Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Protecting connected devices takes more than a strong Wi-Fi password. Security depends on the device, its manufacturer’s update and support practices, how it is configured, and what data it collects and shares. For home users, start with the router and secure each device; when buying or deploying IoT products, check their access controls, data practices, update plans, and role in the wider network.

What security and privacy risks do IoT devices create?

Internet-connected devices can include routers, cameras, appliances, sensors, and other products that communicate over a network or with online services. Their capabilities and consequences vary: a camera in a private room raises different concerns from a device that does not capture images or sound, and a product with remote access has a different exposure from one used only locally.

Cybersecurity concerns include unauthorized access, weak or reused credentials, insecure network connections, and products that do not receive needed security updates. A compromised device may also affect the services or other devices it connects to. NIST’s Considerations for Managing Internet of Things (IoT) Cybersecurity and Privacy Risks (NISTIR 8228, final June 25, 2019) emphasizes that IoT is diverse and that organizations may not know every device they use or how its risks differ from conventional IT.

Privacy is broader than preventing a stranger from accessing a device. Consider what information it collects, why it needs that information, where it travels and is stored, who can access or use it, whether it is shared, and how it can be deleted. Data collection, retention, or sharing that is not needed for the service creates additional privacy exposure even when a device has not been hacked.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Why IoT security is a lifecycle responsibility

A device’s security is shaped before purchase and continues through setup, everyday use, software updates, support, and eventual retirement. A secure home network cannot make an unsupported product receive fixes, just as a capable product can be weakened by default passwords or unnecessary access.

NISTIR 8259 Rev. 1, Foundational Cybersecurity Activities for IoT Product Manufacturers, became final on April 20, 2026, superseding the May 2020 original. NIST says IoT products often lack cybersecurity capabilities customers can use to mitigate risk. The revised report describes manufacturer activities to consider before products are sold, including providing useful cybersecurity functionality and information to customers.

Rank #2
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

For organizations identifying the technical capabilities they need in devices they manufacture, integrate, or acquire, NISTIR 8259A (2020) provides a starting baseline. It is not a universal product score: an organization still has to match capabilities to the device’s function, data, network access, and consequences of compromise. NISTIR 8228 provides the broader lifecycle risk-management context.

How to secure IoT devices at home

Use these steps as a practical baseline. Router and device menus vary by manufacturer and model, so follow the product’s own instructions where a setting is named differently. These measures reduce avoidable exposure but do not guarantee that a device or network is secure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Thetis Pro For Business - FIDO2 Security Key L1 MFA & NFC Passkey Access For School ERP, Employee Online Account, Compatible with Coinbase Google Workspace Apple ID Window Salesforce,Dual USB A +USB C
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Universal Connectivity (USB-C, USB-A, & NFC): Designed for PCs, Macs, iPhones, and Android. For mobile use, simply unfold the key, align it with your phone’s NFC antenna, and hold for a few seconds to authenticate.
  • Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC is supported only through mobile authentication, Not MacOS/windows.
  1. Secure the router first. Sign in to the router’s administration interface using its manufacturer instructions. Change the default administrator credentials and Wi-Fi network name, set a unique Wi-Fi password, enable WPA3 Personal or WPA2 Personal, and install available router software updates. The Federal Trade Commission (FTC) recommends considering a replacement if an older router cannot support WPA2 or WPA3 after updates.
  2. Review optional router features. FTC guidance notes that remote management, Wi-Fi Protected Setup (WPS), and Universal Plug and Play (UPnP) may weaken security on some routers. Consider turning them off if you do not need them, but check the router’s documentation first; feature names, effects, and controls vary.
  3. Check which devices are connected. Open the router’s connected-device or client list and identify the devices using the network. Remove or disconnect devices you no longer use, and investigate devices you cannot recognize before allowing them to remain connected.
  4. Secure each device account. Change factory-set device credentials, use a different password from other accounts, and enable two-factor authentication if the product offers it. Use available security controls such as encryption or account lockout where appropriate.
  5. Check updates and support. Look in the device app, account, or manufacturer’s support information for how security updates are delivered and how the company communicates support or security warnings. Do not assume all products have the same support period.
  6. Review privacy controls and app permissions. Check the device’s settings and companion app for the information collected, permissions requested, sharing options, retention, and deletion controls. Disable collection or permissions you do not need when the product allows it, while recognizing that exact controls differ by brand and function.

