← Back to Blog
Consumer Technology

Your Smart Home Is a Network: How to Buy and Secure Cameras, Locks, Speakers, and Hubs

Jonatan M. Collymoore By Jonatan M. Collymoore • 13 min read

Smart home network security: cameras, locks, speakers, and hubs on one segmented network

Most people still shop for smart home devices one box at a time: a camera here, a smart lock there, a speaker as a gift. Each purchase makes sense on its own. But the moment you connect the third device, something changes that almost no retailer explains: you are no longer buying gadgets. You are building a network—a small, permanently connected network with a front door (your router), a growing list of tenants (every device), and no landlord performing maintenance.

That mental shift is the difference between a smart home that quietly improves your life and one that quietly becomes the softest target in it. The good news is that the security playbook for a smart home is neither expensive nor particularly technical. It is mostly about making deliberate decisions at purchase time and spending thirty minutes on configuration once a year. This guide covers both: how to buy cameras, locks, speakers, and hubs with security in mind, and how to secure the network they all share.

The bottom line: A smart home is a network, and its security is determined less by any single device than by the network it joins. Prioritize three things when buying: local control (Matter/Thread over cloud-only), a credible firmware-update commitment, and no mandatory cloud dependency for core features. Then segment your network, kill default credentials, and enable two-factor authentication on every account that can touch a lock or a camera.

What is actually changing

The average connected household now runs far more than a router and a laptop. Security cameras, video doorbells, smart locks, speakers, displays, plugs, bulbs, thermostats, robot vacuums, and hubs routinely coexist on the same Wi-Fi network. The numbers tell the story: connected devices per household have grown steadily for a decade, and the mix has shifted from novelty gadgets to devices that hold keys, record audio and video, and make decisions about your home's physical access.

Three forces are reshaping this market in 2026. First, Matter—the interoperability standard backed by Apple, Google, Amazon, and Samsung—has made cross-ecosystem setups genuinely practical, with local operation as a core design principle. Second, on-device AI has moved into consumer cameras and speakers: person detection, package classification, and voice processing increasingly happen locally rather than in the cloud. Third, regulation is finally arriving: the United Kingdom's Product Security and Telecommunications Infrastructure (PSTI) regime banned default passwords on connected products in 2024, the European Union's Cyber Resilience Act entered into force in December 2024 with obligations phasing in through 2026 and 2027, and California's SB 327 has required reasonable security features in connected devices since 2020.

None of these forces makes a smart home secure by itself. They make it possible to secure one—and they make the remaining gaps (network configuration, account hygiene, update discipline) the place where the actual risk lives.

Why this matters to three different audiences

Smart home security is not just a consumer topic. It touches the same decision-makers the way every technology trend does—through risk, economics, and operational responsibility.

For households and buyers

Your home network now carries your keys, your video footage, and your conversations. A compromised camera is not an abstract breach: it is someone watching your driveway or your living room. A compromised lock account can undo the physical security your front door provides. The purchasing decisions you make this year—which brands, which protocols, which features require cloud accounts—determine your exposure for the five-to-ten-year life of the devices.

For technology leaders

The smart home is where most employees' security habits are formed, and increasingly where work happens. Remote workers carry corporate data onto home networks that administrators do not control and cannot see. Every corporate-issued laptop that joins a home Wi-Fi network with ten unpatched IoT devices is, in effect, joining a network you did not design. Leaders who understand the consumer IoT landscape can set realistic remote-work policy, choose equipment for their own homes with security defaults in mind, and anticipate the consumer-grade devices that will inevitably appear on corporate networks anyway.

For security professionals

Consumer IoT is the training ground for the threat models you will face at work: default credentials, cloud-account takeover, insecure firmware update channels, and devices that phone home to vendors you do not control. The Mirai botnet, which weaponized default credentials on cameras and routers in 2016, remains the canonical example of what an unsecured IoT fleet becomes. The same failure modes recur in enterprise IoT, medical devices, and building automation. Understanding how to segment and secure a home network is not a hobby—it is the smallest possible version of a real infrastructure problem.

Every smart home device is a computer with a microphone, a camera, or a network connection—usually at least two of the three—and the only thing standing between it and the internet is the configuration you never set up.

The technical reality beneath the trend

To buy and secure a smart home intelligently, you need a working model of how these devices connect. There are three relevant layers: the network protocol, the control model, and the account model.

