SDMmag logo
search
Go to Ask SDM AI
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
SDMmag logo
  • NEWS
  • PRODUCTS
  • TOPICS
    • Access Control & Identification
    • Integration & Network Solutions
    • Life Safety & Fire Alarm
    • Monitoring
    • Smart Home
    • Trends & Industry Issues
    • Video Solutions
  • COLUMNS
    • Digital Shuffle
    • Editor's Angle
    • Insider News & Business
    • Integration Spotlight
    • Marketing Madmen
    • Security & the Law
    • Security Comings & Goings
    • Security Networkings
    • Technology @ Work
    • Technology Solutions & Skills
    • SIA Waypoints
    • Cybersecurity Chronicle
  • EXCLUSIVES
    • Annual Industry Forecast
    • Dealer of the Year
    • Project of the Year
    • SDM 100
    • State of the Market Series
    • Systems Integrator of the Year
    • Top Systems Integrator Report
    • TMA Excellence Awards
  • BLOG
  • MEDIA
    • Videos
    • Podcasts
    • Polls
    • White Papers
  • EVENTS
    • Industry Calendar
    • Webinars
  • MORE
    • Classified Ads
    • Newsletters
    • SDM Store
    • State of Security eBook
    • Sponsored Insights
  • BUYERS GUIDE
    • Buyers Guide
    • Take a Tour
  • EMAG
    • eMagazine
    • Archive Issues
    • Monitoring Today
    • Advertise
  • SIGN UP!
Smart HomeTrends & Industry Issues

Smart Home Cyber Security

What dealers need to know to keep their customers cyber-secure.

By Joan Engebretson
Obsidian-July2018

Controlling user codes for smart door locks is critical to smart home cyber security.

SmartLink 1-July2018

Strong passwords can help secure the smartphone app that customers use to remotely control their smart home systems.

PHOTO COURTESY OF ALULA

Concerns About Hacking of Smart Products-July2018

Parks Associates data indicate that almost half of U.S. broadband households are “very concerned” (rating 6 to 7 on a 7-point scale) about hackers getting control of connected devices. Consumers are equally concerned about hackers getting access to historical data from those devices. An analysis of changes in these consumer attitudes from 2014 to 2016 finds that the total share of consumers who are “concerned” (rating 5 to 7) has increased by 5 percent on both questions and the share of those “very concerned” has grown by 6 percent to 7 percent. Similarly, the share of consumers who are “not concerned” (rating 1 to 3) has shrunk by about 3 percent to 6 percent.

GRAPHIC COURTESY OF PARKS ASSOCIATES

Obsidian-July2018
SmartLink 1-July2018
Concerns About Hacking of Smart Products-July2018
July 30, 2018

Security dealers increasingly are offering smart home devices such as smart lighting control, smart thermostats and smart door locks to their customers. By taking the right precautions, dealers can help ensure that those devices enhance the customer’s lifestyle without posing cyber security vulnerabilities.

 

While the focus of this article is specifically on cyber security for smart home equipment, it’s important to note that there also may be vulnerabilities related to the security system to which the smart home equipment may be connected — a topic addressed in the sidebar titled, “How Secure Are Wireless Security Devices?” on page 76. 

Wireless Communications

Potential cybersecurity vulnerabilities related to smart home equipment fall into three main areas: wireless communications, passwords/user codes, and the security of the customer’s router/broadband modem.

Smart home devices such as smart door locks or smart thermostats may use Z-Wave, Zigbee or Wi-Fi wireless communications.

Ross Werner, chief architect for San Jose, Calif.-based security and smart home equipment manufacturer Qolsys Inc., explains the cyber security protections provided by each of these protocols. “Z-Wave devices fall into two categories: secure (access devices such as door locks) and non-secure (light switches, thermostats, etc.). Secure Z-Wave devices use 128-bit AES encryption; this is what financial institutions and governments use to protect sensitive data. It is built-in, always-enabled, not even possible to be disabled,” Werner explains.

Encryption helps prevent an unauthorized user from using a “sniffer” device to listen to communications in order to learn passwords or other sensitive information.

