Avantec AG
Speicher
IoT – how to deal with security risks? – Tec-Bite IT-Security Blog
- 08 August 2026
- 100%
- Permanent position
- Speicher
About the job
Drivers and business benefits of IoTThe combination of various technological advances such as miniaturisation, connectivity (LoRa, 5G), energy-efficient design and last but not least "Big Data" create the vast growth field of connected things, i.e. the Internet of Things (IoT). Gartner predicts that by 2020 over 30 billion IoT devices will be in use – both in the "consumer" IoT sector (think Amazon Alexa or Philips Hue) as well as in the "industrial" environment. Here, IoT opens up new application and business fields across all industries including retail, logistics, production, energy and healthcare.Through IoT, for example, improved product and customer experiences can be achieved (product analytics, personalised products), efficiency gains implemented (predictive maintenance, real-time monitoring, optimisations, automation) and completely new service and business models built.Security challenges: limitations of the devicesFrom a security perspective, however, IoT also brings risks due to increasing complexity, an expanded attack surface and new vulnerabilities. In particular, there are some challenges when implementing security controls directly on IoT devices:IoT devices are generally small, inexpensive and offer practically no physical securityCPU, memory and battery capacity are limited and make classic crypto mechanisms difficult or impossibleInstallation, upgrade and patching options are very limitedLarge number and heterogeneity of devices (including complex supply chains in manufacturing)Security mechanisms on the device are therefore very limited or not possible at all on many existing devices. For ongoing and future device developments, it is therefore essential that a rethink takes place from "security as an afterthought" to "security by design". This includes, for example, the implementation of application security, patch management and also identity management on the end device.Compensation through network securityNetwork security therefore plays a very important role in the context of IoT to compensate for the limitations of existing IoT devices.As a first measure, stronger control of data flows can be achieved through classic network zoning (e.g. with firewalls) and micro-segmentation of IoT device classes. This often raises the question of the trade-off of how far "out into the field" (i.e. towards the edge) one should reasonably segment for cost reasons (firewall costs).The second important measure is to create visibility and analyse the resulting view. The connection paths and network behaviour patterns of IoT devices provide a great deal of information about whether a device behaves according to expectations, i.e. following its purpose. The collection and analysis of such network data including intelligent classification of behaviour patterns can now be largely automated and thus relieve security analysts and SOC staff.As a third measure, dedicated control and orchestration solutions can be used to classify, authenticate or control the network access of IoT devices. Since no agents can be installed on the IoT devices themselves, these solutions must work "agentless".Finally, another Gartner prediction (FWIW): a CIO's IoT security budget will rise from 1% (2018) to 20% in 2020.IoT Security Webinar (German)The article IoT – how to deal with security risks? first appeared on Tec-Bite.