Network protocols

Wi-Fi remains the most common connection for cameras, speakers, and displays—convenient, high-bandwidth, and the reason every Wi-Fi device shares your network. Zigbee and Z-Wave are mature low-power mesh protocols that have powered sensors, locks, and bulbs for years; they need a hub or a dongle, and they operate on their own radio frequencies, which means a Zigbee lock does not sit on your Wi-Fi network even though its hub does. Thread is the newer low-power mesh protocol, designed alongside Matter, with border routers built into modern hubs, speakers, and some routers to bridge Thread devices onto the local network. Matter itself runs over Wi-Fi, Thread, or Ethernet and is fundamentally a local-control standard: devices in the same house can talk to each other and to local controllers without a cloud round trip.

The practical consequence: devices that support Matter and Thread can keep working, and keep being controllable, when your internet connection drops. Cloud-only devices cannot. That single difference—local control—matters more for reliability and privacy than almost any feature on the box.

The control model: hub, app, or both

Some devices require a physical hub (Zigbee/Z-Wave ecosystems, Thread border routers); some run through a vendor app and cloud service; some can be controlled locally through a hub like Apple Home, Google Home, or Home Assistant. The trend is toward hybrid: local control for core functions, cloud for remote access and advanced features. The security-relevant question is not which model you prefer, but which one the device requires. A camera that requires cloud processing of every frame exposes more of your life to a vendor's servers than one that processes locally and streams only when you watch. Prefer devices where the sensitive functions can run locally, and treat the cloud as an optional convenience rather than a requirement.

The account model

Every cloud-connected device is ultimately an account. The camera you installed in your hallway is attached to an email address, a password, and—if you enabled it—two-factor authentication. Account takeover is the single most common way attackers reach smart home devices: not by hacking the hardware, but by reusing a password that leaked in a breach on a completely different service. This is why the account layer deserves the same attention as the device layer.

How to buy: a decision framework, not a brand ranking

The market changes too fast for durable brand recommendations, and the right choice depends on your ecosystem, your threat model, and your budget. What follows is a set of decision criteria that will remain valid regardless of which brand wins or loses next year.

DeviceBuy forSecurity red flagsWorth paying more for
Cameras & doorbellsOn-device detection (person, package, vehicle), local recording or a recording service you trust, clear retention settingsCloud-only processing with no local mode, cameras that require a monthly subscription for basic security features, no MFA on the appLocal AI detection, local storage or end-to-end-encrypted cloud, standard support for HomeKit Secure Video / Matter
Smart locksPhysical fallback that always works (key, thumb turn), offline access codes, clear audit logLocks that become unusable if the vendor's cloud dies, auto-unlock based only on geofencing, no manual overrideLocal control via Thread/Matter, tamper alarms, codes you can revoke remotely without cloud dependency
Speakers & displaysWake-word processing that is local (stated by vendor), mute switch that cuts the microphone, visible privacy indicatorDevices that require always-on cloud for basic assistant functions, no physical mute, unknown data-retention practicesLocal voice processing, Matter controller capability (useful hub), long update commitment
Hubs & bridgesProtocol support (Thread, Zigbee, Z-Wave), local-first architecture, Home Assistant or open ecosystems if you are technicalProprietary hubs with no local API, mandatory vendor cloud for automationThread border router, local automation engine, open documentation

Two general rules apply across every category. First, ask for the update commitment in writing: how long will this device receive security firmware updates? The UK PSTI regime now requires manufacturers to declare a minimum support period, and several vendors state it on the box or the product page. If a manufacturer cannot tell you how long the device will be patched, assume it will be abandoned the moment the next model ships. Second, prefer devices that work without a mandatory cloud account for their core function. The lock should unlock, the camera should record, the bulb should turn on—even if the vendor's cloud is down or the company disappears.

How to secure what you already own

Most of the risk in an existing smart home is configuration, not hardware. The following sequence takes about thirty minutes and covers the overwhelming majority of realistic attacks.

1. Fix the network perimeter first

2. Segment the network

This is the highest-impact improvement available. If your router has a guest network, put every IoT device on it and keep your phones and computers on the main network. Guest networks typically isolate clients from each other and from the main LAN, which is exactly the property you want. If you have prosumer or open-source gear (Ubiquiti, TP-Link Omada, OpenWrt, pfSense), create a dedicated IoT VLAN with firewall rules that allow IoT devices to reach the internet (for updates) but block them from reaching your main network except for the specific local services they need—typically mDNS/SSDP discovery and the hub itself.

For a typical segmented setup, the rule set is small: allow established connections from IoT to the internet; allow the hub/controller on the main network to reach IoT management ports; block everything else. A common gotcha: casting and some local control use mDNS (port 5353) and IGMP, so you must permit those between the IoT segment and the main segment or your speakers and displays will mysteriously stop being discoverable.