“Z-Wave also benefits from an explicit pairing process where the network controller has to sync with a new device and exchange security keys,” Werner continues. “The latest version of the Z-Wave [software development kit] is fully encrypted.”

Looking for quick answers on security topics? Try Ask SDM, our new smart AI search tool. Ask SDM →

Zigbee is a bit more complicated because each one of multiple vendors has implemented its own version of the networking stack. Overall, though, “if you look at Zigbee 3.0, with proper implementation, its security is comparable to Z-Wave; it also uses 128-bit AES and has a pairing process between devices to the network controller,” Werner says.

Ensuring Wi-Fi security “requires first enabling a robust security protocol and then strong passwords to keep the communication secure,” according to Werner. 

Dave Mayne, vice president of product management for Hudson, Wis.-based manufacturer Alula, notes that most Wi-Fi smart home equipment has encryption as a default setting. A bigger concern, he says, is whether an unauthorized Z-Wave device might be able to connect to a Z-Wave network.

Devices used with Alula and some other smart home systems have a feature that requires the passing of secure software keys — which Mayne says could be thought of as device passwords — back and forth between the system and any device that wants to join the network. 

According to Mayne, “not all manufacturers do that well.” Accordingly, he advises dealers to ask the manufacturer of any smart home equipment what that manufacturer does to make sure that only trusted devices can join the network.

As for encryption of wireless protocols, Mayne comments “You’re always playing a game — hackers try to break [encryption], you enhance it and the hackers try to break it again.”

Recognizing that, dealers will want to keep up with new developments in encryption technology and when appropriate, consider replacing or, if possible, upgrading existing devices so that they have the most current technology.

How Secure Are Wireless Security Devices?

Ironically, potentially the least secure portion of an integrated security and smart home system is not the smart home portion of the system, but rather the security portion. 

According to Mike Hackett, senior vice president of sales and marketing for Qolsys, some of the proprietary protocols that manufacturers use between wireless sensors and the control panel are unencrypted. 

Traditionally, this was not a major concern, he explains. “Ten years ago, it would take a really smart person with a really gigantic server” to “pull up to someone’s house,” listen in on communications between elements of the security system and determine how to gain entry to the system, Hackett observes.

In today’s world, however, he notes that “there’s a simple radio you can buy on eBay or Amazon” which, when combined with watching a video on YouTube, can give almost anyone the ability to crack into unencrypted security system communications. 

Communication between individual elements of an alarm system can be fairly infrequent, but according to Hackett, a potential burglar could hide a sniffer device in a bush near a home targeted for a heist and return a week or so later to gain the necessary information.

Some security manufacturers — including Qolsys, Alula and others — are now encrypting wireless security system communications and some offer retrofit kits for existing systems that may lack encryption. Retrofit kits may enable security dealers to replace only the radio portion of the existing panel, Hackett explains. To minimize upgrade costs, dealers may consider only replacing particularly critical sensors such as wireless key fobs and door/window contacts, he notes.

Advising customers about options such as these could be an important task for security dealers, considering that a recent Parks Associate survey conducted for Qolsys found that 64 percent of professionally monitored security system owners believe their home security system uses encrypted communications from the sensors to the panel, even though the percentage likely is considerably lower. 

“Proprietary protocols used in various security products have varied in the degree of protection they provided, from highly rigorous to much less so,” comments Brad Russell, Connected Home research director for Parks Associates.

User Codes & Passwords

According to Helen Heneveld, president of Holland, Mich.-based Bedrock Learning and author of SDM’s Smart Insights column, the most common vulnerabilities associated with home control systems relate to user codes and passwords. It’s critical for the default passwords on any home control devices that use passwords to be changed.

What malicious actors could do if they were to obtain the password to a home control device varies, depending on whether the device communicates with the security system, Heneveld explains, but one possibility is they might be able to unlock doors or windows.

Heneveld recommends that security dealers offer a password management service to their home control customers to keep track of client passwords and help ensure that those passwords are changed regularly. Homeowners see security dealers as trusted suppliers, Heneveld argues, and by offering password management, dealers not only gain a potential source of recurring monthly revenue (RMR), they also “reaffirm the trust” that customers have in them. 

