Most people still shop for smart home devices one box at a time: a camera here, a smart lock there, a speaker as a gift. Each purchase makes sense on its own. But the moment you connect the third device, something changes that almost no retailer explains: you are no longer buying gadgets. You are building a network—a small, permanently connected network with a front door (your router), a growing list of tenants (every device), and no landlord performing maintenance.
That mental shift is the difference between a smart home that quietly improves your life and one that quietly becomes the softest target in it. The good news is that the security playbook for a smart home is neither expensive nor particularly technical. It is mostly about making deliberate decisions at purchase time and spending thirty minutes on configuration once a year. This guide covers both: how to buy cameras, locks, speakers, and hubs with security in mind, and how to secure the network they all share.
What is actually changing
The average connected household now runs far more than a router and a laptop. Security cameras, video doorbells, smart locks, speakers, displays, plugs, bulbs, thermostats, robot vacuums, and hubs routinely coexist on the same Wi-Fi network. The numbers tell the story: connected devices per household have grown steadily for a decade, and the mix has shifted from novelty gadgets to devices that hold keys, record audio and video, and make decisions about your home's physical access.
Three forces are reshaping this market in 2026. First, Matter—the interoperability standard backed by Apple, Google, Amazon, and Samsung—has made cross-ecosystem setups genuinely practical, with local operation as a core design principle. Second, on-device AI has moved into consumer cameras and speakers: person detection, package classification, and voice processing increasingly happen locally rather than in the cloud. Third, regulation is finally arriving: the United Kingdom's Product Security and Telecommunications Infrastructure (PSTI) regime banned default passwords on connected products in 2024, the European Union's Cyber Resilience Act entered into force in December 2024 with obligations phasing in through 2026 and 2027, and California's SB 327 has required reasonable security features in connected devices since 2020.
None of these forces makes a smart home secure by itself. They make it possible to secure one—and they make the remaining gaps (network configuration, account hygiene, update discipline) the place where the actual risk lives.
Why this matters to three different audiences
Smart home security is not just a consumer topic. It touches the same decision-makers the way every technology trend does—through risk, economics, and operational responsibility.
For households and buyers
Your home network now carries your keys, your video footage, and your conversations. A compromised camera is not an abstract breach: it is someone watching your driveway or your living room. A compromised lock account can undo the physical security your front door provides. The purchasing decisions you make this year—which brands, which protocols, which features require cloud accounts—determine your exposure for the five-to-ten-year life of the devices.
For technology leaders
The smart home is where most employees' security habits are formed, and increasingly where work happens. Remote workers carry corporate data onto home networks that administrators do not control and cannot see. Every corporate-issued laptop that joins a home Wi-Fi network with ten unpatched IoT devices is, in effect, joining a network you did not design. Leaders who understand the consumer IoT landscape can set realistic remote-work policy, choose equipment for their own homes with security defaults in mind, and anticipate the consumer-grade devices that will inevitably appear on corporate networks anyway.
For security professionals
Consumer IoT is the training ground for the threat models you will face at work: default credentials, cloud-account takeover, insecure firmware update channels, and devices that phone home to vendors you do not control. The Mirai botnet, which weaponized default credentials on cameras and routers in 2016, remains the canonical example of what an unsecured IoT fleet becomes. The same failure modes recur in enterprise IoT, medical devices, and building automation. Understanding how to segment and secure a home network is not a hobby—it is the smallest possible version of a real infrastructure problem.
Every smart home device is a computer with a microphone, a camera, or a network connection—usually at least two of the three—and the only thing standing between it and the internet is the configuration you never set up.
The technical reality beneath the trend
To buy and secure a smart home intelligently, you need a working model of how these devices connect. There are three relevant layers: the network protocol, the control model, and the account model.