FTC consumer guidance identifies the router as a key privacy and security control because connected devices use the home network. NIST’s September 2024 NISTIR 8425A, Profile of the IoT Core Baseline for Consumer IoT Products, likewise addresses cybersecurity requirements for consumer-grade routers.

What to check before buying a connected device

Compare products against your intended use rather than relying on a blanket “secure” label or a single feature. Ask for clear answers to these questions before bringing a device into a sensitive space or connecting it to a larger system.

Rank #4
Thales - SafeNet eToken FIDO - FIDO2 Certified Security Key - Passwordless Phishing-Resistant Authentication for Web Apps, Devices & Desktops - USB-C - Pack of 1
  • FIDO2 SECURITY KEY: A versatile, tamper-evident USB-C authentication device with sensitive presence detection for online security. FIDO 2.0 level 1 and U2F certified
  • PASSWORDLESS CONVENIENCE: Replace frustrating passwords with a simple 4-digit PIN for accessing apps and sites. Seamlessly login to web apps and Windows sessions
  • BROAD COMPATIBILITY: Works with Windows, Mac, Linux, Apple, iOS, iPhone, Android and USB-C devices. Seamlessly integrates with Identity Providers or Credential Management Systems supporting FIDO2, including Thales, Microsoft, AWS, and Google
  • ENHANCED USER ADOPTION: Features a sensitive presence detector on the USB key, providing ease of use and superior security. Certified for U2F and FIDO2, ideal for individuals who want to secure access to their personal online accounts - Microsoft, Google, Twitter, Facebook, GitHub
  • THALES: We offer a wide range of FIDO authenticators, providing robust, phishing-resistant MFA that comply with stringent regulations. With almost three decades of experience, Thales is a pioneer in passwordless authentication devices, supported globally by the FIDO Alliance and industry analysts
What to assess Questions to ask Why it matters
Authentication and access Can you replace default credentials? Is two-factor authentication available? Can you control who has access and what they can do? Weak credentials and overly broad access can make unauthorized use easier.
Data practices What data is collected, for what purpose, how long is it kept, who receives it, and how can it be deleted? Privacy risk depends on the information and its handling, not only on whether outsiders can access it.
Updates and support Does the manufacturer explain how updates are delivered and how it communicates support or security issues? Customers need relevant information and security functionality to manage risk over a product’s lifecycle.
Network role and exposure Does the product require remote access? What devices or online services does it connect to? What could be affected if it were compromised? Connectivity and the consequences of compromise vary by product and use.
Sensitive functions Does it use a camera, microphone, location data, health information, or other sensitive information? Can those functions be limited? The privacy impact depends on what the device can observe and where or how it is used.

NIST’s device capability baseline can help organizations identify technical needs, but it is a starting point for evaluation, not a universal rating consumers can apply without context. Read product disclosures and support information alongside the feature list.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Extra care for cameras and other sensitive devices

A camera’s location and access settings matter as much as its general security features. FTC guidance recommends securing the network and using encryption and firewall features when the camera offers them. Think carefully before enabling remote viewing, particularly if the camera can see a bedroom or another private area. Apply the same context-sensitive judgment to microphones, location tracking, or health-related functions: enable only the access and collection that serve a clear need.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

What manufacturers and organizations should do

Manufacturers should treat security and privacy as product-design and lifecycle responsibilities, not as setup problems to pass entirely to customers. NISTIR 8259 Rev. 1 recommends activities that help manufacturers provide cybersecurity functionality and relevant information before products are sold. FTC business guidance, Careful Connections: Keeping the Internet of Things Secure, calls for a risk-based approach that includes security by design, effective authentication and access controls, data minimization, secure handling throughout the data lifecycle, updates and responses to security warnings, and clear customer communication.

Organizations acquiring or operating IoT products should first establish what devices they have and what each one does. They can then determine which capabilities, access restrictions, data controls, update processes, and support information are necessary for the device’s role and risk. Because IoT products differ and inventories may be incomplete, a single checklist or baseline should inform—not replace—context-specific risk management.

For both businesses and product makers, data minimization is a practical privacy rule: do not collect, store, or share information that is not needed. Explain necessary collection clearly, secure information through its lifecycle, and provide a way to remove data when it is no longer required.

Putting the choices together

For a household, the most useful order is to secure the router, identify connected devices, protect each device account, and review updates and data settings. For a buyer or organization, examine what the product can do, what it collects, how access and updates work, and how its network connections affect the surrounding environment. No single setting or product feature substitutes for those decisions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.