Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • IoT and IIoT Security: Some Tech Truths are Evergreen current page
Link copied

IoT and IIoT Security: Some Tech Truths are Evergreen

Jul 16, 2021
Author:
DK Face 2023
Diana Kelley
CSO2 (Chief Strategy Officer/Chief Security Officer) and co-founder of Cybrize, Executive Mentor, Research Analyst, Security Keynote Speaker
Blog banner default
IoT and IIoT Security: Some Tech Truths are Evergreen
DK Face 2023
Diana Kelley
CSO2 (Chief Strategy Officer/Chief Security Officer) and co-founder of Cybrize, Executive Mentor, Research Analyst, Security Keynote Speaker

Last year, I was asked to start a book club to help our team at Microsoft constructively process and cope with the confusion and fear many of us felt during the early weeks of the pandemic. Of course, since we were a cybersecurity-focused team, I put cybersecurity-focused books on the reading list. A colleague of mine picked Cliff Stoll’s classic, The Cuckoo’s Egg and, when it was my turn, I went with Simon Singh’s The Code Book. What’s wonderful about both of these books is how they illustrate core and underlying principles of cybersecurity that impact threat models today.

Stoll’s book tells the story of a real-world attack by a German threat actor who infiltrated a computer at the Lawrence Berkeley National Laboratory (LBNL) by exploiting a vulnerability at MITRE. Stoll was alerted to the attack due to a discrepancy in the billing system. If you haven’t read Stoll’s book, you may be surprised that the attack occurred in 1986. You read that right: it happened 35 years ago.

Singh’s book, also non-fiction, is a historical review of cryptography and the underlying principles of cryptanalysis. Singh explains how modern-day code-breaking rests on the same established practices and techniques that have been used for centuries; even when those techniques have been updated to meet current technology, as is the case with quantum computing and quantum resistant-cryptography.

While doing that book club, I noticed a couple of people left the discussions early on. Wanting to make the book club enjoyable for all, I followed up and asked why. The answer: “those old books have nothing to do with today’s modern cloud enterprise.”

While it’s true that technology is moving rapidly in many ways, it’s also true that today’s cloud-based networks have been built on technology from the past. Access control and identity-based authorization is the touchstone of Zero-Trust Architecture (ZTA); it’s also the foundation of the Resource Access Control Facility or RACF, introduced by IBM back in 1976. And an attacker from another country getting through to US government systems sounds pretty current, if you pay attention to recent headlines.

If we don’t learn the lessons of the past, we’re doomed to repeat the same mistakes. This holds true for newer technologies like IoT and IIoT (industrial Internet of things).

Every day, users interact with consumer IoT, like connected cars, televisions, and lights. On the industrial IoT side, IIoT includes building automation systems, shop floor automation devices, and smart energy grid sensors, which may be components of operational technology (OT) environments. While a thorough risk analysis requires understanding context and a drill down into the different environments and use cases - it’s also helpful to build a baseline understanding of common risks that apply to all devices in the IoT/IIoT ecosystem.

A robust foundation of persistent risks and threats provides defenders with a strong platform on top of which they can build customized threat models. This is why, a few years ago when I was working at IBM, I collaborated with other IoT experts to enumerate Five Indisputable Facts of IOT Security. By addressing these evergreen facts first, experts tasked with building or deploying secure IoT and IIoT can get a leg up on the design process.

The five indisputable facts are:

  1. Devices will operate in hostile environments
  2. Software security will degrade over time
  3. Shared secrets do not remain secret
  4. Weak configurations will persist
  5. As data accumulates, exposure issues will increase

To hear more about the five facts and to learn how to mitigate these risks to build secure, resilient I/IIOT please check out my upcoming August 10th webinar: 5 Indisputable Facts of I/IOT Security


Latest Posts
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
  • How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    May 21, 2026 How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    Blog
    5m
  • Cybersecurity as a Boardroom Priority for Major African TelCos
    May 12, 2026 Cybersecurity as a Boardroom Priority for Major African TelCos
    Blog
    8m
Related
  • Upgrading Your Vulnerability Management Program for DevOps, Cloud, and Containers
    Aug 29, 2018 Upgrading Your Vulnerability Management Program for DevOps, Cloud, and Containers
    Blog
    1m
  • Discover Your Privileged Account Security Vulnerabilities
    Jul 24, 2018 Discover Your Privileged Account Security Vulnerabilities
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.