Network protocols
Wi-Fi remains the most common connection for cameras, speakers, and displays—convenient, high-bandwidth, and the reason every Wi-Fi device shares your network. Zigbee and Z-Wave are mature low-power mesh protocols that have powered sensors, locks, and bulbs for years; they need a hub or a dongle, and they operate on their own radio frequencies, which means a Zigbee lock does not sit on your Wi-Fi network even though its hub does. Thread is the newer low-power mesh protocol, designed alongside Matter, with border routers built into modern hubs, speakers, and some routers to bridge Thread devices onto the local network. Matter itself runs over Wi-Fi, Thread, or Ethernet and is fundamentally a local-control standard: devices in the same house can talk to each other and to local controllers without a cloud round trip.
The practical consequence: devices that support Matter and Thread can keep working, and keep being controllable, when your internet connection drops. Cloud-only devices cannot. That single difference—local control—matters more for reliability and privacy than almost any feature on the box.
The control model: hub, app, or both
Some devices require a physical hub (Zigbee/Z-Wave ecosystems, Thread border routers); some run through a vendor app and cloud service; some can be controlled locally through a hub like Apple Home, Google Home, or Home Assistant. The trend is toward hybrid: local control for core functions, cloud for remote access and advanced features. The security-relevant question is not which model you prefer, but which one the device requires. A camera that requires cloud processing of every frame exposes more of your life to a vendor's servers than one that processes locally and streams only when you watch. Prefer devices where the sensitive functions can run locally, and treat the cloud as an optional convenience rather than a requirement.
The account model
Every cloud-connected device is ultimately an account. The camera you installed in your hallway is attached to an email address, a password, and—if you enabled it—two-factor authentication. Account takeover is the single most common way attackers reach smart home devices: not by hacking the hardware, but by reusing a password that leaked in a breach on a completely different service. This is why the account layer deserves the same attention as the device layer.
How to buy: a decision framework, not a brand ranking
The market changes too fast for durable brand recommendations, and the right choice depends on your ecosystem, your threat model, and your budget. What follows is a set of decision criteria that will remain valid regardless of which brand wins or loses next year.
| Device | Buy for | Security red flags | Worth paying more for |
|---|---|---|---|
| Cameras & doorbells | On-device detection (person, package, vehicle), local recording or a recording service you trust, clear retention settings | Cloud-only processing with no local mode, cameras that require a monthly subscription for basic security features, no MFA on the app | Local AI detection, local storage or end-to-end-encrypted cloud, standard support for HomeKit Secure Video / Matter |
| Smart locks | Physical fallback that always works (key, thumb turn), offline access codes, clear audit log | Locks that become unusable if the vendor's cloud dies, auto-unlock based only on geofencing, no manual override | Local control via Thread/Matter, tamper alarms, codes you can revoke remotely without cloud dependency |
| Speakers & displays | Wake-word processing that is local (stated by vendor), mute switch that cuts the microphone, visible privacy indicator | Devices that require always-on cloud for basic assistant functions, no physical mute, unknown data-retention practices | Local voice processing, Matter controller capability (useful hub), long update commitment |
| Hubs & bridges | Protocol support (Thread, Zigbee, Z-Wave), local-first architecture, Home Assistant or open ecosystems if you are technical | Proprietary hubs with no local API, mandatory vendor cloud for automation | Thread border router, local automation engine, open documentation |
Two general rules apply across every category. First, ask for the update commitment in writing: how long will this device receive security firmware updates? The UK PSTI regime now requires manufacturers to declare a minimum support period, and several vendors state it on the box or the product page. If a manufacturer cannot tell you how long the device will be patched, assume it will be abandoned the moment the next model ships. Second, prefer devices that work without a mandatory cloud account for their core function. The lock should unlock, the camera should record, the bulb should turn on—even if the vendor's cloud is down or the company disappears.
How to secure what you already own
Most of the risk in an existing smart home is configuration, not hardware. The following sequence takes about thirty minutes and covers the overwhelming majority of realistic attacks.
1. Fix the network perimeter first
- Log into your router and change the administrator password to something unique. The default admin password is the single most common smart-home vulnerability.
- Enable WPA3 if supported (WPA2-AES otherwise) and disable WPS, which is a well-known brute-force vector.
- Disable remote administration of the router unless you genuinely need it, and if you do, require a VPN first.
- Apply router firmware updates—the router is the one device that can protect all the others, and it is usually the least updated.
