Security by design: why organisations need to secure IoT ahead of deployment

Security by design: why organisations need to secure IoT ahead of deployment

IoT security must now begin before connected devices reach deployment. Syed Zaeem Hosain, Co-Founder and Chief Evangelist at Aeris, explains why hardware-rooted trust, secure provisioning, and lifecycle protection are becoming engineering requirements.


IN Brief:

  • AI-driven attacks can exploit firmware and embedded software weaknesses across connected industrial fleets, increasing operational and financial exposure.
  • Security by design combines hardware-rooted trust, secure provisioning, authenticated firmware updates, and continuous testing across the device lifecycle.
  • CRA and NIS2 requirements are increasing pressure on manufacturers to evidence device security, update mechanisms, and lifecycle oversight before products reach market.

Syed Zaeem Hosain, Co-Founder and Chief Evangelist, Aeris

IoT security is no longer a challenge that can be addressed at deployment. For Syed Zaeem Hosain, Co-Founder and Chief Evangelist at Aeris, it has become a design and lifecycle issue — one that must be integrated into devices from the start and maintained long after leaving the factory.

An evolving threat landscape is driving this shift. As cyberattacks adopt AI-driven techniques, attackers can identify and exploit vulnerabilities in firmware and embedded software at scale. A single weakness is no longer contained to one device — it can be replicated across industrial deployments, amplifying operational and financial risk.

The manufacturing sector is highly exposed. In industrial IoT and operational technology (OT) environments, connected devices are directly tied to physical processes, making cyber incidents a threat to production or equipment. High-profile incidents, including the disruption at Jaguar Land Rover (JLR), illustrate how compromising a single asset can trigger wider operational and economic consequences.

From add-on security to engineering requirements

Historically, IoT security has been treated as an extension of IT security, often addressed through patching, monitoring or network controls after deployment. That method is proving inadequate.

Regulatory frameworks, such as the Cyber Resilience Act (CRA) and NIS2, are placing greater accountability on manufacturers and solution providers. Organisations must demonstrate how devices are secured, updated and monitored throughout their lifecycle, making security a condition of compliance and market access. Vulnerabilities in firmware, provisioning and device identity are targeted more frequently, exposing gaps between device, network and application-layer protections.

Building security into device architecture

The industry is increasingly adopting a ‘security-by-design’ approach, integrating protection into device architecture from the start. A vital aspect is hardware-rooted trust, using secure elements and trusted execution environments to establish device identity, secure boot processes and firmware integrity. This must be complemented by ‘security-by-default’, which ensures these protections are activated and monitored upon deployment rather than left inactive.

Secure provisioning is essential for authenticating and configuring devices before deployment, protecting credentials, keys, and identities from compromise. Weaknesses in this area can expose entire fleets to risks. Finally, ‘security-by-demand’ highlights the growing expectations from customers, regulators, and enterprise buyers for connected devices to have built-in security features. Procurement decisions increasingly prioritise evidence of secure development practices and compliance.

Securing the lifecycle, not just the device

Secure firmware updates are crucial. Updates need to be authenticated, verified, and delivered securely to prevent unauthorised modifications. This requires cryptographic signing, key management, and reliable delivery across distributed networks.

Security testing throughout the software development lifecycle (SDLC) is essential. Vulnerability scanning, penetration testing, and validating third-party components, including open-source libraries, help identify risks before deployment.

Supply chain transparency is becoming critical. Software Bills of Materials (SBOMs) offer a detailed inventory of the components within a device, allowing manufacturers to track dependencies and respond more effectively to any vulnerabilities. As regulatory requirements evolve, this level of visibility is essential for both compliance and operational resilience.

The challenge of end-to-end protection

The most significant challenge remains achieving coordinated security across the entire IoT ecosystem. Industrial IoT deployments span multiple layers, including the device, the network and cloud-based applications. Securing them in isolation leaves gaps that attackers can exploit.

Many connected devices operate outside traditional enterprise boundaries, meaning threats may not be visible to standard IT security tools. At the same time, approaches designed for enterprise IT do not always translate effectively to embedded or OT environments.

Addressing this requires a more integrated approach. Security must be aligned across device behaviour, network activity and application-layer controls, supported by continuous monitoring and visibility across the IoT stack.

A new baseline for IoT security

Manufacturers and IoT solution providers must prioritise security as a core design principle rather than an afterthought. This means integrating hardware-based trust, secure provisioning, resilient updates and oversight throughout the lifecycle, alongside stronger ecosystem collaboration.

As IoT adoption accelerates, security is no longer just a compliance checkbox — it’s the foundation of trust, resilience, and competitive advantage. Manufacturers and solution providers who embed protection from the first design decision to decommission will not only reduce risk, but also be best positioned to win in a more connected, regulated future.


Stories for you


  • Dismantled: Q3 2026

    Dismantled: Q3 2026

    Q3 2026 pushed established electronics constraints deeper into production systems. HBM4, silicon photonics, 800VDC, agentic EDA and CRA reporting all gained firmer operational footing.


  • Vishay adds 650V SOT-227 power modules

    Vishay adds 650V SOT-227 power modules

    Vishay has launched 650V SOT-227 modules for industrial power conversion. Four devices combine superjunction MOSFETs with established module mechanics and immediate production availability.