Join our Newsletter — 33% off our NHI Course

SOHO Device

A small office or home office device such as a router, gateway, or internet-connected appliance used outside central enterprise control. These devices often sit outside normal patching and monitoring processes, which makes them attractive relay points for attackers.

Expanded Definition

A SOHO device is any small office or home office router, gateway, firewall, printer, camera, NAS, or connected appliance that is deployed outside the normal enterprise control plane. In NHI and IAM conversations, the term matters because these devices often contain embedded credentials, expose administrative interfaces, and act as network trust anchors without the governance applied to managed assets. The security issue is not the form factor alone, but the combination of weak inventory, inconsistent patching, and limited logging. Guidance varies across vendors on whether a SOHO device should be treated as an endpoint, a network device, or an IoT asset, so classification should be based on exposure, identity material, and update authority rather than label alone. That distinction aligns with broader control thinking in the NIST Cybersecurity Framework 2.0 and with identity governance themes in the Ultimate Guide to NHIs. The most common misapplication is assuming a SOHO device is low risk because it is small, which occurs when remote management, default credentials, or hidden service exposure are overlooked.

Examples and Use Cases

Implementing SOHO device controls rigorously often introduces operational friction, because tighter access, patching, and monitoring can disrupt convenience for distributed teams and home users.

  • A home office router reused as a VPN edge device becomes a pivot point if its admin password and firmware updates are never governed.
  • A branch printer or camera with cloud access is enrolled as a business asset, but its embedded token is never rotated or inventoried alongside other secrets.
  • A contractor-operated gateway is allowed to bridge into internal systems, yet it is missing centralized logging and change approval.
  • A smart appliance in a remote office is discovered to hold static credentials that were copied into provisioning scripts and never removed.
  • Security teams compare device exposure against identity and access patterns using the Ultimate Guide to NHIs alongside the NIST Cybersecurity Framework 2.0 to identify unmanaged trust edges.

These use cases show why SOHO devices are often treated as transitional assets that need explicit ownership, logging, and retirement criteria instead of informal user discretion.

Why It Matters in NHI Security

SOHO devices matter because they frequently sit at the boundary between human convenience and machine trust, which is exactly where credential leakage and unmanaged access begin. When these devices are not included in asset inventories, they can hold passwords, API keys, certificates, or admin tokens that never appear in standard reviews. That creates blind spots for service access and lateral movement, especially when remote administration is enabled or default identities remain active. NHIMG research shows that 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, and SOHO devices are often part of that same weak perimeter. The Ultimate Guide to NHIs also highlights that 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, which makes unmanaged edge devices especially relevant to identity compromise chains. Organisational risk increases when a device is treated as disposable infrastructure instead of a governed identity-bearing asset. Practitioners typically encounter the full impact only after an incident review reveals that the initial foothold came through a forgotten router, camera, or gateway, at which point SOHO device governance becomes operationally unavoidable.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
OWASP Non-Human Identity Top 10 NHI-01 SOHO devices often store or expose machine credentials and unmanaged secrets.
NIST CSF 2.0 ID.AM Device inventory and ownership are central to identifying SOHO assets in scope.
NIST Zero Trust (SP 800-207) SC-7 SOHO devices can become trust boundaries that must be isolated under Zero Trust.
NIST SP 800-63 Administrative access to SOHO devices should follow strong authenticator assurance.
OWASP Agentic AI Top 10 A-03 Agentic workflows can amplify risk when they interact with unmanaged SOHO devices.

Inventory SOHO devices that hold identity material and remove embedded credentials from unmanaged edge assets.