Back to Blog
Iot Security
8 min read

Enterprise IoT Security: The Devices Nobody Owns

Cameras, door controllers, HVAC, printers, TVs and sensors — installed by facilities, connected by a contractor, patched by nobody. Securing the estate outside IT.

GuardsArm Team

Security Experts

May 9, 2025

Enterprise IoT devices

Every building has a second network nobody manages. Security cameras, door controllers, HVAC, lighting, lift controls, digital signage, smart televisions, environmental sensors, and — in hospitals — nurse call and pneumatic tube systems. They were specified by facilities, installed by a contractor, and connected to whatever socket was nearest.

This is distinct from medical devices, which at least have a clinical owner and a regulatory framework. See IoMT security for those. Enterprise IoT frequently has neither.

No owner
Specified by facilities, connected by a contractor, patched by nobody
Default credentials
Shipped with them, documented publicly, rarely changed at install
Full network reach
Usually connected to whatever VLAN was available

Why they are attractive to attackers

These devices are a near-ideal foothold. They run embedded Linux with old components, they are never patched, they are not in any asset inventory, they generate no logs anyone reads, and they sit on the internal network with broad reachability. A camera compromised at 2am produces no alert anywhere.

The well-known casino-fish-tank story is amusing precisely because it is typical: the device was trivial, the network position was not.


Discovery first, because the inventory does not exist

  • Passive network discovery — identify by traffic pattern and MAC OUI
  • Walk the building. Genuinely. Look at what is mounted on walls and ceilings
  • Ask facilities for their maintenance contracts — every serviced system is probably networked
  • Check the procurement records for anything installed in the last five years
  • Look for management interfaces on unusual ports across the estate

Record what it is, who installed it, who maintains it, what it talks to, and whether anyone can log in to it.

The contractor still has access
Building system contractors routinely retain remote access for maintenance, established at installation and never reviewed. This is the same problem as clinical vendor access — see third-party remote access — and it is usually worse, because nobody in IT knows it exists.

Controls that work without vendor cooperation

Containing unmanaged IoTFunction-specific VLANs with no internet egress and no route to clinical or corporate networks, with credentials changed and behaviour monitored.Dedicated IoT/OT VLANs by functionCameras separate from HVAC separate from access controlNo internet egress by defaultBroker any cloud management through a proxyNo route to clinical or corporateExplicit allow only to the named management serverChanged default credentials, documentedRecorded in a vault, not a spreadsheetPassive monitoring for deviationBehaviour is highly predictable, so anomalies stand out
Segmentation by function matters: a camera compromise should not reach door controllers.

Segmenting by function rather than lumping all IoT together is the detail most often missed. Cameras and physical access control on the same VLAN means one compromise reaches the doors.


Fix it at procurement

Retrofitting is expensive; specifying is free. Add to the standard purchase terms for any networked building system:

  • Default credentials must be changed at commissioning, and handed over documented
  • The device must support credential change and, ideally, centralised authentication
  • Firmware update path and support lifetime stated in writing
  • No permanent vendor remote access; support access brokered on request
  • Network requirements documented — exactly what it needs to reach
  • Security advisories provided to the customer for the supported life

Facilities procurement rarely includes any of this, and adding it costs nothing at contract stage.


Detecting a compromised device

These devices have the most predictable behaviour on the network, which makes them unusually easy to monitor once you accept you cannot secure them directly.

SignalWhy it matters
A camera initiating outbound internet connectionsCameras receive connections; they rarely need to make them
A device scanning the local subnetAlmost never legitimate behaviour for building equipment
Protocol mismatch on a known portA device speaking something other than its own protocol
Traffic volume far outside its baselineVideo devices have very stable profiles
Authentication attempts against other hostsA device should not be logging in anywhere
Firmware version changing unexpectedlyEither unmanaged updates or tampering

The first row alone is worth implementing. An IP camera reaching out to the internet is either a cloud feature nobody documented or a compromise, and both are worth knowing about.


When one is compromised

Treat it as a network incident rather than a device fault:

  • Isolate the VLAN, not just the device — assume neighbours are affected
  • Preserve the device state before factory-resetting it, which destroys evidence
  • Check what it could reach, and hunt there
  • Establish how it was accessed: default credentials, exposed management interface, or the contractor's remote access
  • Fix the class, not the instance — if one camera had default credentials, they all do

Where to start

Walk one floor and list what is mounted on the walls and ceilings. Then check whether any of it appears in your asset inventory. The gap between those two lists is the scope of the problem, and it is usually large enough to justify the discovery project on its own.

GuardsArm discovers and segments unmanaged IoT and building systems in healthcare estates. Book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on “Enterprise IoT Security: The Devices Nobody Owns”

Talk to the GuardsArm team about how these services apply to your environment.