Securing Thread Network

Has anyone done a security audit for Thread? Or recommended resources?

I’m thinking if I setup a thread network with TBR and add a malicious device on it. Is there a way to firewall that TBR without firewalling the host itself? (Think AppleTV, ZBT-1 or ZBT-2)