Some industry stakeholders have a bit different take, however. Noting that many systems are controlled via an app installed on the customer’s smartphone or through a computer, Nick English, national sales manager for Kwikset Corp., Lake Forest, Calif., recommends that the installer show the customer how to change the password using the app but should avoid knowing the password, instead turning responsibility over to the customer to enter the password into the system.

Using an app that requires customers to use a longer-length password that includes a combination of special characters and upper- and lower-case letters or advising customers to use such a password also can enhance cyber security.

English offers other advice for what security dealers should tell customers when turning a newly installed smart home system over to the customer. He notes, for example, that Kwikset smart door locks can support as many as 30 user codes, but he advises dealers to discourage customers from assigning more of them than they need. He also encourages dealers to inform customers that they can limit the hours during which an individual user can access the system.

“If you have a dog walker and you give them their own user access code, maybe you only make it available during certain times and not on weekends,” English suggests.

The Role of the Router

Some smart home cyber security vulnerabilities originate in a device that typically is not under the security dealer’s control — the broadband modem/router from the cable or phone company or other Internet provider. 

“Right now, I think that’s kind of a hands-off area,” comments Mayne, who notes that security dealers don’t want to be accused of changing something on the router that causes some type of problem for the customer.

Nevertheless, routers could have cyber security vulnerabilities if certain software is out of date, if default passwords haven’t been changed, or for other reasons. One important potential vulnerability is if software ports on the router have been left open, which also leaves open the possibility that a malicious actor might gain entry to the network through an open port. 

“If they can get to the router, maybe they can get to your laptop,” observes Mike Hackett, Qolsys senior vice president of sales and marketing — and that might enable a malicious actor to get to banking records or other sensitive information.

Mayne advises security dealers to consider offering a monitoring service for the router, a move that could enhance smart home cyber security while at the same time provide a new source of RMR. If the monitoring service were to detect potential security vulnerabilities in the router, the dealer could advise the customer to raise the issue with his or her Internet provider. He points to Fing, Bitdefender and Cujo as possible providers of such software. 

Mayne adds, though, that there are some instances in which a smart home system could introduce potential vulnerabilities. Whether or not this could occur relates to how the dealer’s equipment manufacturer implements remote smartphone control, according to Mayne. 

The most secure method, he says, is via a cloud connection. With this approach, if a malicious actor were to gain access to the customer’s account by somehow obtaining or guessing the user’s password, he or she would not be able to gain access to the customer’s home network but only to the cloud interface. Mayne advises dealers to avoid using products that rely on a direct connection to the customer’s home network for remote access.

A Cyber Security Tool for Security Dealers

Security dealers that are members of the Consumer Technology Association may find an interactive tool developed by CTA to be useful in gauging the cyber security of a smart home installation. The tool steps the dealer through a series of questions and, based on those answers, provides a score to indicate the cyber security level of the installation. A checklist that looks at the same issues is available to members and non-members on the CTA site at this link:

https://cta.tech/cta/media/Membership/PDFs/ConnectedHomeSecurityChecklist.pdf

Ongoing Education

Dealers also may want to make cyber security part of their ongoing dialogue with their customers.

“We make it a habit to routinely educate/inform our customers of the best security measures they themselves should take: at the point of sale, during/after installation and on an ongoing basis via phone calls, emails and blog postings,” comments Heather Spencer, coordinator of marketing and social media for GHS Interactive Security, a security dealer based in Woodland Hills, Calif.

Those tips, she notes, include:

  • Create strong passwords.
  • Avoid using the same password for multiple log-ins.
  • Change passwords often.
  • Secure the property’s wireless network and cloud-enabled devices with a firewall.
  • Use a regularly updated anti-virus program across all computers and make sure all computers and networking equipment are patched regularly.
  • Ensure equipment firmware is updated on a regular basis.
  • Only purchase security equipment from a trusted source.

