Protect firmware, networks, sensors, update channels, credentials, and physical interfaces from attack. Build a threat model and apply secure boot, signed updates, least privilege, segmentation, and incident response.