Smart Devices Are Everywhere – But Are They Secure?
From smart home cameras and video doorbells to Wi-Fi routers and connected appliances, Internet of Things (IoT) devices have become part of everyday life. While these devices offer convenience, they can also become targets for cybercriminals if they are not properly secured.
To help consumers make informed choices, Singapore introduced the Cybersecurity Labelling Scheme (CLS), administered by the Cyber Security Agency of Singapore (CSA). The CLS allows consumers to easily identify smart devices that have undergone cybersecurity assessment and meet recognised security requirements.
When shopping for smart devices, the CLS label provides a simple way to understand the level of cybersecurity protection built into the product.
Why Does Singapore Need It?
Cybercriminals often target poorly secured IoT devices because they are easier to compromise than traditional IT systems.
Globally, IoT cyberattacks have continued to rise as more connected devices enter homes and businesses. Weak passwords, outdated software, and insecure configurations can expose users to risks such as:
- Unauthorised access to devices
- Data theft and privacy breaches
- Malware infections
- Devices being recruited into botnets for larger cyberattacks
As digital adoption accelerates, Singapore has taken a proactive approach by encouraging manufacturers to build security into their products from the start.
What Is the Cybersecurity Labelling Scheme (CLS)?
The Cybersecurity Labelling Scheme is a voluntary labelling programme developed by the Cyber Security Agency of Singapore (CSA).
Devices certified under the scheme receive a cybersecurity label that indicates the level of security testing and assurance completed.
For consumers, the label serves as a simple indicator that cybersecurity has been considered during the product’s design and development.
Understanding the Four CLS Levels
The CLS currently consists of four assurance levels:
Level 1
The manufacturer declares that the device meets baseline cybersecurity requirements.
Level 2
The device undergoes independent testing by an approved third-party laboratory.
Level 3
The device is tested against internationally recognised security standards and undergoes more rigorous assessment.
Level 4
The highest level of assurance under CLS, involving comprehensive security evaluation and certification.
Higher levels provide greater confidence that the product has undergone more extensive cybersecurity scrutiny.
How Does a Device Qualify?
Depending on the assurance level, manufacturers may need to demonstrate:
- Secure default settings
- Strong password controls
- Secure software development practices
- Regular security updates and patch management
- Protection of user data
- Vulnerability management processes
- Secure communications and encryption
These requirements help reduce common cybersecurity weaknesses found in connected devices.
Do the Standards Change Over Time?
Yes. Cyber threats continue to evolve, and cybersecurity requirements must evolve as well. CSA periodically reviews and updates security criteria to ensure that the scheme remains relevant against emerging threats.
Manufacturers may need to reassess products or obtain recertification to maintain compliance with updated requirements.
What Types of Devices Are Covered?
The Cybersecurity Labelling Scheme currently applies to various consumer IoT products, including:
- Smart home hubs
- Smart cameras
- Video doorbells
- Wi-Fi routers
- Smart locks
- Smart lighting systems
- Other connected consumer devices
The scheme continues to expand as more categories of smart devices become eligible.
How Does the Label Help Consumers?
The CLS makes cybersecurity easier to understand.
Instead of researching technical specifications or security features, consumers can simply look for the cybersecurity label when comparing products.
Benefits include:
- Greater confidence in purchasing decisions
- Improved awareness of cybersecurity risks
- Encouragement for manufacturers to improve product security
- Better protection for homes and personal information
What If a Device Doesn’t Have the Label?
A device without a CLS label is not necessarily insecure.
However, consumers should take additional steps to evaluate the device, such as:
- Checking whether security updates are provided regularly
- Reviewing the manufacturer’s security track record
- Ensuring strong password controls are available
- Reading independent reviews and security assessments
Where possible, choosing a labelled product can provide additional assurance.
What Should You Do If You Already Own Smart Devices?
Even if your devices are not CLS-certified, you can still improve their security.
Some good cybersecurity practices include:
- Change default passwords immediately
- Enable multi-factor authentication where available
- Keep firmware and software updated
- Disable unused features and services
- Secure your home Wi-Fi network
- Remove devices that no longer receive security updates
These simple steps significantly reduce cyber risk.
The Future of Smart Device Security
As more devices become connected, cybersecurity will become increasingly important.
We can expect:
- Stronger security requirements
- More product categories covered under certification schemes
- Greater international alignment between cybersecurity labels
- Increased consumer awareness of cyber risks
The long-term goal is to make secure-by-design products the industry standard rather than the exception.
Stay Safe and Shop Smart
The Cybersecurity Labelling Scheme helps consumers make more informed decisions when purchasing connected devices.
The next time you’re shopping for a smart home device, look out for the CSA Cybersecurity Label. It is a quick and easy way to identify products that have undergone cybersecurity assessment and provide a higher level of assurance.
Cybersecurity starts with informed choices. A few minutes of checking today can help prevent significant problems tomorrow.











