By default, the *Sense line is secure out of the box, so long as you keep it up to date by applying regular patches to it via the web ui. This is due to the out-of-box default block all incoming rule. That being said, there are various benchmarks out there you can follow to make sure everything is up to snuff. Center For Internet Security (CIS) has a pretty robust set of guidelines out there, including one for *Sense that tend to be beginner friendly.
Setting up VLANs for different devices with appropriate firewall rules are also best practice for controlling what can talk to each other and scoped to various ports and protocols. When you say "first steps", this is what really comes to mind, at least for me. Build out a set of three VLANs for trusted devices, IoT devices, and guest users, then go from there. Typically these networks are easy to setup because all three are segregated from each other and generally don't have line of site to the other's network. Eventually, you'll want to setup a server network and allow devices on the trusted net to communicate with each other. That's always fun to setup and you learn very quickly what ports and protocols need allowed for various things. The logs, vendor's whitepapers, and an AI assistant can help you out with crafting these rules. I can't tell you what you'll need, because you run different things than me, I'm sure.
Once you get things separated out, you mentioned you want to monitor and nanny devices on those networks. Look into deploying Zen Armor. They have great beginner friendly web filtering and monitoring you can slap into your firewall for free (or $10 bucks a month if you spring for it). That'll give you all the automation, pretty graphs and monitoring tools you need to keep an eye on things at a basic level.
Things are as secure as you make them. Harden for people doing stupid things in your home. There's no such thing as "overdoing" security, but your stance should be catching and filtering out the occasional bad link someone clicks on, not defending against nation states. Keep ports closed, and if you want something to be available publicly, route it through a Cloudflare Tunnel and secure it with Cloudflare Access if you don't want anyone else to see it.
Wow, this is a wall of text, but I hope this points you in the right direction. Feel free to ping me if you need help or further direction!