Why IoT Devices Are the Hardest Assets to Secure on Your Network
1 in 3 data breaches now involves an IoT device. Find out why traditional IT security tools fail for connected devices, and where to apply security instead.
Eight hardware vendors, eight VPN tunnels, and one flat network behind all of them. Here is the model that replaces it.
You give a third-party vendor remote access to an industrial device without a VPN by brokering the session instead of joining the network. The vendor authenticates to a broker, the broker checks the policy, and the connection is initiated outward from inside your environment to the one device that vendor is authorised to reach. The vendor gets SSH, VNC or RDP in a browser, time-limited and recorded. No client software, no inbound firewall rule, and no route to anything else.
A VPN puts the vendor on your network. Access control after that point depends on segmentation you built for a different purpose, firewall rules maintained by people who have moved on, and the vendor's own laptop hygiene.
One compromised vendor endpoint reaches everything that endpoint's route allows. In an OT environment that is more than one device. Lateral movement is the whole risk, and a VPN concentrates it.
The operational problems arrive first. Eight hardware vendors mean eight VPN configurations, overlapping private address ranges, and a support call every time a tunnel drops. IP conflicts between vendor networks are a standing tax on the team maintaining them.
Then there is the audit question. Who connected, to which device, when, and what did they do. A VPN log answers the first part and none of the rest.
Zero Trust access inverts the direction of the connection. Nothing listens on a public address. An App Connector inside your environment opens an outbound session to a broker, the Zero Trust Exchange, and the broker stitches the authorised vendor session onto it. Ports stay closed because there is nothing to expose.
Privileged Remote Access is the part the vendor sees. The vendor opens a browser, authenticates, and gets a console session to a named device. No agent on the device, and none on the vendor's laptop. That matters for industrial hardware, because most of it will never run a client. No operating system to host one, no memory to spare.
Access is scoped to one application on one device rather than to a network range. Least privileged access is the term for it. The difference is between handing over a key to a room and a key to the building.
Sessions are time-limited, recorded and co-viewable, so your engineer watches while the vendor works. The recording is the audit trail: every device, every user, every third-party contractor that accessed that device, and what actions they took.
Take a European EV charging operator with eight hardware vendors. Each vendor needs access to its own chargers and nothing else. With VPNs, that is eight tunnels, overlapping addressing, and network-wide exposure per vendor. With brokered access, each vendor gets a browser session, restricted to business hours, recorded, initiated from the Zero Trust Exchange. No client install. No IP conflicts. No route beyond the specific device.
Those devices reach the network over cellular rather than fixed lines, so keep the layers separate when you design it. The SIM identifies the device. SecureNet keeps device traffic off the public internet. The Zero Trust layer checks every session before a connection opens.
IXT Zero Trust addresses NIS2 Article 21(2) technical controls: access control, network segmentation, incident detection, supply chain access, audit trail and continuous authentication. Supplier access is the measure most industrial operators find hardest to evidence, and a recorded, policy-scoped session is direct evidence.
It does not make you compliant on its own. Risk documentation, incident response plans, staff training and supplier governance stay with you. NIS2 puts personal liability at board and C-suite level, which is why that distinction is worth stating plainly rather than blurring.
List your vendors and the exact devices each one needs to reach. Most lists come out shorter than the access currently granted. That gap is the finding.
Then take the vendor with the widest access and the least oversight, and move that one first. Ask us how it works for your deployment.
Related articles
1 in 3 data breaches now involves an IoT device. Find out why traditional IT security tools fail for connected devices, and where to apply security instead.
VPN was built for users, not devices. Learn why it fails in IoT environments and how Zero Trust security eliminates the attack surface without client software.
NIS2 covers IoT and OT devices. Standard SIM connectivity leaves most organisations exposed. Here is what the directive actually requires and why it matters for connected devices.