on in my network. I am not quite at the stage of adding VLAN’s but it will probably come.