Search the blog
A video doorbell, a couple of cameras, a smart speaker, the router the broadband company posted to you, and a television that is more computer than screen. That is an ordinary UK household now, and every one of those devices is a small computer on your network that you never log in to, never update and probably set up in a hurry with the app.
Two things have changed. Since 29 April 2024 the law has required manufacturers to meet a security baseline before they can sell a connected product in the UK, so a new device should no longer arrive with "admin/admin" on a sticker. And the Information Commissioner's Office (ICO), backed by a county court judgment, has made it clear that a doorbell camera pointing at the street is your legal responsibility, not the manufacturer's. This article explains both, then gives the settings we change when we set up home networks and cameras.
What the PSTI law actually requires
The Product Security and Telecommunications Infrastructure Act 2022 (PSTI) and its 2023 Regulations came into force on 29 April 2024 (DSIT, 2024). They apply to "relevant connectable products", which the Act defines broadly as anything capable of connecting to the internet, plus devices that talk to such a product over a non-internet link such as Zigbee or Bluetooth (UK Parliament, 2022). The three requirements are taken from the top of the government's earlier Code of Practice for consumer Internet of Things (IoT) security and match the international standard ETSI EN 303 645 (DSIT, 2024):
- No universal default passwords. A password must be either unique to each unit or set by you. A "unique" password may not be a simple counter, may not be derived from public information, and may not be derived from the serial number unless it is properly hashed (Legislation.gov.uk, 2023).
- A way to report security problems. The manufacturer must publish a point of contact for reporting vulnerabilities, say when the reporter will get an acknowledgement, and provide status updates until the issue is fixed (Legislation.gov.uk, 2023).
- A published security update period. The manufacturer must state the minimum period during which it will provide security updates, in English, free of charge, without asking for your personal details, and "in such a way that is understandable by a reader without prior technical knowledge" (Legislation.gov.uk, 2023).
The duties fall on manufacturers, importers and distributors, so a UK retailer selling an unlabelled device from an overseas marketplace is also on the hook. Products must be accompanied by a statement of compliance, which may be digital (DSIT, 2024). The Office for Product Safety and Standards (OPSS) enforces the regime, and the Act allows penalties of up to the greater of £10 million or 4% of worldwide revenue, with a further daily penalty of up to £20,000 while a breach continues (UK Parliament, 2022).
What it does not cover
The law is deliberately narrow.
- It is a floor, not a guarantee of quality. A device can be fully compliant with a two-year update period. The law only makes the manufacturer tell you the number.
- Excepted products. Desktop and laptop computers, tablets without a mobile-data connection, electric-vehicle charge points, medical devices and smart meters are outside the regime, as are products for Northern Ireland that already meet the equivalent EU rules. Since 25 February 2025 cars, motorbikes and agricultural vehicles have been excepted too (DSIT, 2024; Legislation.gov.uk, 2023).
- It does not reach back. Devices bought before April 2024 are as they were.
- Compliance is patchy. When Which? surveyed 128 smart-device brands in June 2024, 29 (23%) had not published a support policy or answered the question, and a further 23 had policies with no clear guaranteed period. Among camera brands, Ezviz committed to supporting its wireless cameras until 2031 and Ring to four years, while Arlo and Ubiquiti appeared to have no published policy (Which?, 2024). We have not repeated that survey, so check the current page for any device before you buy.
Doorbell cameras and the neighbours: the part people miss
A camera that only sees your own hallway is nobody's business but yours. A doorbell that records the pavement, the shared driveway or the house opposite is different. The ICO's position is that if you cannot avoid capturing "someone else's property, a public area or communal space, then data protection law applies" and you are responsible for the personal information you record (ICO, n.d.). In practice that means a clear reason for the camera, not capturing more than you need, a sign, deleting footage regularly or automatically, handing over recordings in most cases if a person captured asks, and stopping recording someone who objects when you have no legitimate reason to continue (ICO, n.d.).
The ICO also says what it will not do: it will not remove or reposition a neighbour's camera, retrieve footage for you, or take court action on your behalf (ICO, n.d.). That is where Fairhurst v Woodard comes in. In October 2021 a judge at the County Court at Oxford found that a homeowner with a Ring doorbell, two Ring spotlight cameras and a Nest camera had breached data protection law and harassed his neighbour. The judgment records that the doorbell could reliably capture audio at about 68 feet and the shed camera at around 53 feet, and that "it was not possible to turn off the audio recording facility on these devices" at the time, so conversations in the neighbour's garden and parking spaces were "susceptible to being heard and recorded" (County Court at Oxford, 2021). The lesson is not that doorbells are illegal; it is that a camera's field of view and microphone range are legal facts, not marketing features.
Most current cameras and doorbells let you switch audio off and draw "privacy zones" that black out a neighbour's window or door. Use them. If you are installing cameras for a business, the rules are stricter again, and our CCTV and security service handles the signage and retention side as part of the job.
