You don’t really want to add a router into the mix and keep the one hub in my opinion because:
- It would be redundant if the router you add is an all in one with a modem too
- Even if it doesn’t have a modem built in, you are introducing double NAT for no good reason
- Add another routing device on your network and you add latency (albeit probably negligible)
- You just add potential for issues that could be hard to trace in the future e.g. you end up with two DHCP servers by accident
I personally think a blanket wide network VPN is a bad idea. You’d get more “protection” from nasties on the families machines by implementing something like a PiHole with a good blocklist of nasty places. After a lot of tuning my PiHole blocks over one million domains and on a few occasions has stopped the family’s machines from loading a nasty link in an email. Then you could use quad 9 DNS servers as your upstream DNS servers and have a decent level of network wide protection. Plus things like iPlayer and online banking will still work which sometimes stops doing so behind a VPN.