Cybersecurity Standard
Baseline hardening, credential and update policies for every Smart Citizens smart home.
The essentials
- Zero default passwords in the field
- MFA on every remote-access account
- Firmware baseline enforced monthly
- Segmented network by policy
- Logs retained for 90 days minimum
Purpose
Prevent smart-home devices from being the entry point into the customer's digital life.
Scope
All Smart Citizens deployments and every device we deliver, integrate, or support.
Design principles
Principle 1
Least privilege — every account gets the minimum it needs
Principle 2
Defence in depth — network + device + application
Principle 3
Assume breach — plan for detection and containment, not only prevention
Principle 4
Patch, don't rely on obscurity
Engineering requirements
Engineering requirements
- No factory or default passwords in production
- Unique credentials per device where supported
- MFA on all engineer and owner remote-access accounts
- Firmware update policy documented per device family
- Central logging with 90-day retention
- WPA3 on Wi-Fi where supported (WPA2-AES otherwise)
Best practices
Vault
Vault: All secrets in the Smart Citizens vault
Rotation
Rotation: Rotate engineer credentials on staff change same-day
Access review
Access review: Owner reviews access list quarterly
Cameras
Cameras: Cameras on their own VLAN with strict egress
Installation workflow
Installation workflow
How it works
1. Change defaults
Change every factory password before dispatch.
2. Register vault entries
Store new credentials in the vault, tagged by site.
Configuration & programming workflow
Configuration & programming workflow
How it works
1. Apply hardening
Disable unused services on every gateway (Telnet, UPnP, WPS).
2. Enable logging
Forward logs to the central collector.
3. Enforce MFA
Require MFA on the customer portal at first login.
Commissioning steps
Commissioning steps
How it works
1. Port scan
Scan the site from IoT and guest VLANs; confirm expected exposure only.
2. Credential audit
Confirm no default credentials remain.
3. Log verification
Confirm logs are arriving at the collector.
Validation checklist
Validation checklist
- No default passwords anywhere on site
- MFA active on all remote accounts
- Firmware at approved baseline
- Logs arriving at central collector
- Leaving factory passwords
- Sharing engineer credentials
- Skipping firmware updates
Quality assurance checklist
Vault entry
Every device has a vault entry with rotation date.
Port exposure
External exposure matches the approved list.
Acceptance criteria
| Feature | Target | Verification method | Priority |
|---|---|---|---|
No default credentials | 0 | Scanner report | High |
MFA coverage | 100% | Portal audit | High |
Log delivery | >= 99% of events | Collector metrics | Medium |
Risk matrix
| Feature | Likelihood | Impact | Mitigation |
|---|---|---|---|
Shared engineer credential | Medium | High | Per-engineer credentials; MFA required |
Unpatched CVE in gateway | Medium | High | Monthly patch cadence; emergency patch SLA 72 h |
Camera exposed to WAN | Low | High | Camera VLAN denies egress by default |
Common mistakes & troubleshooting
Troubleshooting tips
How it works
Owner locked out
Reset via signed vault procedure, not via factory reset.
Logs missing
Verify collector reachability from the site controller VLAN.
Documentation requirements
Documentation requirements
- Access control list
- Firmware baseline record
- Patch history
- Incident response runbook
Maintenance timeline
Maintenance timeline
How it works
Monthly
Patch review; credential rotation for shared accounts.
Quarterly
Owner access review; port exposure re-scan.
Annually
Full pen-test on the smart-home surface.
Version & change log
Version 1.0
Approval status: Approved · Effective date: 2026-01-15 · Last revision: 2026-07-08
Author / Reviewer
Author: Smart Citizens Engineering · Reviewer: Dr. Ashraf Nouri
Change log
v1.0 — 2026-07-08
Initial published edition. (Smart Citizens Engineering)
Frequently asked questions
Frequently asked questions
Do you support customer-owned devices?
Yes — but only after they meet the Smart Citizens minimum hardening checklist.
Is the customer notified of incidents?
Yes — Smart Citizens follows a documented incident-response runbook that includes owner notification thresholds.
Smart Citizens Engineering. "Cybersecurity Standard." Smart Citizens, 2026-01-15. https://ai.smartcitizens.ae/standards/cybersecurity-standard.
Smart Citizens Engineering (2026). Cybersecurity Standard. Smart Citizens. Retrieved 2026-07-23, from https://ai.smartcitizens.ae/standards/cybersecurity-standard
Design your smart environment with Smart Citizens
Talk to Smart Citizens engineers for a bespoke design, budget estimate, and rollout roadmap.
