LOGBOOK

HELP

Quiz Entry - updated: 2026.09.18

Which three domains does end-to-end IoT security and privacy have to cover?

Security of the devices, security of the communication to and from them, and security in the cloud — all three, or the chain has a weak link.

End-to-end protection spans device, communication and cloud: the defender must protect all three, while an attacker needs one exploitable weakness.

* End-to-end protection spans device, communication and cloud: the defender must protect all three, while an attacker needs one exploitable weakness. *

  1. Security of IoT devices — the endpoint itself: execution security, device-level security, protecting compute, network and storage, and the sensor data held on board.
  2. Communication to and from IoT devices — the wireless links (WiFi, cellular, LoRa and the rest) and the commands and data crossing them.
  3. Security in the cloud — the backend: data analytics, control systems, big data and container orchestration.

Cutting vertically through all three are end-to-end security and end-to-end data encryption — properties that no single domain can provide alone.

The reason for insisting on all three is the asymmetry of an attacker's job. A defender must hold every domain; an attacker needs one. A perfectly hardened cloud is reached through a device with a default password; a perfectly hardened device is undone by a cloud account takeover that pushes it new configuration; an impeccable device and cloud are bridged by an unencrypted radio link that lets an attacker forge readings.

Tip: the three domains map exactly onto the three architecture tiers from the fundamentals topic — device, communication, cloud. Same structure, different question: the architecture asks what runs where, the security view asks who can touch it.

Go deeper:

From Quiz: SIOT / IoT Networking and Security | Updated: Sep 18, 2026