22 July 2026 · By Brett Casterton

Smart-home security: how to keep connected devices from becoming the weak link

A British family home hallway at early evening — a mother in an olive-green jumper sets up a small purple smart speaker on her phone, a video doorbell visible on the doorframe beside her, and her partner working at a laptop in the home office through the doorway behind
Doorbell, speaker, laptop — all on the same Wi-Fi until you split them apart.

Last week we looked at how to get rid of old tech safely. This week it's the other side of the same coin — every internet-connected thing you're still using. Same goal: keep your money and your data safe, at home and at work.

The doorbell that kept dropping offline

A Greater Manchester family called us in after a strange run of little glitches. Their smart doorbell kept dropping offline, the baby-monitor app started behaving oddly, and the dad's work laptop kept asking for fresh logins at unusual times. Nothing on its own screamed "cyber incident" — but together it was enough to make them nervous, and they were right to be.

The real problem was the network, not just the gadgets. The doorbell, baby monitor, smart TV, voice assistant and the work laptop were all sitting on the same home Wi-Fi. Some devices still had default admin passwords. One had never had its app permissions reviewed. Updates had been ignored for months on the older ones. That's a lot of little doors, all open at once.

We split the network in half — smart-home gear on a guest SSID, work laptop and personal phones on the main one — reset the accounts to strong unique passwords, turned on two-step verification everywhere it was offered, and pushed the pending firmware updates. It wasn't glamorous, but it shut down the risk. That's the honest truth with smart-home security: most of the danger comes from ordinary devices being left on ordinary settings.

Same pattern hits businesses through the back door. A Tameside accountancy client asked us to look at a partner's home setup after his wife's Instagram was compromised — the account had been used to phish their contacts. Turned out the same weak password lived on the router admin page, the smart TV account and a five-year-old baby monitor still bolted to the nursery wall. One password, three devices, one compromised account leading straight back to a laptop that touched client data every day.

Why this matters

  • At home, the NCSC says smart devices should be secured because some aren't safe out of the box. The UK's Product Security and Telecommunications Infrastructure (PSTI) Act came into force in April 2024 and forces manufacturers to stop shipping devices with default passwords — but that doesn't magically fix the millions of older gadgets already in UK homes.
  • At work, the same guidance matters for home workers because insecure home IoT devices share the network with work laptops. Device-security guidance for organisations is very clear that secure configuration and separation of connected devices are non-negotiable — but almost nobody applies that logic to their own kitchen and hallway.

The fix

Smart-home security means treating connected gadgets like proper computers: strong unique passwords, two-step verification where available, updates on, privacy settings reviewed, and — where possible — kept off the same network as sensitive kit. The NCSC and NI Cyber Security Centre both advise thinking about security before buying, not after something goes wrong. For business owners with home-working staff, this is exactly the kind of hygiene that shows up in a Cyber Essentials assessment, and it's baked into the awareness pack we run for every client on our M365 Hardened posture.

Three things you can do this week

🏠 At home

Go round every camera, doorbell, speaker and their app and change the default password to something strong and unique. If the app offers two-step verification, turn it on. Then check what permissions the app has on your phone — most of them are asking for more than they need.

🏢 At work

If you or your staff work from home, keep smart-home devices off the same network as business kit where possible. Most modern home routers can broadcast a guest Wi-Fi in two clicks — that single split reduces the risk if one gadget is compromised.

🌍 For everyone

Buy from brands that support updates. Avoid no-name gadgets with vague support, and replace anything the manufacturer has stopped updating. An unsupported smart device is a permanently open door — no amount of good habits fixes that.

Where you sit on the risk scale

The same four habits keep showing up between "trouble waiting to happen" and "actually pretty solid". Honest comparison — most UK homes we look at are somewhere in the top two rows.

Setup Password Updates Network Risk
Straight out of the box Default Unknown Shared with everything High
Bit of a tidy-up, no plan Sometimes changed On some devices Shared with everything High
Strong passwords + updates on Strong & unique On everywhere Still shared Medium
Passwords + updates + guest Wi-Fi split Strong & unique On everywhere Guest network for gadgets Low
Unsupported device still plugged in Irrelevant No support left Any Replace it

What this looks like locally

We've helped families and home-working staff across Tameside, Stockport (SK1), Ashton-under-Lyne (OL6) and Sale (M33) lock down home networks full of doorbells, smart TVs, cameras and speakers. The pattern is always the same: nobody thinks of these devices as computers, so nobody gives them computer-level security until something starts behaving oddly. Half an hour with the router, the device apps and a password manager fixes ninety per cent of what we find.

For the business side of the same conversation, see our piece on why attackers get in through the firewall and VPN, not the password — the guest-network split we recommend at home is exactly the same idea applied to your office edge.

Frequently asked

Are smart-home devices really a security risk?

Yes. The NCSC says smart devices should be secured because some are not safe out of the box. The UK PSTI Act came into force in April 2024 and requires manufacturers to stop shipping devices with default passwords, but that doesn't fix the millions of older devices already in UK homes — those still need to be reset and updated by hand.

What should I do first with a new smart device?

Four things in order: change the default password to a strong unique one, turn on two-step verification if the app offers it, install any pending firmware updates, and review the privacy settings — most devices ship set to share more than they need to.

Should smart devices be on a guest Wi-Fi network?

Ideally, yes. Keeping smart-home gadgets on a separate network from your main devices and work laptop means that if a doorbell or speaker is compromised, the attacker still can't reach your work files or personal banking. Most modern home routers can broadcast a guest network in a couple of clicks.

Do cheap smart devices carry more risk?

Often, yes. The NCSC and NI Cyber Security Centre both recommend buying from trusted manufacturers that provide ongoing security updates. No-name devices from marketplaces are the ones most likely to stop receiving updates within a year or two — and then any weakness in them stays open forever.

What if the manufacturer stops supporting a smart device?

Replace it. Once updates stop, any known weakness stays open. This is why buying a well-supported brand matters more than buying the cheapest version — a £30 doorbell that's abandoned in eighteen months is more expensive over three years than a £70 one that's still receiving updates.

Does a smart-home hack really matter if I've got nothing to hide?

It matters more than people realise. A compromised camera can be watched by strangers; a compromised smart speaker can be joined to a botnet that attacks other people's networks; and a compromised gadget on the same Wi-Fi as your work laptop is a foothold on the corporate network. It's rarely about your data alone — it's about what your home is being used for.

"A smart doorbell is still a computer with a camera on your network. The minute you think of it like that, the security decisions get much easier." — Brett Casterton, Inology IT

Previous tip: Getting rid of old tech safely — how to wipe phones, laptops and drives before you recycle them.

Want help with this one?

I'm one form away.

I'm Brett at Inology IT — based in Tameside, looking after families and small businesses right across Greater Manchester. Drop your details below and I'll be in touch within one working day.

We'll never sell your details. See our privacy policy.

Last reviewed by Brett Casterton, July 2026.

← Back to Weekly Tech Tips

Inology IT — managed IT support for businesses and charities across Greater Manchester, headquartered in Tameside.