
We have become remarkably comfortable putting internet-connected devices into almost every part of our lives.
Our televisions are connected. Our doorbells have cameras and microphones. Our vacuum cleaners map our homes. Solar inverters connect to cloud platforms. Baby monitors stream video. Cars increasingly resemble computers on wheels.
Yet when most of us buy these products, we have almost no practical way of knowing whether they have been designed securely.
That is why I think Australia’s new Security Labelling Scheme for Smart Devices is a fantastic initiative, and one that is becoming more important by the month.
The scheme, led by the Connected Technology Alliance and funded by the Australian Government’s Department of Home Affairs, will provide participating smart devices with a cyber security rating of up to four levels. The pilot begins in October 2026.
At the most basic level, products need to meet Australia’s mandatory security requirements. Higher ratings progressively recognise stronger authentication, secure communications and data storage, security-by-design practices and, at the highest level, penetration testing against common attacks.
In other words, cyber security starts becoming something an ordinary consumer can actually see and compare at the point of purchase.
That change is overdue.
When the router is the security problem
A particularly concerning example emerged in the United States recently.
Security researchers at VulnCheck investigated routers manufactured by Shenzhen Zhibotong Electronics, or ZBT, a Chinese manufacturer whose hardware is widely white-labelled and sold internationally under other brands.
This matters because the person buying the router may have no idea who actually manufactured it.
VulnCheck found firmware-level implants in a number of ZBT routers. One, dubbed ENDLESSDOORS, was enabled by default, started when the router booted and operated with root privileges. It attempted to contact command-and-control infrastructure, with inadequate authentication and encryption.
Further investigation of a white-labelled router sold by a US supplier uncovered two more implants. One could phone home and accept remote commands, while another exposed remote root-level command execution.
These were not simply devices that somebody had subsequently hacked. The functionality was present in the firmware supplied with the products.
The researchers subsequently traced ZBT hardware and associated supply chains across numerous countries, including Australia.
That should concern all of us.
A router occupies one of the most trusted positions in a home or small business. Almost everything else communicates through it. If the router itself cannot be trusted, securing the laptops, phones, cameras and other devices behind it becomes considerably harder.
It also demonstrates the problem with opaque technology supply chains. The logo printed on the plastic enclosure may tell you surprisingly little about who manufactured the hardware, wrote the firmware or operates the infrastructure with which it communicates.
Your vacuum cleaner can see more than you might think
The same issue is appearing in products we would traditionally never have considered cyber security devices.
Earlier this year, a software engineer experimenting with a DJI Romo robot vacuum reportedly discovered a vulnerability that gave him access to around 7,000 robot vacuums across 24 countries.
The potential access reportedly included live camera feeds, microphone audio, device information and maps of people’s homes.
DJI subsequently fixed the vulnerability.
The important point is not to single out one manufacturer. Vulnerabilities are found in technology products from companies and countries all over the world.
The lesson is that a modern robot vacuum is no longer simply a vacuum cleaner.
It can contain cameras, microphones, LiDAR, detailed maps of the inside of a house, Wi-Fi credentials, cloud connectivity and software capable of receiving remote instructions.
We need to start purchasing these products accordingly.
Cars may be the next major challenge
Connected vehicles take the issue to another level.
Modern vehicles can contain multiple cameras, microphones, GPS, Bluetooth, mobile network connectivity, driver information, contact details imported from phones, location histories and remotely updateable software.
The United States has already taken significant regulatory action around connected vehicle technology linked to China and Russia, based on concerns about access to sensitive data and the possibility of remote access to vehicle systems.
Those restrictions are now having a real impact on the automotive supply chain, and in September major automakers were again urging the US Congress to strengthen restrictions on Chinese connected vehicles and technology.
This should not be interpreted as evidence that a product is insecure simply because it was manufactured in China.
That would be both technically unsound and counterproductive.
The real issue is whether we know what a connected product is doing, where our data is going, who can access it, how long it will receive security updates, whether its software supply chain can be trusted and whether anybody independent has actually tested its security claims.
Those questions apply whether the device comes from Shenzhen, Seoul, Silicon Valley or Sydney.
Interestingly, connected vehicles are not part of Australia’s initial smart-device labelling scheme. The Australian Government has, however, identified connected vehicles as an area for further work under Horizon 2 of the Australian Cyber Security Strategy.
I think that expansion will be important.
Cyber security needs to become a purchasing criterion
The great strength of the new Australian scheme is not simply the technical standards behind it.
It is that it begins to turn cyber security into a consumer purchasing criterion.
We already understand this approach elsewhere.
We compare energy-efficiency ratings when buying appliances. We look at ANCAP safety ratings when buying cars. Food carries nutritional information. Electrical products must satisfy safety standards.
Those mechanisms work because they take something complicated and make it visible.
Cyber security has traditionally been different.
Consumers are effectively expected to research firmware policies, encryption standards, vulnerability-disclosure programmes, cloud architectures, software-support periods and manufacturer security practices before buying a $150 camera or $500 robot vacuum.
That is unrealistic.
Even technology professionals would struggle to properly evaluate every connected product they purchase.
A meaningful security label changes the economics.
If two otherwise comparable products are sitting next to each other and one carries a Level 4 cyber security rating while the other offers no meaningful evidence about its security, consumers have information on which they can make a decision.
Manufacturers then have a commercial reason to invest in better security.
That may ultimately be more powerful than simply telling consumers to use stronger passwords.
Security should be built in, not added later
Australia’s mandatory smart-device rules, which commenced on 4 March 2026, already establish an important baseline. They include requirements around issues such as unique passwords, vulnerability reporting and transparency about security updates.
The new labelling scheme builds on that foundation by allowing manufacturers that go further to demonstrate it.
This reflects an important change in cyber security thinking.
For too long we have placed much of the responsibility on the consumer: change your password, configure your firewall, install the update, check the settings, secure your network.
Those things remain important, but there is only so much a consumer can do with an inherently insecure product.
If a device leaves the factory containing an unauthenticated remote-control mechanism operating with root privileges, no amount of password education is going to fix the underlying problem.
Security needs to be designed into the product.
It needs to be secure by default.
It needs to be maintained throughout the product’s useful life.
And increasingly, manufacturers should be expected to prove it.
A very welcome step
The number of connected devices surrounding us is only going in one direction. NBN Co has cited research suggesting broadband households already contain around 25 connected devices on average, with that number expected to reach 44 by 2030.
Many of these devices will spend years sitting quietly on our networks.
Some will have cameras.
Some will have microphones.
Some will know when we are home.
Some will know where we are.
Some will control physical systems in our houses.
And some, increasingly, will transport our families.
We should know whether we can trust them.
Australia’s Security Labelling Scheme for Smart Devices will not solve every IoT security problem, and I would like to see the concept progressively extended as connected technology moves into more parts of our lives.
But it introduces something that has been badly missing from the consumer technology market: visibility.
Cyber security should not be buried on page 47 of a technical specification, discovered in a researcher’s vulnerability report years after purchase, or left entirely to consumers to work out for themselves.
It should be visible on the box.
And it should influence what we buy.
This article was prompted by David Braue’s Information Age reporting on Australia’s new smart-device cyber security rating scheme, published by the Australian Computer Society on 8 September 2026.