Skip to content
Engineering standardExpertUpdated 2026-07-08

Cybersecurity Standard

Baseline hardening, credential and update policies for every Smart Citizens smart home.

Executive summary

The essentials

  • Zero default passwords in the field
  • MFA on every remote-access account
  • Firmware baseline enforced monthly
  • Segmented network by policy
  • Logs retained for 90 days minimum

Purpose

Prevent smart-home devices from being the entry point into the customer's digital life.

Scope

All Smart Citizens deployments and every device we deliver, integrate, or support.

Design principles

Principle 1

Least privilege — every account gets the minimum it needs

Principle 2

Defence in depth — network + device + application

Principle 3

Assume breach — plan for detection and containment, not only prevention

Principle 4

Patch, don't rely on obscurity

Engineering requirements

Engineering requirements

Mandatory requirements
  • No factory or default passwords in production
  • Unique credentials per device where supported
  • MFA on all engineer and owner remote-access accounts
  • Firmware update policy documented per device family
  • Central logging with 90-day retention
  • WPA3 on Wi-Fi where supported (WPA2-AES otherwise)

    Best practices

    Vault

    Vault: All secrets in the Smart Citizens vault

    Rotation

    Rotation: Rotate engineer credentials on staff change same-day

    Access review

    Access review: Owner reviews access list quarterly

    Cameras

    Cameras: Cameras on their own VLAN with strict egress

    Installation workflow

    Installation workflow

    Delivery

    How it works

    1. 1. Change defaults

      Change every factory password before dispatch.

    2. 2. Register vault entries

      Store new credentials in the vault, tagged by site.

    Configuration & programming workflow

    Configuration & programming workflow

    Delivery

    How it works

    1. 1. Apply hardening

      Disable unused services on every gateway (Telnet, UPnP, WPS).

    2. 2. Enable logging

      Forward logs to the central collector.

    3. 3. Enforce MFA

      Require MFA on the customer portal at first login.

    Commissioning steps

    Commissioning steps

    Delivery

    How it works

    1. 1. Port scan

      Scan the site from IoT and guest VLANs; confirm expected exposure only.

    2. 2. Credential audit

      Confirm no default credentials remain.

    3. 3. Log verification

      Confirm logs are arriving at the collector.

    Validation checklist

    Validation checklist

    Validation checklist (must do)
    • No default passwords anywhere on site
    • MFA active on all remote accounts
    • Firmware at approved baseline
    • Logs arriving at central collector
    Common mistakes
    • Leaving factory passwords
    • Sharing engineer credentials
    • Skipping firmware updates

    Quality assurance checklist

    Vault entry

    Every device has a vault entry with rotation date.

    Port exposure

    External exposure matches the approved list.

    Acceptance criteria

    Acceptance criteria
    FeatureTargetVerification methodPriority
    No default credentials
    0Scanner reportHigh
    MFA coverage
    100%Portal auditHigh
    Log delivery
    >= 99% of eventsCollector metricsMedium
    Acceptance criteria

    Risk matrix

    Risk matrix
    FeatureLikelihoodImpactMitigation
    Shared engineer credential
    MediumHighPer-engineer credentials; MFA required
    Unpatched CVE in gateway
    MediumHighMonthly patch cadence; emergency patch SLA 72 h
    Camera exposed to WAN
    LowHighCamera VLAN denies egress by default
    Risk matrix

    Common mistakes & troubleshooting

    Troubleshooting tips

    Delivery

    How it works

    1. Owner locked out

      Reset via signed vault procedure, not via factory reset.

    2. Logs missing

      Verify collector reachability from the site controller VLAN.

    Documentation requirements

    Documentation requirements

    Documentation deliverables
    • Access control list
    • Firmware baseline record
    • Patch history
    • Incident response runbook

      Maintenance timeline

      Maintenance timeline

      Delivery

      How it works

      1. Monthly

        Patch review; credential rotation for shared accounts.

      2. Quarterly

        Owner access review; port exposure re-scan.

      3. Annually

        Full pen-test on the smart-home surface.

      Version & change log

      Version 1.0

      Approval status: Approved · Effective date: 2026-01-15 · Last revision: 2026-07-08

      Author / Reviewer

      Author: Smart Citizens Engineering · Reviewer: Dr. Ashraf Nouri

      Change log

      v1.0 — 2026-07-08

      Initial published edition. (Smart Citizens Engineering)

      Frequently asked questions

      FAQ

      Frequently asked questions

      Do you support customer-owned devices?

      Yes — but only after they meet the Smart Citizens minimum hardening checklist.

      Is the customer notified of incidents?

      Yes — Smart Citizens follows a documented incident-response runbook that includes owner notification thresholds.

      Official citation
      How to cite
      Suggested citation
      Smart Citizens Engineering. "Cybersecurity Standard." Smart Citizens, 2026-01-15. https://ai.smartcitizens.ae/standards/cybersecurity-standard.
      Smart Citizens Engineering (2026). Cybersecurity Standard. Smart Citizens. Retrieved 2026-07-23, from https://ai.smartcitizens.ae/standards/cybersecurity-standard
      CategoryEngineering Standard
      AuthorSmart Citizens Engineering
      PublisherSmart Citizens
      Published2026-01-15
      Last updated2026-07-08
      VersionPlaceholder-ready
      Language
      en
      LicenseCC BY-NC 4.0 (unless noted)
      DOIPlaceholder-ready

      Design your smart environment with Smart Citizens

      Talk to Smart Citizens engineers for a bespoke design, budget estimate, and rollout roadmap.