The checklist
The table below is what we do on a home visit, in the order we do it. Most items take under five minutes each.
| Area | Do this | Why |
|---|---|---|
| Router | Change the admin password from the one on the sticker; turn off remote management; switch on automatic firmware updates; replace an old ISP router that no longer gets them | The admin login controls every other device |
| Wi-Fi | Use WPA3 (or WPA2 if a device cannot join) with a long passphrase you do not share with visitors | Old WPA/WEP is trivially cracked |
| Guest network | Put cameras, plugs, speakers and TVs on the guest or IoT network, away from laptops and phones | A hacked bulb cannot reach your bank login |
| UPnP and port forwarding | Turn both off unless you know you need them | NCSC advises it; they open holes from outside |
| Every device | Change any default password to three random words; turn on 2-step verification wherever offered | Stops most account takeovers |
| Cameras and doorbells | Automatic updates on; remote viewing off if unused; audio off unless needed; privacy zones set | Privacy, and the ICO obligations above |
| Storage | Local (memory card or base station) or a cloud plan with 2-step verification; automatic deletion on | Limits what is lost if an account is breached |
| Support period | Before buying, find the stated update period and put the end date in your calendar | The law obliges them to publish it |
Two rows deserve a word more. The NCSC's advice for smart devices is short: create your own password, change any default, and "if the device or app offers 2-step verification (2SV), turn it on" (NCSC, 2019). Its camera guidance notes that some cameras ship with a default such as "admin or 00000", exactly what the PSTI rules now prohibit, and recommends disabling remote viewing if you do not need it and turning off UPnP and port forwarding on the router (NCSC, 2020).
On storage, cloud recording survives a burglar taking the camera; local storage keeps footage in your house and off a subscription. Neither is wrong. What matters is that the account controlling the footage has a unique password and 2-step verification, and that old clips are deleted automatically, so a breach or a request for footage only ever involves a few days of video. And the guest network is the most effective change on the list: the day one of those devices stops getting updates, it is isolated rather than sitting next to your laptop.
When a device stops getting updates
The NCSC suggests treating the manufacturer's support date as a "use by" date: after it, the device becomes "easier to hack, or may stop working altogether" (NCSC, 2019). Our order of preference is:
- Check whether the manufacturer has extended support; the regulations require any extension to be published (Legislation.gov.uk, 2023).
- If the device only talks to your own network (a printer, a bridge, an older camera recording to a local box), keep it on the guest network and disable remote access. Not ideal, but contained.
- If it needs the internet to work, or it is the router itself, replace it. An unsupported router is the one device we will not leave in place.
- Factory-reset whatever you retire, as the NCSC advises before any device changes hands (NCSC, 2019), and take it to an electrical recycling point rather than the bin.
What this means for you
If you buy a camera or doorbell today, the manufacturer must publish how long it will receive security updates; if you cannot find the number, buy a different one. Once it is up, twenty minutes on the router, the guest network and 2-step verification is worth more than any feature on the box. If the camera can see anything that is not yours, treat the ICO list as a to-do list, starting with the sign and automatic deletion. And keep the 3-2-1 backup rule running alongside: the backup keeps a copy of what matters, and the settings above keep strangers out of the rest.
If you would rather someone did it with you, that is a single home visit: router, Wi-Fi, guest network, every camera and doorbell checked, and a one-page sheet listing what runs where and when its support ends. For business premises, start with our CCTV and security page or contact us.
Sources
- County Court at Oxford (2021) Fairhurst v Woodard, Case No. G00MK161, judgment of HHJ Melissa Clarke, 12 October 2021. https://www.skadden.com/-/media/files/publications/2021/10/privacy-cybersecurity-update/fn5_fairhurstvwoodardjudgment1.pdf (accessed 25 August 2026).
- Department for Science, Innovation and Technology (DSIT) (2024) Regulations: consumer connectable product security. GOV.UK guidance. https://www.gov.uk/guidance/regulations-consumer-connectable-product-security (accessed 25 August 2026).
- Information Commissioner's Office (ICO) (n.d.) Home CCTV systems. https://ico.org.uk/for-the-public/home-cctv-systems/ (accessed 25 August 2026).
- Legislation.gov.uk (2023) The Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023. https://www.legislation.gov.uk/ukdsi/2023/9780348249767 (accessed 25 August 2026).
- National Cyber Security Centre (NCSC) (2019) Smart devices: using them safely in your home, 15 February 2019, reviewed 23 February 2024. https://www.ncsc.gov.uk/guidance/smart-devices-in-the-home (accessed 25 August 2026).
- National Cyber Security Centre (NCSC) (2020) 'Smart' security cameras: using them safely in your home, 3 March 2020. https://www.ncsc.gov.uk/guidance/smart-security-cameras-using-them-safely-in-your-home (accessed 25 August 2026).
- UK Parliament (2022) Product Security and Telecommunications Infrastructure Act 2022, c. 46. https://www.legislation.gov.uk/ukpga/2022/46 (accessed 25 August 2026).
- Which? (2024) How long will your smart tech last? Big brands fail to deliver on new laws, 20 June 2024. https://www.which.co.uk/news/article/how-long-will-your-smart-products-last-big-brands-fail-to-deliver-on-new-security-laws-atIYq4m4VP09 (accessed 25 August 2026).