2. Segment the network
This is the highest-impact improvement available. If your router has a guest network, put every IoT device on it and keep your phones and computers on the main network. Guest networks typically isolate clients from each other and from the main LAN, which is exactly the property you want. If you have prosumer or open-source gear (Ubiquiti, TP-Link Omada, OpenWrt, pfSense), create a dedicated IoT VLAN with firewall rules that allow IoT devices to reach the internet (for updates) but block them from reaching your main network except for the specific local services they need—typically mDNS/SSDP discovery and the hub itself.
For a typical segmented setup, the rule set is small: allow established connections from IoT to the internet; allow the hub/controller on the main network to reach IoT management ports; block everything else. A common gotcha: casting and some local control use mDNS (port 5353) and IGMP, so you must permit those between the IoT segment and the main segment or your speakers and displays will mysteriously stop being discoverable.
3. Fix the account layer
- Use a unique password for every smart home account—camera apps, lock apps, assistant accounts, hub accounts. A password manager makes this painless.
- Enable two-factor authentication on every account that can control a lock or a camera. This is non-negotiable for anything with a door or a lens.
- Review third-party integrations: every "connect your camera to this service" grant is an additional account that can be compromised.
- Use aliases or app passwords where vendors force you to log in with an email; never reuse the password from your primary email account.
4. Update everything, then schedule updates
- Update the firmware of every device now, and enable automatic updates where available.
- Remove devices that no longer receive updates from sensitive positions. An unpatched camera or hub is a liability you are paying to host; retire it from the network, or at minimum isolate it completely and stop pointing it at your living space.
- Set a quarterly reminder to check for updates and review which devices are connected to your Wi-Fi. Your router's client list is your inventory.
5. Reduce the exposure you cannot patch
- Position cameras and speakers with the assumption that they can be accessed: no bedroom cameras, no always-on microphones in private rooms.
- Disable features you do not use—remote access, cloud recording, auto-unlock, voice purchasing—rather than leaving them enabled "just in case."
- Check app permissions: a smart home app rarely needs your contacts, location history, or photo library.
- If a device has a physical microphone or camera mute, use it when the device is in sensitive rooms.
AI in the smart home: the new layer to assess
AI has quietly become the differentiator in consumer IoT, and it cuts both ways. On the positive side, on-device AI is a privacy win: a camera that classifies "person" or "package" locally—using a neural network on its own chip—never uploads the frames used for that decision. Voice assistants increasingly process wake words and even full requests locally, which shrinks the amount of your speech that transits a vendor cloud. This is a genuine architectural improvement over the early cloud-everything era, and buyers should reward it.
On the negative side, AI adds a new attack surface. Local models are software like any other: they need updates, and a compromised model or AI feature can misclassify events, disable detection to hide activity, or exfiltrate data through new telemetry channels. Prompt-injection-style attacks—where malicious content in the physical world or in transmitted audio steers an AI feature's behavior—are an emerging research area, not a settled threat, but the principle from enterprise AI applies at home too: the more a device can do autonomously, the more carefully you should control what it can access and what it can act on.
The buying implication is simple: prefer on-device AI, but treat it as software. It is an upgrade when the vendor updates it and a liability when the vendor abandons it. The update commitment you demanded for the hardware applies with equal force to the AI features inside it.
Regulatory context: the floor is rising
It is worth knowing where the regulatory baseline now stands, because it changes what "secure" means when you shop.
- UK PSTI regime (in force April 2024): internet-connected products sold in the UK must not ship with universal default passwords, must publish a vulnerability-disclosure policy, and must state a minimum support period. This is the first major national regime to make these practices mandatory rather than aspirational.
- EU Cyber Resilience Act (in force December 2024; obligations phasing in 2026–2027): connected products sold in the EU will face security-by-design requirements, vulnerability-handling obligations, and reporting duties for actively exploited vulnerabilities. The full obligations apply progressively, with the first reporting duties arriving in 2026.
- California SB 327 (since 2020): requires connected devices to be equipped with reasonable security features, with unique-per-device passwords as the canonical example.
