Last updated: April 29, 2026
IoT devices ship with security debt. Default creds, no update mechanism, hardcoded keys. Supply chain compounds it.
Issues
- Default credentials never changed (Mirai botnet exploited this)
- No firmware updates after sale (10-year-old vulns active)
- Hardcoded private keys discovered post-shipment
- Foreign-manufacture concerns (geopolitical)
- Recycled chips with unknown firmware
Indian regulatory environment
2022 CERT-In Direction requires equipment imported into critical sectors to be assessed. NCIIPC publishes vulnerability advisories. NCERT-CSF specific to telecom IoT (TRAI mandate).
Defender
- Network segmentation (IoT untrusted zone)
- Mandatory password change at deployment
- Update tracking; replacement schedule for unpatchable
- Vendor risk management for IoT manufacturers (RingSafe Trust use case)
Module Quiz · 6 questions
Pass with 80%+ to mark this module complete. Unlimited retries. Each question shows an explanation.
Custom team training + practitioner advisory
Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.