| IoT security is the practice of protecting the connected equipment on a business network: cameras, sensors, smart TVs, door controllers and payment terminals. IoT security means knowing what is connected, keeping supported devices updated, controlling who can administer them, and limiting what they can reach. |
Start your IoT security count with the things on your network that have an IP address and no keyboard.
A small office turns up eight or nine without trying. Four security cameras, a video doorbell, the meeting room display, two printers, an EFTPOS terminal, the heat pump controller and whatever the landlord installed in the ceiling.
Now name the last person who logged into any of them. For most businesses the honest answer is the installer, on the day it went in.
Those devices are the gap that IoT security has to close. Your laptops get patched, your servers get monitored and your staff get trained, while a camera running firmware from 2021 sits on the same network with a password printed in a manual anyone can download.
In April 2026 the National Cyber Security Centre joined fifteen international partners in an advisory on covert networks, the large-scale device networks, commonly called botnets, that are used to hide malicious activity. It names what those networks are built from: small office routers, internet of things and smart devices, firewalls, and network attached storage.
Read that list again. Cameras and storage boxes appear on it because they make useful infrastructure for somebody else’s attack, whatever they happen to record.
What Is IoT Security in a Business Setting?
IoT security is the set of controls that protect connected equipment through the capabilities it actually has. The internet of things, usually shortened to IoT, covers any device that reports to a network without a person driving it.
What these devices share is that they sit outside the processes used to manage laptops and servers. Most of them support account management, firmware updates, service restrictions and logging. What varies is how much, and whether anyone has ever looked.
A laptop tells you it needs updating. A camera says nothing at all, for years, and keeps sending pictures the whole time.
So the first step in IoT security is to give every device an owner and a maintenance plan. A Windows-based recorder, a managed tablet and an embedded camera all belong in the same discussion, and none of them should be treated the same way.
Which devices count as IoT in a normal business?
More than owners expect, because the label rarely appears on the purchase order. Anything below is on the list.
- Security cameras and video doorbells, along with the recorder they write to.
- Printers and multifunction devices, which hold scanned documents and often a web interface.
- EFTPOS and payment terminals, and the tablets running a point of sale app.
- Access control: door readers, electric strikes and the intercom at the gate.
- Building services, meaning heat pumps, lighting controllers, alarm panels and irrigation timers.
- Meeting room displays, smart TVs and the conferencing bar under the screen.
- Network attached storage, or NAS, the box in the cupboard holding backups and shared files.
The last two on that list surprise people. A smart TV is a computer with a browser and a microphone, and a network attached storage box is a Linux server that nobody administers.

What Are the Biggest IoT Security Risks?
The biggest IoT security risks come from devices being useful, always on and unwatched, which is a different problem from data theft. An attacker who takes a camera gains a machine inside a real business network that nobody is looking at.
It gets put to work straight away. The device relays traffic so other attacks appear to come from a legitimate New Zealand address, it holds a dormant foothold for later, and it scans the network it sits on.
The economics favour the attacker. Finding one unpatched camera model gives access to every business that bought it, and the search costs nothing.
One line in the advisory explains the scale. It reports evidence that these covert networks are created and maintained by Chinese information security companies, and used for activity such as scanning as part of reconnaissance, so the person using your camera may never have chosen it.
For a small business that changes the IoT security calculation. Nobody picked you, and nobody is going to skip you either, because the whole thing runs on scanning for models with known holes.
What does an attacker do with a hacked camera?
Usually nothing you would notice. The device keeps working, the picture keeps recording, and the only sign is traffic leaving at odd hours to places your business has no reason to reach.
The damage arrives later. A foothold that sat unused for three months becomes the route to a file server, and the incident report has to explain a device nobody could name.
Some businesses find out from their internet provider. Traffic from a conscripted device draws a complaint, and the first conversation about IoT security happens with a service desk asking why.
Why Can’t You Just Install Antivirus on These Devices?
Because most of them cannot accept it. Security software needs an operating system that takes third-party code, and a camera or a door controller runs firmware that does not.
Two different disciplines meet here. Managed computers are covered by endpoint security, where an agent reports back, and everything in this post is about the devices no agent can reach.