These regimes do not make a specific product secure, and compliance is not a guarantee—but they raise the floor for the worst offenders and give buyers a legitimate question to ask: "What is the minimum support period, and where is your vulnerability disclosure policy?" A vendor that answers clearly is making a different kind of product than one that does not.
What happens next
Three developments are worth watching over the next two years.
First, the local-first architecture will win. Matter, Thread, and local AI are not separate trends; they are the same trend—control and processing moving back into the home. The products that survive the next market cycle will be the ones whose core functions do not depend on a vendor cloud. This is good for security and good for consumers, and it will quietly become the default expectation rather than a premium feature.
Second, update support will become a disclosed specification, like screen size or battery life. The PSTI minimum-support-period declaration and the CRA's support obligations are forcing what consumers always needed: a way to compare how long a device will be maintained. Expect product pages to start advertising "5 years of security updates" the way phones advertise cameras.
Third, the home network will become a managed asset. The rise of mesh systems with built-in security features, ISP-provided secure routers, and consumer VLANs reflects a market realizing that the network is the security boundary. In the same way that homeowners learned to change furnace filters and test smoke detectors, households will learn to segment networks and rotate device credentials—because the alternative, an unmanaged network of twenty computers with cameras and microphones, is not a viable long-term position.
The smart home is not a collection of gadgets. It is the first network most people will ever operate—and the most important one, because it is the one their family lives inside. Buying deliberately, segmenting the network, and maintaining the account layer are not chores. They are the difference between a home that uses technology and a home that is defined by its vulnerabilities.
Official references
- Connectivity Standards Alliance — Matter — the interoperability standard and its local-operation design.
- Thread Group — the low-power mesh protocol behind Thread border routers.
- UK Product Security and Telecommunications Infrastructure Act 2022 — the PSTI regime, including the default-password ban and minimum support period.
- EU Cyber Resilience Act — European Commission — the regulatory framework for connected products.
- California SB 327 — Connected Devices — the first US state IoT security law.
- NIST cybersecurity resources — including IoT device cybersecurity baselines and guidance.
Frequently asked questions
What is the safest way to set up a smart home?
Start with the network, not the gadgets. Change the router admin password, enable WPA3, disable WPS and remote administration, and put IoT devices on a separate network or guest network if your router supports it. Then change every device's default password to a unique one, enable two-factor authentication on the accounts that manage your devices, and keep firmware updates on. The single most common failure is not the device—it is leaving the default credentials and default network configuration in place.
Do smart cameras and speakers actually listen to everything?
No, in normal operation they do not record or transmit continuously. Smart speakers listen for a wake word locally and begin streaming only after they detect it; cameras record when triggered, on a schedule, or continuously depending on your settings. The real risks are elsewhere: cloud accounts that can be hijacked, microphones and cameras that can be accessed after a compromise, and apps with overbroad permissions. Treat every connected device as a potential microphone and camera, position them accordingly, and review which devices have cloud accounts at all.
What does Matter mean for smart home security?
Matter is a connectivity standard backed by Apple, Google, Amazon, and Samsung that lets devices from different ecosystems work together locally, over Wi-Fi, Thread, or Ethernet, with no cloud bridge required for core operation. For security this is mostly positive: it reduces vendor lock-in, standardizes device onboarding with secure pairing, and enables local control that continues working without internet. It does not remove the need for firmware updates, strong accounts, or network segmentation—it improves the baseline, it does not guarantee it.
Do I need a separate network for my smart home devices?
It is the single highest-impact improvement most households can make. A separate IoT network—a dedicated SSID, a guest network, or a VLAN on prosumer gear—limits what a compromised camera or speaker can reach: no direct path to your computers, phones, or network storage. Most modern routers offer at least a guest network, and mid-range and prosumer routers add VLAN or network-isolation features. If you cannot segment, at minimum disable unnecessary features, use unique passwords, and keep firmware updated.
Securing your home—or your workforce's homes?
Null Session Intelligence helps organizations assess IoT and remote-work risk, design network segmentation, and audit consumer-grade technology exposure.
Discuss your situation