The modern workplace is filled with connected devices that aren't laptops or servers. Smart thermostats control building climate, IP cameras monitor facilities, electronic access badge readers secure doors, smart lighting systems adjust automatically, and networked printers serve documents to the entire office. These Internet of Things (IoT) devices are convenient, efficient, and increasingly ubiquitous — but they also represent one of the most under-managed security risks in corporate environments. IoT devices frequently run embedded operating systems with limited security capabilities, receive infrequent firmware updates, and are deployed with default credentials that are published in manuals available to anyone online. This post examines the specific security risks IoT devices introduce and the practical controls every business should implement.
Default Credentials: The Open Door You Forgot to Lock
The single most common IoT vulnerability is unchanged default credentials. Most IoT devices ship with a standard username and password — often something like admin/admin or admin/password — that is documented in the user manual and widely known. Attackers maintain databases of default credentials for thousands of device models, and automated scanners constantly probe internet-facing IP addresses for devices responding with these factory logins. In 2016, the Mirai botnet infected hundreds of thousands of IoT devices — primarily IP cameras and DVRs — by trying just 60 default username/password combinations. The resulting botnet launched some of the largest DDoS attacks ever recorded, taking down major websites and DNS providers.
The fix is straightforward but frequently overlooked: change every default password on every IoT device before deploying it on the network. This includes thermostats, cameras, access control systems, smart TVs, conference room displays, and network-attached printers. Use strong, unique passwords — not the same password across all devices, because if one is compromised, the attacker shouldn't gain access to others. For devices that support it, disable default accounts entirely and create new administrative accounts with non-predictable names. Document every credential in a secure password manager so the information is available when maintenance is needed but isn't sitting in a spreadsheet on a shared drive. This sounds basic, but in our experience auditing SMB environments in the Vancouver area, a significant percentage of deployed IoT devices still carry their factory credentials months or years after installation.
Network Segmentation: Isolating IoT from Critical Systems
Even with strong credentials, IoT devices present risk because their security posture is generally weaker than your laptops and servers. A compromised smart thermostat shouldn't be able to reach your database server. A hacked IP camera shouldn't have a path to your domain controller. Network segmentation is the control that prevents a compromised IoT device from becoming a launching point for deeper network intrusion. The principle is simple: place IoT devices on a separate VLAN with firewall rules that restrict what they can communicate with.
In practice, this means configuring your network switches and firewall to create a dedicated IoT VLAN. Assign IoT devices to this VLAN through port-level configuration or wireless SSID segregation. Then create firewall rules that permit only the specific communications each IoT device needs — for example, IP cameras need to stream to the NVR (network video recorder) but do not need internet access; smart thermostats may need to reach a cloud management portal but should not have access to internal file servers. Deny all other traffic by default. This approach, known as least-privilege network segmentation, ensures that even if an IoT device is compromised, the attacker's ability to move laterally is severely limited. If your current network equipment doesn't support VLANs, that's itself a signal that your switching infrastructure is due for replacement — VLAN support has been standard on business-grade switches for over a decade.
Firmware Update Management and Monitoring IoT Traffic
IoT device firmware updates are critical but routinely neglected. Manufacturers release firmware patches to fix security vulnerabilities, but unlike Windows or macOS, IoT devices don't always auto-update. Many require manual intervention — downloading a file from the manufacturer's website and uploading it through the device's web interface. This means vulnerabilities go unpatched for months or years. Assign someone responsibility for checking firmware updates quarterly for each IoT device category. For IP cameras and access control systems, this is especially critical — these devices are frequent targets, and known vulnerabilities are publicly cataloged in databases like CVE (Common Vulnerabilities and Exposures). If a manufacturer has stopped releasing firmware updates for a device, that device should be evaluated for replacement — running unpatchable IoT firmware on your corporate network is an unacceptable risk.
Monitoring IoT network traffic provides visibility into whether devices are behaving normally. A smart thermostat that suddenly starts making outbound connections to an unknown IP address is likely compromised. An IP camera transmitting gigabytes of data outside business hours warrants investigation. If you have a firewall with traffic monitoring capabilities — most modern business firewalls from Fortinet, Palo Alto, or SonicWall include this — configure alerts for anomalous traffic patterns originating from the IoT VLAN. Even basic monitoring, like logging all outbound connections from IoT devices and reviewing them weekly, can catch problems early. The goal isn't to watch every packet but to establish a baseline of normal behavior so you can detect deviations.
Real Breach Examples: What's Actually Happened
The IoT threat isn't theoretical. Beyond the Mirai botnet, several real-world breaches demonstrate how IoT devices become attack vectors. In 2017, researchers discovered that a connected fish tank thermometer at a casino was being used to exfiltrate data — the thermometer was connected to the corporate network, had default credentials, and attackers used it as a pivot point to access other network segments. In 2018, a vulnerability in a popular brand of IP cameras allowed remote attackers to view live feeds and gain shell access to the camera's embedded Linux system — with over 100,000 devices exposed to the internet. In 2021, vulnerabilities in a widely used access control system allowed attackers to remotely unlock doors, potentially granting physical access to secure facilities. These aren't fringe cases — they represent the standard pattern of IoT exploitation: weak credentials, unpatched firmware, network access that should have been restricted, and a lack of monitoring that would have caught the anomalous behavior.
For SMBs, the lesson is that IoT device risk is proportional to the access the device has, not the importance of the device itself. A $200 smart thermostat may seem inconsequential, but if it's on the same network segment as your file server and domain controller, it's an attack surface that matters. Treat every IoT device with the same security rigor you'd apply to a server: change defaults, segment the network, update firmware, and monitor traffic.
Conclusion: IoT Security Requires Deliberate Action
The convenience of IoT devices — climate control, security cameras, automated access — is real and valuable. The risk they introduce is also real, but manageable with deliberate controls. Change default credentials on every device before deployment. Segment IoT devices onto a dedicated VLAN with restrictive firewall rules. Maintain firmware update discipline and replace devices that can no longer be patched. Monitor IoT traffic for anomalous behavior. These steps don't require enterprise-grade tools or large budgets — they require awareness, process, and follow-through. The cost of ignoring IoT security is measured in breaches, and as the examples above show, attackers are actively scanning for vulnerable devices every minute of every day.
Beawit Consulting provides IT services to SMBs in the Vancouver/Portland metro area, specializing in Azure, M365, hybrid cloud, and network engineering. We help organizations assess IoT security risks, design network segmentation, and implement monitoring controls for connected devices.
Looking for reliable internet connectivity for your business? Use our Scout lookup tool to search available options from over 75 providers, including AT&T, Comcast, Cox, Crown Castle, Fidium, Frontier, Lumen, Spectrum, Verizon, and Zayo — with instant pricing proposals and contracts.
Contact us at contactus@beawit.net or (360) 399-6834 to discuss IoT security for your workplace.