When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.
Secure Your WiFi Network First
Your WiFi network is the front door to every smart device in your home. If someone gets onto your WiFi, they can potentially access all connected devices.
- Change the default router admin password. Log into your router (usually 192.168.1.1 or 192.168.0.1) and set a strong, unique admin password. The default “admin/admin” or “admin/password” is the first thing attackers try.
- Use WPA3 encryption (or WPA2 if your router doesn’t support WPA3). Never use WEP – it can be cracked in minutes.
- Set a strong WiFi password. Use at least 12 characters with a mix of letters, numbers, and symbols. Avoid dictionary words and personal info like your address or birthday.
- Change your network name (SSID) to something that doesn’t identify you or your router model. “SmithFamily-WiFi” or “NETGEAR-5G” gives away too much information.
Create a Separate IoT Network
Many modern routers support guest networks or VLANs. Put all your smart home devices on a separate network from your computers and phones.
- Log into your router’s admin panel.
- Set up a guest network or secondary SSID.
- Connect all smart home devices (cameras, plugs, speakers, thermostats) to this separate network.
- Keep your computers, phones, and tablets on your main network.
This way, even if a smart device gets compromised, the attacker can’t reach your computers or access files on your main network. Most mesh router systems (Eero, Google Wifi, Asus ZenWifi) make setting up a separate IoT network straightforward through their app.
Keep Firmware Updated
Smart device manufacturers release firmware updates that patch security vulnerabilities. Outdated firmware is one of the most common ways devices get compromised.
Enable auto-updates wherever possible. Check each device’s app for an auto-update setting. Most major brands (Ring, Nest, Philips Hue, TP-Link) support automatic firmware updates.
Manually check for updates monthly if auto-update isn’t available. Open each device’s app, go to Settings, and look for “Firmware Update” or “Software Update.” Routers in particular often don’t auto-update – log into the admin panel and check for updates regularly.
Use Strong, Unique Passwords
Every smart device account should have its own unique password. Reusing passwords across services means one breach exposes everything.
Use a password manager. Apps like 1Password, Bitwarden (free), or the built-in password managers in iOS and Android generate and store strong, unique passwords for each account. You only need to remember one master password.
Don’t use default passwords. Some devices ship with default passwords or PINs. Change them during initial setup. If a device doesn’t let you change its password, that’s a red flag about its security.
Enable Two-Factor Authentication
Two-factor authentication (2FA) adds a second verification step beyond your password – usually a code sent to your phone or generated by an authenticator app.
| Service | 2FA Available | How to Enable |
|---|---|---|
| Ring | Yes | Ring app, then Account, then Two-Step Verification |
| Google Home / Nest | Yes | Google Account settings, then Security, then 2-Step Verification |
| Amazon Alexa | Yes | Amazon account settings, then Login & Security, then Two-Step Verification |
| Apple HomeKit | Yes | Built into Apple ID (Settings, then Apple ID, then Password & Security) |
| Samsung SmartThings | Yes | Samsung account settings |
Use an authenticator app (Google Authenticator, Microsoft Authenticator, Authy) instead of SMS codes when possible. Authenticator apps are more secure because they can’t be intercepted through SIM swapping attacks.
Disable Features You Don’t Use
Every enabled feature is a potential entry point for attackers. Turn off what you don’t need.
Remote access: If you never access your smart devices from outside your home, disable remote access in each device’s settings. This prevents anyone from reaching the device over the internet.
UPnP (Universal Plug and Play): Disable UPnP on your router. UPnP automatically opens ports on your network, which smart devices use for convenience but which also create security holes. Find this setting in your router’s admin panel under “UPnP” or “NAT” settings.
Voice purchasing: If you have Alexa or Google Home, disable voice purchasing or set a voice PIN. Without this, anyone in earshot (or a voice from a TV or radio) could potentially place orders on your account.
Unused smart features: If your smart TV has a microphone you never use, turn it off. If your smart speaker has a “drop-in” feature you don’t use, disable it.
Secure Smart Cameras and Doorbells
Cameras are the highest-risk smart devices because they capture video inside and outside your home.
Use a unique, strong password for your camera account. Never reuse a password from another service.
Enable 2FA on your camera account (Ring, Nest, Wyze, etc.).
Review shared access regularly. Check who has access to your camera feeds. Remove old roommates, ex-partners, or anyone who no longer needs access. In Ring, go to Account, then Shared Users. In Google Home, go to the camera settings and check “Linked accounts.”
Set up activity zones. Limit recording to specific areas to avoid capturing unnecessary footage of public spaces or neighbors’ properties.
Monitor Your Network
Keep track of what’s connected to your network and spot unfamiliar devices.
Router admin panel: Most routers list all connected devices. Log in and review the list periodically. If you see a device you don’t recognize, remove it and change your WiFi password.
Router apps: Eero, Google Wifi, Netgear (Nighthawk/Orbi), and Asus apps all show connected devices with names and connection details. Some send notifications when new devices join the network.
Network scanning apps: Fing (free) scans your network and identifies all connected devices by brand and type. It’s useful for finding devices that show up with cryptic names in your router’s list.
Troubleshooting
Device won’t connect after changing WiFi password. Every smart device stores your WiFi credentials. After changing your password, each device needs to be reconnected. Most require a factory reset and fresh setup through the app. Plan for this when changing your WiFi password – it takes time with many devices.
2FA codes not arriving. If using SMS, check your phone’s signal. If using an authenticator app, make sure the time on your phone is set to automatic (authenticator codes are time-based). Most services offer backup codes during 2FA setup – keep these in a safe place for exactly this situation.
Can smart home devices be hacked?
Yes, but most attacks target weak passwords, outdated firmware, or unsecured WiFi rather than sophisticated exploits. Devices from major brands with current firmware and strong passwords are reasonably safe. The biggest real-world risk is credential stuffing – attackers use leaked passwords from other breaches to try logging into smart device accounts. Unique passwords and 2FA eliminate this risk.
Are cheap smart devices less secure?
Often, yes. Budget smart devices from unknown brands may not receive firmware updates, may use weak encryption, or may send data to servers with questionable security practices. Stick with established brands (Google, Amazon, Apple, Ring, TP-Link, Philips) that have a track record of regular security updates and transparent privacy policies.
Should I worry about voice assistants listening?
Smart speakers listen for their wake word (“Alexa,” “Hey Google,” “Hey Siri”) but don’t continuously record or transmit audio. You can review and delete your voice history in each service’s privacy settings. For extra privacy, use the physical mute button on the speaker when you don’t want it listening at all. The hardware mute physically disconnects the microphone – it can’t be bypassed by software.
See also: How to Reset Netgear Router, How to Connect Smart Plug to WiFi, How to Improve Internet Connection
Sources
CISA – Securing IoT Devices | NIST – IoT Security Guidelines