I’ve been told that I should put my IoT devices on a separate VLAN from everything else, but what other steps can I take to make sure that my devices don’t get hacked?

Note: I will be using a dedicated wifi router for my IoT and hooking that up (on it’s own VLAN) to a OPNsense firewall server. I’m using a dedicated router for this because 1. I have an extra one and 2. my IoT requires both wifi and ethernet connections. Right now Google is controlling my IoT but I hope to set up my own app for it at some point.