What do the architect, the operator and the CISO each owe an IoT deployment?
The architect designs it to be securable, the operator keeps it secure while it runs, and the CISO decides how secure it has to be and holds everyone to it.
Architect — build it so it can be defended:
- IoT security is achievable within power, cost and budget constraints — it is not a matter of resources being unavailable.
- Few architects and developers have strong experience building secure IoT systems, so the skill gap is itself a risk to manage.
- Build robust software/hardware co-design for the variety of devices in play.
- Provide secure and reliable firmware updates, since there is no reset or reinstall for devices with no physical access.
Operator — keep it defended in production:
- Control managed, secure and reliable firmware updates across the distributed device estate.
- Build communication security on open standards — proprietary protocols or proprietary update mechanisms may not work, and lock the operator into a vendor's assumptions.
CISO — set the bar and enforce it:
- Evaluate IoT security and assess the risks of connected devices, including understanding how the data is accessed and managed.
- Provide security requirements — new policies, standard operating procedures and tests.
- Work with suppliers and operators to make devices more secure by design.
- Strengthen security standards on connected devices.
The division reflects when each party can act. The architect's window closes at design time; the operator's runs for the device's whole service life; the CISO's is continuous and is the only one with authority over the other two and over the supplier relationship.
Tip: the open-standards requirement is the most practically consequential item. A proprietary update mechanism means that if the vendor loses interest, the estate cannot be patched — and IoT devices routinely outlive the companies that made them.
Go deeper:
Wikipedia — Cyber Resilience Act — the EU turning these duties into law for products with digital elements: risk assessment before market, security updates automatic by default, and incident reporting within 24 hours.