All advisories

Technology Advisories

Advisory

Smart devices need clear boundaries on your business network

TVs, cameras, printers, and connected building devices should have only the access their business purpose requires.

Published:

These advisories provide general guidance. They do not announce a live incident or confirm a client breach.

Why segmentation matters

The Canadian Centre for Cyber Security recommends isolating IoT networks and restricting their access to systems handling sensitive information. Separating devices can reduce the reach of a compromised device. Updates, secure credentials, and lifecycle management remain necessary.

A separate network name is only the beginning

Ginga’s assessment can examine enforced firewall rules between device groups. A separate Wi-Fi name or VLAN is not a complete boundary if traffic can still reach every business system. The design should document allowed connections, administration access, internet needs, and exceptions.

Keep business operations in view

Inventory each device’s owner, purpose, model, software support, and dependencies. Printing, casting, recording, and vendor maintenance may require specific connections. Agree on those needs before changing access, then validate both permitted and blocked traffic during a planned change window.

Medical equipment, access controls, alarms, and building systems may have safety or vendor requirements. Their owners and vendors should participate in planning. A written rollback plan helps protect continuity if an expected function stops working.

Example client response

“We can assess how your connected devices are separated from business systems under your support agreement and plan any changes around your operations.”

Sources & further reading