Five challenges when securing xIoT devices

Dave Stagg

If you work in IT, chances are you know precisely how many laptops and desktops your company is managing (or you can find out pretty quick smart).

But do you know how many xIoT (Extended Internet of Things) devices you have? If your answer is “no,” you’re not alone.

On a recent webinar, John Terrill, Chief Information Security Officer at Phosphorus, said that in his last role, he assumed they didn’t need to worry about IoT security. That was before he discovered they had over 13,000 IoT devices (and counting).

With International Data Corporation (IDC) forecasting there will be around 41.6 billion IoT devices in 2025 – keeping nefarious cybercriminals out should be a top priority.

What are xIoT devices, and what’s the problem anyway?

IoT devices encompass a broad category that includes any physical device connected to the internet – from consumer applications like smart watches to smart home appliances.

However, unlike a standard IoT device, xIoT also includes devices used in critical infrastructure, manufacturing, healthcare, and other industrial settings – so these could be medical devices for monitoring patients, to smart building systems, industrial controllers, and Operational Technology (OT). So, it’s like IoT, but way bigger.

The problem is that due to the sheer volume and variety of xIoT devices, managing their security is a challenge. And because they operate differently to traditional endpoints like laptops, desktops, and smartphones, they need a different mindset and approach.

What makes xIoT devices hard to secure?

Let’s run through five main factors to consider when looking to secure your xIoT devices.

  1. You can’t use EDR or NGAV
    With traditional endpoints, Endpoint Detection and Response (EDR) and Next Generation Antivirus (NGAV) are great tools to identify and respond or prevent attacks. They leverage advanced analytics and threat intelligence to monitor your system’s behaviour and detect anomalies in real time.
    However, when it comes to your xIoT devices, things get a lot trickier. Why? Because xIoT devices don’t have the compute power or resources, their ability to support the heavy processing requirements of EDR and NGAV is limited.

  2. Firmware is factory delivered, and you can’t modify or update it
    Damn and drat. While factory delivered firmware is great for ease of use, it does mean that many xIoT devices don’t come with a firmware update mechanism. Your IT team can’t tinker with the settings. While that’s not always a bad thing, in the case of an xIoT device, it is an issue.
    If you think about how you depend on software like Windows or Adobe being regularly updated with security patches and bug fixes, a lack of firmware updates and an inability for the end user to make modifications means that any vulnerabilities can’t be fixed.

  3. Security isn’t a primary consideration at the design phase
    Nowadays, we talk a lot about taking a “secure-by-design” approach. This means that security is considered and integrated from the outset in the design, development and deployment of products and services. Which is great.
    Although endpoint device developers are hyper focused on securing and testing, xIoT seems to have fallen through the cracks. This is a serious boon to hackers (party time in cybercrime HQ), but it’s not so great for you.
    Given that xIoT devices can serve as an entry point for cybercriminals to gain access to your network, it’s worrying that so many of those used in businesses around Australia haven’t been designed with a security-first approach. Because they’re generally purpose built, for example, an IP camera or a temperature sensor – security isn’t usually a primary consideration. And that’s an oversight that could cost you dearly.

  4. People want simple setup
    It’s understandable that simplicity is a significant selling point for xIoT devices. However, that self-same lack of complexity can inadvertently compromise your security, making devices desirable targets for hackers.
    xIoT devices often come with out-of-the-box configurations or factory settings like default usernames (Device1) and passwords (like password or 12345). The defaults are usually easy to guess, and the simplified setup process may limit the user’s ability to configure settings, leaving the devices vulnerable to attack. Those users who focused on quick installation (because they have 500 of these devices to install and a week to do it) may not understand the implications.
    The problem is that by connecting these devices to your network without proper segmentation of protection, someone-who-shall-remain-nameless has introduced 500 open doors to hackers.

  5. The phone home flaw!
    Having an xIoT device “phone home” means sending data back to a central server or manufacturer. While it sounds routine enough, if the device is transmitting sensitive information without robust encryption, the data can be intercepted, leading to a breach.
    Also, xIoT devices that regularly communicate with a central server can create a single point of failure. If that server’s compromised, then cybercriminals could potentially gain access to a vast flotilla of xIoT devices.
    And going back to the setup limitations of xIoT devices, this includes setting privacy controls. So, device users may not be able to control what data is sent back to home base, how and where it’s stored – which of course violates data privacy laws.
    A constant reliance on a central server to communicate to function means that if the server goes down, so does the xIoT device. And even if the server never goes down, insecure or poorly implemented network protocols can expose the device to remote exploitation.

Are we being negative about xIoT?

Not, not in the least. We like and appreciate the power of a great xIoT device as much as the next person.
But we are wary about their wholesale acceptance into the business environment without the due care, attention, and diligence needed to keep the world’s data safe.
The good news is that xIoT will gradually become more secure as the business world becomes more aware of the risks, governments implement regulations prioritising device security, and manufacturers pull up their security-first socks – but that may be too late.
So – let’s talk sooner than later.

Published On: April 7th, 2025 / Categories: Security / Tags: LAPS, Local Administrator Password Solution