That does not leave nothing to configure. Secure these devices through the controls they do support: current firmware, unique credentials, administration restricted to the people who need it, and unnecessary services switched off. Network separation then limits what a compromised device could reach.
Separation reduces exposure rather than removing it, which is where IoT security is most often misunderstood. A segmented camera still records identifiable people and a segmented door controller still opens a door, so the device keeps whatever value it had to whoever reaches it.
The vendor platform is worth checking rather than dismissing. Some management platforms report firmware status, access history and security settings, and some show only a live picture. The useful question is which one this product gives you, because an app that shows the camera feed proves nothing except that the device is reachable.
What happens when the manufacturer stops issuing firmware?
The device keeps working and stops being fixable, which is the most common IoT security problem in small business. A camera range sold in 2019 may have had its last firmware in 2022.
After that date, newly discovered vulnerabilities may stay unpatched, because no fix is coming. That is not the same as every flaw applying to your installation, and it does not mean nothing can be done, so review the device against its exposure, what it actually does, and the safeguards available to it.
Priority follows risk rather than age. An unsupported recorder with its administration reachable from the internet needs attention ahead of an older camera that can reach nothing but its recorder.
Then it becomes a replacement decision, which is a budget conversation, and a hard sell when the equipment still produces a perfectly good picture. The practical IoT security answer is to date the fleet, find the end-of-support year for each model, and put replacement in the capital plan before the auditor or the insurer asks.
How Do You Find Every Connected Device You Own?
Start with the records you already hold, then walk the building, because neither finds everything on its own. Switch, WiFi, DHCP and vendor management platforms between them list most of what is connected, and the walk finds what sits on a separate connection nobody documented.
Scan where you need to, and agree it first. Some equipment is supplier-managed or sensitive to being probed, so IoT security work goes better when the scan is arranged with whoever maintains the device than when a payment terminal drops out mid-afternoon.
A walk usually turns up two or three devices the business had forgotten. A camera at the back of a store that was left when the tenancy changed, or a printer in a cupboard still holding scanned records.
The walk matters because of the ones installed by somebody else. Alarm companies and landlords put connected equipment on premises, and so do vending and coffee machine suppliers. All of it lands on your network.
Before you change anything, find out what depends on it. Agree credential, firmware and network changes with the provider responsible for the device, then confirm afterwards that recording, payments, door access or whatever else it drives still works.
What should a device inventory record?
An IoT security inventory needs enough to make a decision without going back to the cupboard: what the device is, where it sits, its model and firmware version, who installed it, who can log in, and the year support ends.
That last field is the one nobody fills in and the one that drives the budget. A list without support dates tells you what you own and not what you have to do about it.
Keep it somewhere your provider can see. An inventory in one person’s spreadsheet stops working the week that person leaves.
How many suppliers can reach your network?
Supplier access is the IoT security gap that inventories miss, because remote access is usually installed as a convenience and never reviewed. The alarm company, the camera installer, the heat pump technician and the point of sale vendor may all hold a way in.
Each of those paths was set up for a good reason on the day. The problem is that none of them expires, and the person who used it last may have left that company years ago.
Ask every supplier three things: who at your end authorised the access, what it reaches, and how it is logged. If they cannot answer the third one, you have no way to audit what they did.
Where the access is needed, put it behind something you control. Give them a named account you can switch off, so removing the access later takes one minute and no phone calls.
Who Manages Devices Installed by Another Supplier?
Agree three things and write them down: who owns the equipment, who maintains its software, and who controls its network connection. They are frequently three different answers. The installer may manage the device while your IT provider manages what it is allowed to reach, and both need to know who can connect remotely and who approves a change.
Allowing equipment onto your network makes the risk yours. It does not make you its administrator, and an IoT security conversation that opens by assuming otherwise tends to stall.
Keep supplier access to the equipment they support, on individual accounts with multi-factor authentication where the platform offers it, and remove it when the contract or the person changes.
Include the vendor portal in that discussion. Controlling your own network does not remove the access an installer holds through a cloud management account, and that access often survives every change you make on site.
What Should You Ask Before Buying a Connected Device?
Ask how long it will get security updates, and get the answer in writing before the purchase order. Price and picture quality are easy to compare in a showroom, while support lifetime sets what this device will cost you over eight years.
Seven IoT security questions separate a device you can run from one you will be stuck with.
Until what date will this model receive security updates?
Get the answer in writing before the purchase order. If the vendor cannot say, assume the answer is the day you buy it.
Does each unit ship with a unique password?
Or does the whole product line share one, so that a single leaked credential opens every device you own.
How do I report a vulnerability?
Ask whether the vendor has published a disclosure policy. A supplier with no route for reporting flaws is unlikely to be fixing them.
Does the device need the internet to work, or only to be convenient?
Plenty of cameras and controllers run perfectly on a local network and phone home only for a remote-viewing app the business never uses.
Can the business own and recover the administration account?
If the installer holds the only administrator login, you depend on that company for the life of the equipment and for whatever it costs to get back in.
What keeps working if the internet or the vendor cloud service fails?
Some devices keep recording and keep releasing doors on their own. Others stop, which turns a broadband fault into a building access problem.
How are data, accounts and remote access removed when the device is retired?
Ask before you buy. A recorder sold, returned or skipped with its footage and its accounts intact is a privacy problem with your name on it.
That last one is worth pressing. Plenty of cameras and controllers run perfectly on a local network and phone home only for a remote-viewing app the business never uses.

One more IoT security habit deserves attention at purchase time. Installers frequently set the same password across every device they commission, so a fleet of twelve cameras has one credential between them.
One leaked credential then opens the whole fleet. Ask for unique credentials per device, and have them handed over into a shared vault rather than a spreadsheet or an email thread, so the handover does not become the weakness.
Is there an IoT security standard for connected devices?
Yes. ETSI EN 303 645, currently at version 3.1.3 published in September 2024, sets baseline cyber security requirements for consumer internet of things devices.
Its leading provisions are the ones a buyer can check without a lab: no universal default passwords, a published way to report vulnerabilities, and software that can be kept updated.
The standard notes that shared default credentials across a product line have caused many IoT security problems and that the practice needs to stop. A unique per-device password satisfies the provision.
Its scope is consumer internet of things, which covers a good deal of what a business actually buys, including cameras, displays and smart building equipment. It does not extend to industrial controllers, payment systems or enterprise appliances, so it is a useful question rather than a complete one.
You do not need to read the document. Ask the vendor whether the product was built against it, because a supplier who knows the standard will answer the update-lifetime question without checking. Familiarity is not proof, though. Knowing the standard says nothing on its own about whether this particular product is secure.
What Privacy Rules Apply to CCTV and Security Cameras?
The Privacy Act applies to CCTV, because a camera collects personal information about identifiable people. That puts your camera footage in the same legal category as your customer database, which is the part most businesses miss.
The consequence is a right of access. Under privacy principle 6 a person can ask for footage of themselves, and the Office of the Privacy Commissioner’s guidance on CCTV access requests says the starting point is that you give it to them.
That guidance turns a camera purchase into an IoT security decision. You must secure the relevant footage as soon as a request arrives so it is not overwritten, and lacking the ability to blur other people in the frame is not accepted as a reason to refuse.
Newer systems include facial blurring in the management software and older ones do not, so add it when you next upgrade. Deliberately deleting footage, or allowing it to be deleted knowing a request has been made, is an offence carrying a fine of up to $10,000.
Put that beside the price of a recorder. A system chosen on cost alone can turn a routine request into a bill and a complaint.
Where Should Connected Devices Sit on Your Network?
On their own segment, with rules that let them do their job and nothing else. A camera needs to reach its recorder, and it has no business reaching your file server.
Designing those zones is part of our network security services, and the rules are enforced at the managed firewall where somebody reviews them. Visitor traffic is a separate question again, handled in guest WiFi.
The IoT security part is what the rule should say. Allow the device to its controller, allow the updates it needs, deny the rest, and log what gets denied so you find out when a device starts behaving differently.
One practical IoT security trap: putting cameras on the guest network because it is already separate. A guest network is configured to hand visitors an internet connection, usually with client isolation and no route to internal systems, so a camera placed on it may lose the path to its recorder while keeping its path out to the internet. What settles the question is the rules on that network, not its name.
