The Internet of Things (IoT) connects physical devices to networks so they can collect, exchange, and act on data. Connected devices can include printers, cameras, sensors, smart building systems, medical equipment, vehicles, and industrial equipment.
For businesses, IoT can improve efficiency, automate processes, and provide valuable data. But every connected device can also introduce cybersecurity and privacy risks.
IoT security is the practice of protecting connected devices, the data they collect, and the networks and systems they connect to.
Why is IoT security important?
IoT devices can create additional pathways into a network. If a device is compromised, an attacker may be able to use it to access data, disrupt operations, or launch attacks against other systems.
The risk can be greater when an organization has many connected devices to manage. Different devices may use different software, operating systems, network connections, and security controls.
NIST notes that IoT devices can create new pathways into and out of the networks where they are used, making it important to consider the security of the devices, their data, interfaces, and connected systems.
What are the biggest IoT security risks?
IoT security risks can vary depending on the device and how it is used. Common concerns include:
Weak authentication
Devices with weak, reused, or default credentials can be easier for attackers to compromise.
Organizations should use strong authentication and change default credentials when appropriate.
Unpatched software
Like computers and other connected technology, IoT devices can contain software vulnerabilities.
Manufacturers and organizations should have a process for applying security updates and addressing vulnerabilities throughout the device's supported lifecycle.
Insecure network connections
An IoT device that communicates over an insecure connection may expose information or provide attackers with an opportunity to interfere with communications.
Network protections and appropriate encryption can help reduce these risks.
Poor access controls
Not every user or device needs access to every system or piece of information.
Organizations should limit access based on what each device, application, and user actually needs.
Insufficient device security
Some IoT devices may have limited security capabilities or make it difficult for customers to manage security effectively.
NIST's current IoT guidance emphasizes that manufacturers can help by building appropriate cybersecurity capabilities into products and providing customers with the information they need to secure and maintain them.
Lack of support and end-of-life planning
An IoT device can remain in service for years. Organizations should understand how long a manufacturer will provide security updates and what happens when the device reaches the end of its supported life.
A device that can no longer receive necessary security updates may eventually become a security liability.
How can businesses improve IoT security?
IoT security starts before a device is connected to the network.
1. Know what devices are connected
Maintain an inventory of IoT devices used throughout the organization.
Record information such as:
- Device type and location
- Manufacturer and model
- Software or firmware version
- Network connection
- Business purpose
- Owner or responsible team
- Security update and support status
You cannot effectively secure devices you do not know are connected to your environment.
2. Evaluate security before purchasing
Security should be part of the purchasing decision, not something considered after a device is deployed.
When evaluating an IoT product, ask:
- Does the device support strong authentication?
- How are software and security updates delivered?
- Does the manufacturer provide security support?
- How long will the product be supported?
- Can unnecessary services or connections be disabled?
- What security information does the manufacturer provide?
- What happens when the device reaches end of life?
NIST's 2026 guidance specifically encourages manufacturers to consider cybersecurity activities before products reach customers and throughout the product's lifecycle.
3. Keep devices updated
Install available firmware and software updates according to the manufacturer's recommendations.
Organizations should also monitor for security advisories affecting their connected devices and have a process for responding to vulnerabilities.
4. Use strong authentication and access controls
Protect administrative accounts with strong authentication and, when supported, multi-factor authentication.
Limit administrative access to the people who need it, and avoid using shared accounts whenever possible.
5. Segment IoT devices from other systems
Where appropriate, organizations can use network segmentation to separate IoT devices from critical business systems.
Segmentation can help limit what an attacker can reach if an IoT device is compromised.
The right network design depends on the organization's environment and the purpose of the connected devices.
6. Monitor connected devices
Monitor IoT devices for unusual activity, unexpected connections, and other signs of compromise.
An unexpected change in device behavior may indicate a security problem.
7. Plan for device retirement
IoT security does not end when a device is removed from service.
Organizations should have a process for securely removing devices, credentials, stored information, and network access when equipment is replaced or retired.
What should IoT manufacturers do?
IoT security is a shared responsibility between manufacturers, organizations, and users.
Manufacturers can improve security by considering cybersecurity throughout product development and providing customers with the capabilities and information needed to secure and maintain their devices.
Current NIST guidance recommends that manufacturers address cybersecurity activities before and after products reach customers, including areas such as risk assessment, security support, maintenance, and communicating cybersecurity information to customers.
NIST also maintains a core baseline of technical and supporting capabilities that can help organizations evaluate the cybersecurity capabilities of IoT products.
What happens if an IoT device is hacked?
The consequences depend on the device and the systems connected to it.
A compromised IoT device could potentially be used to:
- Steal or expose information
- Access other systems
- Disrupt business operations
- Monitor activity
- Modify device behavior
- Become part of a botnet
- Launch attacks against other systems
For devices that control or monitor physical environments, the consequences can extend beyond data security. An attack could potentially affect equipment, facilities, or other physical processes.
This is why organizations should consider both cybersecurity and operational risks when deploying connected devices.
IoT security FAQs
What is IoT security?
IoT security is the practice of protecting internet-connected devices, the data they handle, and the networks and systems they connect to.
Why are IoT devices vulnerable?
IoT devices can have different hardware, software, network connections, and security capabilities. Some may also have limited resources for security or remain deployed for many years. Poor authentication, outdated software, insecure configurations, and inadequate manufacturer support can increase risk.
How can I secure an IoT device?
Use strong authentication, keep the device updated, change default credentials, limit unnecessary network access, monitor for unusual activity, and follow the manufacturer's security recommendations.
Should IoT devices be on a separate network?
Network segmentation can be useful for limiting the potential impact of a compromised IoT device. Whether and how to segment devices depends on the organization's infrastructure and security requirements.
Who is responsible for IoT security?
IoT security is a shared responsibility. Manufacturers should provide appropriate security capabilities and support, while organizations and users need to configure, update, monitor, and retire devices appropriately.
The bottom line
IoT can provide significant benefits for businesses, but every connected device can introduce additional security considerations.
A strong IoT security strategy starts with knowing what devices are connected and understanding the risks they introduce. From there, organizations should evaluate security before purchasing devices, use strong authentication and access controls, keep software updated, monitor devices, segment networks where appropriate, and plan for the full lifecycle of each product.
IoT security is not a one-time task. Connected devices need to be secured and maintained throughout their useful life.