What are the four categories of IoT security threat, and what does each cover?
Service disruption, system management, side-channel attacks and unauthorised access — one for availability, one for the update lifecycle, one for physical access, one for the network edge.
* Four threat categories connect technical weaknesses to business and safety consequences. *
| Threat category | What it covers |
|---|---|
| Service disruption | Disabling endpoints via default passwords or weak crypto; classic attacks that still work — DDoS, DHCP-related attacks, IP spoofing; and the resulting equipment downtime |
| System management | Vulnerabilities found after deployment, needing in-field firmware upgrade on devices with limited or no UI; and the integrity and authenticity of code before it runs, i.e. secure boot |
| Side-channel attacks | Exploiting physical access to extract secrets from one device and use them to attack others; countered by hardware protection against techniques like correlation power analysis |
| Unauthorised access | Potential network entry points, unauthorised devices joining, zero-touch deployment models at large scale, unsecured ports and USB |
The risks these threats create are deliberately stated in business terms rather than technical ones: theft of data, loss of productivity, loss of privacy, damaged reputation, danger to health and safety, and non-compliance with laws and regulations.
That last framing matters. "Danger to health and safety" is the item with no equivalent in ordinary IT security, and it is what justifies treating an IoT compromise differently from a database leak — the device is attached to the physical world, so the failure can be too.
Tip: note how often defaults appear — default passwords, zero-touch onboarding, unsecured ports. A large share of real IoT compromise is not a broken algorithm but a shipped-as-is configuration.
Go deeper:
Wikipedia — Side-channel attack — the one category with no real enterprise-IT equivalent: attacks on timing, power, electromagnetic and acoustic leakage rather than on the algorithm.