Adding smart home capabilities can enhance customers’ experiences with their security systems and boost dealer revenues. Keeping cyber security top of mind can help ensure that customers have a positive experience with their smart home systems and may even provide additional revenue opportunities in the form of password management and monitoring of customers’ home networks.


More Online

For more information about cyber security of security technology, visit SDM’s website where you will find the following articles:

“Cyber Security & Its Impact on Operational Technologies”

www.SDMmag.com/cyber-security-operational-technologies

“Cyber Security & the Internet of Things”

www.SDMmag.com/cyber-security-and-iot

“Cyber Security & IP Cameras: Everyone’s Concern”

www.SDMmag.com/cyber-security-ip-cameras-everyones-concern

“The Seeming Paradox of Cybersecurity”

www.SDMmag.com/paradox-cybersecurity

“Cyber Security Threats, the IoT and Preparing for the Zombie Apocalypse”

www.SDMmag.com/preparing-for-the-zombie-apocalypse

 “The Brave New World of Cybersecurity and the Security Integrator’s Role In It”

www.SDMmag.com/brave-world-cybersecurity


KEYWORDS: cyber security security dealers

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Joan Engebretson is a contributing writer for SDM Magazine.

Recommended Content

JOIN TODAY
to unlock your recommendations.

Already have an account? Sign In

  • SDM 100

    SDM 100: Top 100 Security Dealers of 2026

    The top 100 security dealers navigated a complex...
    Exclusives
    By: Karyn Hodgson
  • Security camera

    State of the Market: Video Surveillance

    As video surveillance shifts from siloed systems to...
    State of the Market Series
    By: Brianna Wilson
  • 2026 Industry Forecast

    SDM 2026 INDUSTRY FORECAST

    Rapid technology advances meet shifting economic...
    Exclusives
    By: Karyn Hodgson
Manage My Account
  • SDM Newsletters
  • Online Registration
  • eMagazine Subscriptions
  • Subscription Customer Service
  • Manage My Preferences

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the SDM audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of SDM or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Doctor examining child patient with mother present in medical clinic
    Sponsored byHID

    The Human Side of Hospital Security: How Modern Visitor Management Protects People First

Popular Stories

Video surveillance camera

Why Video Health Monitoring Is a ‘No Brainer’

ESA Board of Directors Q2 26 Elections

Electronic Security Association Announces 2026 Board of Directors Election Results

TMA & SDM Logos

Becklar, Elite & Puget Win 2026 TMA/SDM Monitoring Center Excellence Awards

SDM Dealer of the Year 2026 Promotion

Poll

What’s the most promising trend in the industry?

What’s the most promising trend in the industry?
View Results Poll Archive

Products

Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

See More Products
SDM 100 2026 Rankings

Related Articles

  • adt

    ADT Unveils Home Automation, Cyber Security Solutions at CES

    See More
  • parks whitepaper

    Parks Associates’ Whitepaper Examines Cyber Security’s Impact on the Smart Home Market

    See More
  • Genetec Security Center 5.7 Synergis Control System - SDM Magazine

    New Version of Genetec's Platform Adds New Cyber Security, Privacy, Access Control & Smart-Data Analytics Features

    See More

Events

View AllSubmit An Event
  • August 28, 2025

    Smart Home as a Security Differentiator

    ON DEMAND: In a competitive market, offering smart home integration can give dealers and integrators a crucial edge. In this webinar, discover how connected devices can enhance traditional security systems and deepen customer loyalty.
View AllSubmit An Event

Related Directories

  • Southern Lock & Supply

    Southern Lock has been a family-owned, major wholesale distributor of security products since 1946. With trusted products, expert service, and locations across the Southeast, we are your one-stop shop for security hardware, electronic access, and automotive locksmithing equipment.
  • DWG

    DWG is your trusted distribution partner, delivering cutting-edge security, surveillance, fire and life safety, and networking solutions nationwide. We empower professional integrators with premium products, expert support, and fast shipping—helping you win more projects, grow your business, and stay ahead in an evolving industry.
×

Be in the forefront of security intelligence when you receive SDM.

Join over 10,000+ professionals when you subscribe today.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Directories
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing