Why Majority of Security Experts Are Finding It Difficult to Secure Key IoT Devices?
The number of IoT Devices used by businesses continues to grow every year. According to Statista, companies deployed more than 8.7 billion connected devices in 2020. That number will reach over 25 billion by 2030. As adoption increases, security teams face new challenges in protecting these systems and keeping attackers out.
To understand these concerns, Tripwire and Dimensional Research surveyed hundreds of professionals responsible for securing IoT Devices. Their responses reveal why today’s connected environments create major security gaps—and why organizations still struggle to keep up.

Why Securing IoT Devices Is So Difficult
Nearly every security professional surveyed (99%) said they face obstacles when trying to secure their organization’s IoT Devices. Many of these challenges stem from the rapid growth of devices and the lack of visibility across environments.
1. Poor Visibility and Inventory Management
About 60% said they struggle to maintain an accurate inventory. Without knowing what devices exist, teams cannot monitor or protect them. As one expert put it: “You can’t secure what you can’t see.”
2. Inconsistent Configuration and Weak Policy Enforcement
More than half of respondents noted issues with:
-
Enforcing security policies
-
Setting secure configurations
-
Detecting unauthorized changes
These weaknesses leave IoT Devices exposed to attacks that exploit default settings or outdated software.
3. Limited Forensic Data After Incidents
Over one-third of security professionals said they cannot collect the data needed after a suspected breach. Without logs, alerts, or behavior records, incident response becomes slow and incomplete.
Industrial IoT Devices Create Even Bigger Risks
Organizations that rely on industrial machinery face unique risks. Historically, security practices focused on traditional IT—servers, workstations, and networks. But industrial systems combine operational technology (OT) with connected sensors and cloud apps.
This convergence means security teams must:
-
Understand how machines behave
-
Track more data sources
-
Monitor IoT Devices that were never designed with security in mind
Additionally, 53% of experts worry about privacy risks created by these devices, while 42% say they are highly concerned about overall security weaknesses.
Why Current Security Strategies Aren’t Enough
Most organizations admit their current methods do not cover all IoT Devices. In fact:
-
75% say connected devices don’t fit into their existing security models
-
88% say they need more resources to implement proper protection
-
97% are concerned about supply-chain risks created by these devices
As attacks grow more sophisticated, many companies fear they cannot keep up without major changes.

Supply Chain Security Is a Growing Concern
A large majority of cybersecurity and industrial security experts worry that IoT Devices introduce new supply chain risks. Many do not fully understand how vendors handle updates, firmware security, or device-level data.
Key findings include:
-
97% fear vulnerabilities within their supply chain
-
86% believe IoT security policies are not strong enough
-
59% increased their supply-chain security budgets
Because supply-chain attacks continue to grow, organizations recognize the need for stronger standards around industrial control systems (ICS) and device-level security.
How Organizations Can Respond
To secure the future, businesses must rethink how they manage and protect IoT Devices. This includes:
-
Stronger inventory and discovery tools
-
Continuous monitoring
-
Unified security policies across IT and OT
-
Better forensic logging
-
Vendor risk assessments
-
Compliance with evolving industry frameworks
Organizations that modernize their security model today will be better prepared for tomorrow’s threats.
Share This Post
Adopting Microsoft Teams And Using it with WebEx