Enterprise IoT Security: The Devices Nobody Owns
Cameras, door controllers, HVAC, printers, TVs and sensors — installed by facilities, connected by a contractor, patched by nobody. Securing the estate outside IT.
GuardsArm Team
Security Experts
Every building has a second network nobody manages. Security cameras, door controllers, HVAC, lighting, lift controls, digital signage, smart televisions, environmental sensors, and — in hospitals — nurse call and pneumatic tube systems. They were specified by facilities, installed by a contractor, and connected to whatever socket was nearest.
This is distinct from medical devices, which at least have a clinical owner and a regulatory framework. See IoMT security for those. Enterprise IoT frequently has neither.
Why they are attractive to attackers
These devices are a near-ideal foothold. They run embedded Linux with old components, they are never patched, they are not in any asset inventory, they generate no logs anyone reads, and they sit on the internal network with broad reachability. A camera compromised at 2am produces no alert anywhere.
The well-known casino-fish-tank story is amusing precisely because it is typical: the device was trivial, the network position was not.
Discovery first, because the inventory does not exist
- Passive network discovery — identify by traffic pattern and MAC OUI
- Walk the building. Genuinely. Look at what is mounted on walls and ceilings
- Ask facilities for their maintenance contracts — every serviced system is probably networked
- Check the procurement records for anything installed in the last five years
- Look for management interfaces on unusual ports across the estate
Record what it is, who installed it, who maintains it, what it talks to, and whether anyone can log in to it.
Controls that work without vendor cooperation
Segmenting by function rather than lumping all IoT together is the detail most often missed. Cameras and physical access control on the same VLAN means one compromise reaches the doors.
Fix it at procurement
Retrofitting is expensive; specifying is free. Add to the standard purchase terms for any networked building system:
- Default credentials must be changed at commissioning, and handed over documented
- The device must support credential change and, ideally, centralised authentication
- Firmware update path and support lifetime stated in writing
- No permanent vendor remote access; support access brokered on request
- Network requirements documented — exactly what it needs to reach
- Security advisories provided to the customer for the supported life
Facilities procurement rarely includes any of this, and adding it costs nothing at contract stage.
Detecting a compromised device
These devices have the most predictable behaviour on the network, which makes them unusually easy to monitor once you accept you cannot secure them directly.
| Signal | Why it matters |
|---|---|
| A camera initiating outbound internet connections | Cameras receive connections; they rarely need to make them |
| A device scanning the local subnet | Almost never legitimate behaviour for building equipment |
| Protocol mismatch on a known port | A device speaking something other than its own protocol |
| Traffic volume far outside its baseline | Video devices have very stable profiles |
| Authentication attempts against other hosts | A device should not be logging in anywhere |
| Firmware version changing unexpectedly | Either unmanaged updates or tampering |
The first row alone is worth implementing. An IP camera reaching out to the internet is either a cloud feature nobody documented or a compromise, and both are worth knowing about.
When one is compromised
Treat it as a network incident rather than a device fault:
- Isolate the VLAN, not just the device — assume neighbours are affected
- Preserve the device state before factory-resetting it, which destroys evidence
- Check what it could reach, and hunt there
- Establish how it was accessed: default credentials, exposed management interface, or the contractor's remote access
- Fix the class, not the instance — if one camera had default credentials, they all do
Where to start
Walk one floor and list what is mounted on the walls and ceilings. Then check whether any of it appears in your asset inventory. The gap between those two lists is the scope of the problem, and it is usually large enough to justify the discovery project on its own.
GuardsArm discovers and segments unmanaged IoT and building systems in healthcare estates. Book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on “Enterprise IoT Security: The Devices Nobody Owns”
Talk to the GuardsArm team about how these services apply to your environment.


