CyOne Security AG
Bauen
Cyber Security in IoT: indispensable yet neglected
- 07 August 2026
- 100%
- Permanent position
- Bauen
About the job
For manufacturers and operators of IoT applications, security often plays a secondary role. This can backfire. Without considering cyber security, the IoT device becomes a gateway for cyber criminals: the corporate infrastructure turns into a high-risk zone. Learn about the three relevant IoT security aspects in this blog post.
The Internet of Things (IoT) is spreading rapidly across all industries and markets, and the IoT network is becoming increasingly dense – including in industrial environments (IIoT). As a result, IIoT applications often penetrate more critical areas of our digital society. Connected devices in fields such as medical technology and critical infrastructures are becoming the norm. This drastically increases risks and can have massively negative effects on companies and the economy through dangerous cyber incidents. Besides the loss of confidentiality and impairments to data availability, data manipulation—especially in the fields of medicine, pharmaceuticals, transport, and critical infrastructures—can have dramatic consequences for life and limb. And yet: the topic of cyber security is still trivialised, if not ignored, in IIoT applications today.
Cyber attacks on IIoT devices are a reality
Many companies already operating IIoT applications are poorly prepared against cyber attacks. Major risks are posed by inadequately protected IIoT devices themselves (sensors, actuators, gateways). Alongside classic attack vectors such as email, attackers increasingly use these as entry points into corporate infrastructure or as springboards for compromising other systems within segmented infrastructures. The main vulnerabilities responsible for this are: IIoT device traffic is often transmitted unencrypted, IIoT devices operate around the clock, are always online, poorly maintained, and infrequently monitored. Additionally, combined with knowledge of the deployment environment, they provide information about the identity of the user or company. Cyber criminals deliberately exploit existing IoT security gaps. Entire production chains can be paralysed, customer data manipulated, companies extorted, or even industrial espionage conducted. In the worst case, human lives are endangered. The massive increase in cyber attacks should actually compel manufacturers and operators to take action.
Secure IoT connectivity alone is not enough
Traditional cyber security providers today often focus on secure network connections from the perimeters to the operator, cloud provider, or user. While this consideration is fundamentally correct, it only covers part of the necessary measures. To comprehensively and "end to end" protect an IoT ecosystem, secure IIoT devices and expertise for secure integration into an existing network infrastructure are also required. Regulatory bodies have recognised this, for example in medical technology, issuing cyber security requirements for medical devices, such as the Food and Drug Administration (FDA) in the USA and the Medical Device Regulation (MDR) by the EU.
The three relevant aspects in IoT security: security regarding connectivity, product, and integration
"Security by Design" is the motto for manufacturers
A comprehensive security consideration must therefore be included already in product development. Retrofitting missing security components and functions in IIoT products is risky and expensive. Secure hardware and software design with validations and plausibility checks, consistent data separation, traceability, secure interfaces, monitoring, and update capability must be planned and implemented consistently from the outset. "Security by Design" is the efficient and sustainable approach. Only in this way can manufacturers develop updatable products that can continuously adapt to changing cyber risks during operation and remain usable for operators for longer.
Operators must demand security aspects
Operators are also responsible: when evaluating a new network-capable IIoT device, a closer look is necessary. Operators must demand and verify more detailed information from manufacturers regarding security aspects such as connectivity, more secure IIoT products, secure integration, and data management. Only in this way can they rely on their IT/OT infrastructure not becoming a risk factor due to newly purchased connected products.
Success factor for manufacturers and operators
With "Security by Design," manufacturers gain a decisive competitive advantage and further market access by minimising cyber risks for their products and applications. Operators can rely on a secure solution, thus minimising operational risks and extending product lifespans. Therefore, it is worthwhile for all parties to increasingly invest in IIoT security or product cyber security in the future.
The specific expertise regarding the three IoT security aspects, which span the entire product lifecycle, clearly differ from the classic cyber security expertise for IT infrastructures that have been established in companies in recent years. It is worthwhile to involve project-specific IoT security experts to achieve holistic and sustainable IIoT security. This allows manufacturers' development teams to focus on their core business – developing innovative IIoT devices – and conserve personnel resources.
Gaining time-to-market
The high complexity of IoT ecosystems makes ensuring security difficult if the necessary specific expertise is lacking. Therefore, companies must ask themselves the question "Make or Buy?": Do we build all the very specific IoT security knowledge ourselves, or is it more sensible to involve experts on a project basis?
CyOne Security supports manufacturers and operators of IoT applications with its profound expertise to achieve the highest possible, sustainable, and comprehensive IoT cyber security. Thus, customers do not have to build all security competencies themselves but can obtain the missing competencies from an expert on a project basis. This gains them time-to-market and allows them to focus on their core business.
"IoT Security – Make or Buy?" – Is it worthwhile to build the required IoT and product cyber security expertise in-house, or is it advisable to purchase it on a project basis? Our decision checklists help you with this decision.