On which dimensions does IoT security differ from enterprise IT security?
Robustness, environment, variety, volume and consequence — five dimensions on which IoT is not a smaller version of IT security but a harder one.
* Physical exposure, scale and heterogeneous devices compound the challenges of managing security. *
| Dimension | Why IoT differs |
|---|---|
| Robustness | IoT security must be more robust than IT security, because the devices are connected to the physical world — a failure has physical effects |
| Environment | Devices are exposed to natural elements and deployed in hostile environments, which leaves them physically vulnerable in ways a server in a rack is not |
| Variety | Significantly more types of device and more types of network than in enterprise IT, so there is no single platform to standardise on |
| Volume | Billions of IoT devices versus millions of IT devices connected to enterprise systems |
| Consequence | A hacked device can drastically change a company's risk profile — the example given is medical equipment that stops working |
The five compound rather than merely adding up. Variety defeats the standard enterprise answer of a managed baseline image; volume defeats manual administration; environment means you must assume an attacker can physically hold a device, which is why side-channel attacks appear in the IoT threat list and rarely in the IT one; and consequence means the residual risk you are left with is measured in harm rather than in records.
Tip: the compact version is "more robust, worse environment, more kinds, more of them, worse when it goes wrong." Each phrase kills one comfortable assumption carried over from enterprise IT.
Go deeper:
NIST IR 8228 — Considerations for Managing IoT Cybersecurity and Privacy Risks — the same argument made as guidance for risk managers, working from how IoT devices interact with the physical world and how differently they can be accessed and managed.