3. Fix the account layer

4. Update everything, then schedule updates

5. Reduce the exposure you cannot patch

AI in the smart home: the new layer to assess

AI has quietly become the differentiator in consumer IoT, and it cuts both ways. On the positive side, on-device AI is a privacy win: a camera that classifies "person" or "package" locally—using a neural network on its own chip—never uploads the frames used for that decision. Voice assistants increasingly process wake words and even full requests locally, which shrinks the amount of your speech that transits a vendor cloud. This is a genuine architectural improvement over the early cloud-everything era, and buyers should reward it.

On the negative side, AI adds a new attack surface. Local models are software like any other: they need updates, and a compromised model or AI feature can misclassify events, disable detection to hide activity, or exfiltrate data through new telemetry channels. Prompt-injection-style attacks—where malicious content in the physical world or in transmitted audio steers an AI feature's behavior—are an emerging research area, not a settled threat, but the principle from enterprise AI applies at home too: the more a device can do autonomously, the more carefully you should control what it can access and what it can act on.

The buying implication is simple: prefer on-device AI, but treat it as software. It is an upgrade when the vendor updates it and a liability when the vendor abandons it. The update commitment you demanded for the hardware applies with equal force to the AI features inside it.

Regulatory context: the floor is rising

It is worth knowing where the regulatory baseline now stands, because it changes what "secure" means when you shop.

These regimes do not make a specific product secure, and compliance is not a guarantee—but they raise the floor for the worst offenders and give buyers a legitimate question to ask: "What is the minimum support period, and where is your vulnerability disclosure policy?" A vendor that answers clearly is making a different kind of product than one that does not.

What happens next

Three developments are worth watching over the next two years.

First, the local-first architecture will win. Matter, Thread, and local AI are not separate trends; they are the same trend—control and processing moving back into the home. The products that survive the next market cycle will be the ones whose core functions do not depend on a vendor cloud. This is good for security and good for consumers, and it will quietly become the default expectation rather than a premium feature.

Second, update support will become a disclosed specification, like screen size or battery life. The PSTI minimum-support-period declaration and the CRA's support obligations are forcing what consumers always needed: a way to compare how long a device will be maintained. Expect product pages to start advertising "5 years of security updates" the way phones advertise cameras.

Third, the home network will become a managed asset. The rise of mesh systems with built-in security features, ISP-provided secure routers, and consumer VLANs reflects a market realizing that the network is the security boundary. In the same way that homeowners learned to change furnace filters and test smoke detectors, households will learn to segment networks and rotate device credentials—because the alternative, an unmanaged network of twenty computers with cameras and microphones, is not a viable long-term position.

The smart home is not a collection of gadgets. It is the first network most people will ever operate—and the most important one, because it is the one their family lives inside. Buying deliberately, segmenting the network, and maintaining the account layer are not chores. They are the difference between a home that uses technology and a home that is defined by its vulnerabilities.

Official references

Frequently asked questions

What is the safest way to set up a smart home?

Start with the network, not the gadgets. Change the router admin password, enable WPA3, disable WPS and remote administration, and put IoT devices on a separate network or guest network if your router supports it. Then change every device's default password to a unique one, enable two-factor authentication on the accounts that manage your devices, and keep firmware updates on. The single most common failure is not the device—it is leaving the default credentials and default network configuration in place.

Do smart cameras and speakers actually listen to everything?

No, in normal operation they do not record or transmit continuously. Smart speakers listen for a wake word locally and begin streaming only after they detect it; cameras record when triggered, on a schedule, or continuously depending on your settings. The real risks are elsewhere: cloud accounts that can be hijacked, microphones and cameras that can be accessed after a compromise, and apps with overbroad permissions. Treat every connected device as a potential microphone and camera, position them accordingly, and review which devices have cloud accounts at all.

What does Matter mean for smart home security?

Matter is a connectivity standard backed by Apple, Google, Amazon, and Samsung that lets devices from different ecosystems work together locally, over Wi-Fi, Thread, or Ethernet, with no cloud bridge required for core operation. For security this is mostly positive: it reduces vendor lock-in, standardizes device onboarding with secure pairing, and enables local control that continues working without internet. It does not remove the need for firmware updates, strong accounts, or network segmentation—it improves the baseline, it does not guarantee it.

Do I need a separate network for my smart home devices?

It is the single highest-impact improvement most households can make. A separate IoT network—a dedicated SSID, a guest network, or a VLAN on prosumer gear—limits what a compromised camera or speaker can reach: no direct path to your computers, phones, or network storage. Most modern routers offer at least a guest network, and mid-range and prosumer routers add VLAN or network-isolation features. If you cannot segment, at minimum disable unnecessary features, use unique passwords, and keep firmware updated.

Securing your home—or your workforce's homes?

Null Session Intelligence helps organizations assess IoT and remote-work risk, design network segmentation, and audit consumer-grade technology exposure.

Discuss your situation