What if a device has to be reachable from outside?
Put it behind a connection you control instead of opening a port to it. Forwarding a port to a recorder publishes that device to the entire internet, and scanning services index it within hours.
The alternative is a virtual private network, shortened to VPN, or the vendor’s own relay service if it supports one properly. Staff connect to the business first and reach the device from inside.
On most small networks this change does more for IoT security than anything else on the list. A recorder that was directly exposed and now sits behind a VPN has stopped being findable at all.
Check what is already exposed before assuming your IoT security covers it. Installers open ports to make remote viewing work on handover, and nobody closes them afterwards.
How would you know if a device had been compromised?
From its traffic, because the device itself will not tell you. Watch for a camera that suddenly talks to an address in another country, at volume, in the small hours.
That means somebody has to be watching the boundary and know what normal looks like for each segment. Logging denied traffic gives you the IoT security baseline, and monitoring turns the baseline into an alert.
Without it the discovery route is external. An internet provider notice, a blocklist entry or a customer complaint all arrive after the device has been working for somebody else for weeks.
What Does It Cost to Get IoT Security Under Control?
What IoT security costs depends less on how many devices you have than on what is already in place. The first pass is usually configuration work rather than capital, and replacement is the part that costs real money, which can be staged across budget years.
| What changes the scope | What to look at |
|---|---|
| Configuration work, usually the first pass | |
| Sites and device types | How many locations, and how many different kinds of equipment rather than how many units |
| Supplier coordination | How many installers and vendors have to agree a change, and whether the work needs out-of-hours windows |
| Credential, firmware and access cleanup | How many devices still hold shared or default credentials, and how many remote-access paths have to be traced and closed |
| Equipment, where the real money is | |
| Existing switches and WiFi Check first |
Whether what is installed can separate device traffic properly, or has to be replaced before anything else is possible |
| Replacement equipment Can be staged |
How much of the fleet is past support, and what installation and ongoing management it needs |
Do not assume discovery and separation can always be done on the equipment already in place. A network built without segmentation in mind sometimes needs the switching replaced first, and that is the finding that moves a budget rather than the device count.
Something else is starting to force the issue. Insurers and larger customers now ask what is on your network and how it is separated, and a contract questionnaire is a poor place to discover you cannot answer.
Ask for a scoped quote after the discovery step, because that is the first point at which a number means anything. Read it against a single compromised device, where the cost is incident response plus the time spent explaining it to a customer.
What can you do this week for nothing?
Two IoT security jobs, both free. Walk the building and write down every device with a network cable or a WiFi connection, then find out who maintains the three that matter most before anyone touches their credentials.
Write the date beside each entry as you go. A list with dates on it becomes a plan, because you can sort it by age and start at the top.
When you do change credentials, put the new ones straight into a shared vault the team can reach rather than a document or an email. Our guide to choosing a password manager covers what an approved vault has to do.
The recorder behind your cameras is usually the right place to start. It holds the footage, it frequently has a web interface open, and it is the device most likely to still be on factory credentials.
Get the Devices Nobody Is Managing Under Control
Exodesk has operated since 1989, with offices in Christchurch and Dunedin serving businesses across New Zealand. Our IoT security work finds what is on your network, separates the devices from the systems they have no business reaching, and tells you which ones are past saving. Our cyber security work covers the monitoring that watches them afterwards.
Contact us today to discuss how we can help your business or connect with us on LinkedIn to stay updated with more insights.
Frequently Asked Questions
What does IoT stand for?
IoT stands for internet of things, meaning physical equipment that connects to a network and reports data without a person operating it. In a business that covers cameras, printers, payment terminals, door readers, building controllers and smart displays. The common thread is that they sit outside the processes used to manage computers, so nobody notices when one needs attention.
Why is IoT security different from normal cyber security?
Normal cyber security assumes you can install software on the thing you are protecting. Most connected devices accept no security agent, so IoT security works through the controls they do support, meaning current firmware, unique credentials and restricted administration, together with limits on what they are allowed to reach across the network.
How do I find all the connected devices on my network?
