Nowadays IoT devices are ubiquitous, bringing convenience in our lives. However, security and privacy issues due to vulnerabilities in the devices remain a major concern. This talk presents a systematic way of analyzing vulnerabilities in an IoT network using attack graph, and how an effective defense strategy can be found using limited budgets.