Multiple networks with VLANs on the same switch is actually pretty secure. Even with physical access, use MAC based ACLs. For wireless this is wholely insecure. For wired, it is actually rather secure, unless someone is going to take the time and effort to log in to the device in question locally to yank the MAC from the NIC.
I'd leave DHCP in place and use MAC based ACLs on each port if you think your kids are going to get up to extra shennanigans.
Personally I plan on VLANs, but probably no ACLs down the road. In part to segment out their regular computers for security reasons (not so much to prevent their access to normal resources) along with a better router, so that I can push either their entire VLAN, or do it by IP to push their connections over VPN (because, I love them...but I know how I was at that age...reasonably cautious, but damned if I want their "shenanagans" spilling over. A hint of anonymity on the source is not a terrible thing. Ease enough to say "don't torrent things", harder to enforce without an iron fist).