Start with your switch, WiFi, DHCP and vendor platform records, then walk the building, because each method misses what the others find. Scan where you need to, agreeing it first with whoever maintains supplier-managed or sensitive equipment. The walk catches gear installed by alarm companies, landlords or suppliers that never made it onto any register.
Do IoT devices need antivirus software?
Most cannot run it. Protection comes from the controls the device does support, meaning current firmware, unique credentials, restricted administration and unnecessary services turned off, together with putting it on its own network segment and monitoring its traffic. A device running a full operating system, such as a Windows-based recorder, is a computer and should get the usual endpoint protection.
What is the most common IoT security mistake?
Leaving the credentials the device shipped with. Shared default passwords are published in manuals and vendor forums, so a device still using one is reachable by anybody who identifies the model. The recorder behind a camera system is the usual offender.
Is there an IoT security standard I can ask suppliers about?
Yes. ETSI EN 303 645 sets baseline cyber security requirements for consumer internet of things devices, and its leading provisions are no universal default passwords, a published vulnerability disclosure process, and software that can be updated. It covers consumer devices, including consumer products bought for business use, rather than industrial controllers, payment systems or enterprise appliances. Asking whether a product was built against it tells you something about the supplier, though it is not evidence that the product itself is secure.
What happens when a device stops getting firmware updates?
Newly discovered vulnerabilities may stay unpatched, because no fix is coming. That does not mean every flaw applies to your installation or that nothing can be done, so review the exposure, what the device does and what safeguards are available, then plan replacement by risk rather than age. The device carries on working normally, which is why these survive years past the point where they should have gone.
Do security cameras create legal obligations in New Zealand?
Yes. CCTV footage of identifiable people is personal information, so the Privacy Act applies and individuals can request footage of themselves under privacy principle 6. Preserve the relevant footage promptly when a request arrives, verify who is asking, and consider other people in the frame before releasing it. Deliberately deleting footage, or allowing it to be deleted knowing a request has been made, can be a criminal offence.
Can I put my cameras on the guest WiFi to keep them separate?
It is a common mistake. A guest network is normally configured to give visitors an internet connection, with client isolation and no route to internal systems, so a camera on it may lose the path to its recorder while keeping its path out to the internet. What decides the question is the rules on that network rather than its name, and connected devices are better on their own segment with rules written for them.
How much does IoT security cost a small business?
Most of the first pass is configuration on equipment you already own, so it usually costs less than owners expect. What moves the number is how many sites and device types are involved, whether the existing switches and WiFi can separate device traffic without being replaced, how many suppliers have to agree changes, and how much of the fleet is past support. Ask for a scoped quote after discovery, because that is the first point at which a figure means anything.
Who is responsible for a device the landlord installed?
Allowing it onto your network makes the risk yours, but that does not make you its administrator. Agree who owns the equipment, who maintains its software and who controls its network connection, because those are often three different parties. Document the make and model, find out who holds the admin login and whether the contractor also keeps access through a vendor portal, then put that connection on a segment of its own.
Can a connected device keep working without its cloud service?
It depends on the product, which is why it is worth asking before you buy. Some cameras keep recording locally and some door controllers keep releasing doors on a stored schedule when the connection drops. Others stop, lose remote administration, or cannot be reconfigured until the vendor service returns. Find out which behaviour you are buying, because it decides whether a broadband fault is an inconvenience or an operational problem.
What should happen before a device is sold, returned or replaced?
Remove the data and the access before the hardware leaves. Wipe stored footage, scans or transaction records, remove the accounts on the device, and disconnect it from any vendor cloud portal so it is no longer tied to your organisation. Cancel whatever remote access suppliers held to it, and take it off the inventory. A recorder or printer passed on with its contents intact is a privacy breach waiting to be found by whoever receives it.
Can Exodesk help a New Zealand business with IoT security?
Yes. Exodesk has operated since 1989, with offices in Christchurch and Dunedin serving businesses across New Zealand. We handle discovery, network separation, the credential and firmware work, and the monitoring that follows.
Could you list every device on your network?
Cameras, door controllers, TVs and payment terminals rarely appear on anybody’s asset list, and none of them will tell you when they stop being supported. A free IT assessment scans what is actually connected, so the list is real rather than remembered.
Or read more about our cyber security services.

