Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • Securing IoT with Privileged Access Management current page
Link copied

Securing IoT with Privileged Access Management

Aug 8, 2018
Author:
Derek Smith 2025
Derek A. Smith
Founder, National Cybersecurity Education Center
Blog banner default
Securing IoT with Privileged Access Management
Derek Smith 2025
Derek A. Smith
Founder, National Cybersecurity Education Center

blog-securing-iot-with-privileged-access-management.jpg

Back in the early 2000s, utility companies were introduced to smart meters to provide a practical, hands-off way of collecting and monitoring data on how customers used their utilities. This was a predecessor for enabling other digital connections among remote devices and business systems, with the Internet as the go-between.

Today, this is known as the internet of things (IoT) and is used almost everywhere from smartphones, watches, refrigerators, and cars to medical implants and industrial machinery. With the increased use of IoT devices comes an increased security risk as well. So, our question to you is, has your organization fully prepared to secure IoT connectivity?

Check out my on-demand webinar to learn more "Privileged Access and IoT: How to Clear the Path for IoT in Your Organization Without Increasing Risk" view now

IoT-Related Breaches

Recently, there have been many examples of security breaches related to the increased use of IoT devices – from the hacking of baby monitors and smart TVs to remotely hijacked cars. However, one of the biggest threats to any business is understanding who has access, or the ability to access, from what devices to the infrastructure and the level of access they have.

Real world examples of cyber-attacks against IoT in the past few years include:

  • Texas Tornado Alarms being set off, causing panic across the city
  • A German Steel mill blast furnace being damaged
  • Ukraine Power Grid being taken off-line and impacting 86,000 homes
  • Hospital devices hit with ransomware, causing a state of emergency to be declared because the hospitals were unable to continue critical services
  • IoT devices being turned into a BOT, and then being controlled and used to participate in a DDoS (Distributed Denial of Service) attack like the one that has targeted Dyn, bringing popular websites like Netflix, Twitter, Amazon, AirBnb, CNN and the New York Times to their knees and offline

The 2017 Verizon Data Breach Digest report stated “Today, the IoT is not confined within an organization’s typical control boundary, as the connected infrastructure has moved far beyond those control lines. These devices exist virtually everywhere, are available anytime, and are on a variety of platforms. This must prompt organizations to think about IoT threat modeling in a manner that incorporates security and privacy by design.” If you are not already figuring out how to control your IoT devices, you are behind and need to start working on this right away.

IoT Devices Generally Lack Security Controls

Several things in common with all IoT devices is that they collect data, they communicate across the internet, and in most scenarios, they have credentials and passwords to protect their configuration or to communicate across networks. IoT connected devices pose a significant risk to enterprises and governments alike. These devices typically do not have the same security controls that protect the rest of the enterprise network. For example, industrial control systems are often maintained for many years before being replaced or updated—some with a lifecycle of 15 or more years. Attackers know this and are increasingly exploiting the weaker security associated with IoT devices to compromise them and use them as launching platforms to gain unauthorized access to network systems.

IT teams are becoming more vigilant about securing access to the networks that connect valuable things, like factory equipment and smart grid hardware. IoT focuses on how such things interact with each other, including the things themselves, people, tools, and apps. To secure these devices, Gartner noted that privileged access management (PAM) would be essential for ensuring IoT networks cannot be hacked. This will not be an easy feat though. With the increased number of endpoint devices due to IoT, the demands on PAM will become much more complicated.

How Privileged Access Management Helps Secure IoT

PAM helps to manage the people and the hundreds of thousands of “things” that are connected to a network. As stated by Garner, PAM will be vital to effective IoT solutions and will become an integral part of every IoT solution. PAM IoT is substantially different from traditional PAM. Security specialists must treat PAM IoT as a specialized domain and not simply as an extension of traditional PAM because there are huge differences between PAM IoT and traditional PAM, and, unfortunately, legacy PAM tools and technologies are largely unprepared to deal with these differences.

Applying PAM will help defend against IoT-related security threats. But what makes things more complicated is that the “someone” with privileged access can be a systems administrator or just another connected device or back-end service. This is what complicates matters. For instance, consider how many potential access points will be available to hackers as IoT devise continue to expand. Also consider that almost every major hack, including IoT-related hacks, can be attributed to privileged accounts.

That’s why good PAM is so important. It enables you to secure the credentials for these at-risk accounts, no matter how they’re accessed. It also allows you to audit and log account activity to help prevent breaches and demonstrate compliance.

The increased threats contributed to IoT devices demand stronger security measures be put into place. So, while password-based and two-factor authentication methods have proven sufficient for devices like ATMs and smartphones, risky IoT scenarios require more robust safeguards. PAM systems give you the capability to monitor access against many and to manage all credentials through the same PAM system. This approach provides a centralized point of authentication and is especially effective to help prevent exposure and risk to privileged accounts.

As the number of IoT devices continue to increase, your privileged access measures need to keep up. Specifically, they need to provide for privilege account management capabilities that can scale to accommodate the anticipated surge in connected devices and related access requests. The increase in IoT devices leads to a larger network of devices that creates a target-rich environment for hackers. Having a strong PAM solution that can rapidly monitor and detect anomalies in device access and usage patterns will help prevent compromise.

PAM will nullify the IoT machine to machine connectivity issue. If a device is not recognized, it will not be allowed to access the network, system or any information. In the case of a breach or unauthorized access, it will become much easier to identify in real-time and lock systems down. A full-featured PAM solution will help give your organization better protection against hacks while also ensuring access is seamless for authorized users.

PAM can also help with compliance. A good PAM solution will create a paper trail to record who accesses what.

Since PAM IoT is still relatively new, it could be some time before available solutions are equipped to address security requirements in IoT scenarios. But you can get a head start by protecting communication among devices and service providers. Make sure you send user credentials using secure channels. Also, properly secure any APIs you use to connect IoT devices and services and add an additional layer of protection beyond password usage by using advanced authentication methods, such as multi-factor and risk-based authentication.

Check out my on-demand webinar to learn more "Privileged Access and IoT: How to Clear the Path for IoT in Your Organization Without Increasing Risk"
view now

Latest Posts
  • Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Jun 12, 2026 Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Blog
    7m
  • Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Jun 9, 2026 Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Blog
    6m
  • Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Jun 8, 2026 Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Blog
    5m
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
Related
  • Using Application Control & Allow / Deny Listing to Protect against Malware, Threat Actors, & LotL Exploits
    Mar 31, 2021 Using Application Control & Allow / Deny Listing to Protect against Malware, Threat Actors, & LotL Exploits
    Blog
    1m
  • How BeyondTrust’s Remote Support Solution Enabled Pernod Ricard Spain to Securely Scale Its Business
    May 23, 2019 How BeyondTrust’s Remote Support Solution Enabled Pernod Ricard Spain to Securely Scale Its Business
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.