Securing your IoT devices: 8 lessons from IXT and Illumio
Eight lessons from IXT and Illumio on securing IoT and OT devices that cannot run agents: patch limits, Zero Trust, visibility and lateral movement.
Your security plan was written for laptops. Your chargers, meters, pumps and controllers were never part of that conversation. One of Trevor Dearing's customers summed up the gap in one line: "My next patching opportunity is February 2027."
On 8 October, Henning Solberg, CTO at IXT, and Trevor Dearing, who runs the Industry Solutions team at Illumio, spent an hour on the devices at the bottom of every security plan. The ones that cannot run an agent, cannot take a patch on demand, and cannot tell you when something is wrong. These are the eight lessons that came out of it. The full session is available as a recording on demand.
1. IoT and OT are two different problems
IoT devices such as sensors, meters and trackers work on their own and report straight to a cloud or head-end system. OT devices sit inside a hierarchy of industrial control systems: production lines, electricity grids, water treatment, EV chargers. Treat them as one category and you build blind spots into your plan.
Henning added a twist. IoT devices with AI at the edge are starting to behave more like OT. The line between the two keeps moving, and your security model has to move with it.
2. You cannot secure OT the way you secure IT
CISOs are inheriting OT security as plants and grids connect to the rest of the business. The IT playbook breaks on contact. Patch windows come once or twice a year. Active vulnerability scans have crashed OT environments, so discovery has to be passive. Agents that reach into the kernel are a risk in their own right.
The goal is different too. OT security is about keeping the operation running. IT security adds the integrity of data on top.
Constrained devices make this harder still. A small microcontroller, unattended in a cabinet, has no room for security software. If the device cannot protect itself, the network has to show you where it talks and whether it does something it shouldn't.
3. Regulation is enforced now, whatever your sector
NIS2, the Cyber Resilience Act and the Radio Equipment Directive all reach remote devices. If you operate or build connected equipment, at least one of them applies to you.
Trevor flagged a gap in the Cyber Resilience Act. It requires products to ship secure, but it does not define what secure means. That puts the burden on you as a buyer to make vendors show their work. He also pointed to joint guidance on secure OT connectivity from the UK NCSC, German, Dutch and other national authorities. Read it now. Today's guidance becomes tomorrow's regulation.
4. AI changes the speed of attacks, not the basics
AI finds vulnerabilities faster than any team patches them. If you are struggling to close the ten you know about, a thousand more from automated discovery will not help. The answer is prevention. Surround the most exposed systems so a known weakness has nowhere to go.
Most successful attacks still come through basic faults and misconfigurations, not sophistication. As Trevor put it: "Cyber security isn't about technology, it's about policy."
There is an upside. Boards now discuss patching. That gives security teams an opening for budget conversations they did not have two years ago.
5. Zero Trust means allowing the good, not hunting the bad
Trevor's definition is the clearest we have heard: "Zero Trust is a shift away from trying to find the bad stuff and stopping it, to identifying the good stuff and allowing it." There is far less good traffic than bad, so the allow list is the smaller and more manageable job.
In OT, that means explicit rules. "Device A talks to device B using a specific protocol, and nothing else." Headless devices cannot be changed, so enforcement lives in the network: switch access lists, firewalls and Zero Trust Network Access (ZTNA). VLANs only count as security when dynamic VLAN protocols are switched off.
Connectivity providers have to change as well. Henning was candid about it: "Maybe we have been a bit naive. We are providing the bit pipe... we thought the customer would be safe within that environment. This is rapidly changing now." A private APN hides traffic. It does not defend it.
6. Cellular gives you a head start
A wired or Wi-Fi network is a shared space. Cellular is point-to-point by design. Each device connects on its own, and endpoints are shielded from each other before any policy is applied. In Henning's words, cellular "gives that endpoint protection from the ground up."
Trevor sees the same shift on the ground. Factories and energy sites are moving to 5G for reliability and because it is easier to secure.
7. You can't protect what you can't see, and the first map always surprises
A real-time map of who talks to whom shows you the connections nobody planned for. Henning described an EV charger configured to reach one OCPP backend. The map showed the manufacturer's cellular module also reaching a firmware server abroad, plus time sync and other protocols nobody had accounted for. Trevor shared a bank whose ATMs were "only connected to one place". The map showed six other connections.
Visibility also changes how you rank risk. Exposure is the vulnerability score plus how many things a system connects to. A high-scoring system with one controlled connection is low exposure. A low-scoring workstation connected to ten things is high exposure. Until you patch, restrict what a system talks to. Trevor calls this virtual patching. His first practical step: search your OT estate for RDP and remove it.
8. Assume they get in. Stop them moving.
Trevor explained lateral movement with a burglar. They get in through an open window, then walk to the room with the valuables. Your job is to keep them locked in the first room. Attacks are inevitable. Containment is the part you control.
The EV charger shows why. The app, the card payment and the SCADA link that controls power all sit in one box. Each needs its own boundary. That is the case for micro-segmentation, and the topic of our next session.
Where to start
An attendee asked whether to enforce rules top-down or bottom-up. Trevor's answer was risk-led. Label every system, from your CMDB or an asset discovery tool. Add vulnerability and threat data. Then work in three steps. First, surround the high-risk, high-exposure systems. Second, separate IT from OT and IoT. Third, apply explicit allow policies between your most important systems. Default deny is the end state of Zero Trust. It is rarely day one.
The session tested these ideas against three sectors. EV charging networks run mixed fleets from several vendors, with OCPP alongside CoAP and MQTT, and third parties who need remote access. Electricity grids now connect hydro, solar, wind and other producers into systems built on ageing protocols. Water and sewage operators run remote, unattended pump stations, with cyber budgets that compete against leaks and spills.
How IXT applies this to existing fleets
Most fleets in the field cannot be changed. IXT moves enforcement to the network instead. The IXT SIM identifies the device. SecureNet keeps its traffic on a private APN, off the public internet. Zscaler ZTNA in IXT's core network checks every session before a connection opens. Illumio gives you the traffic map and policy-based segmentation on top.
Nothing is installed on the device. That works for a small sensor and for a 5G router alike. Trevor's verdict: "This solution does simplify things a lot, especially at the headless end for those devices."
Watch the full session
The recording covers each lesson in more depth, including both audience questions and the three use cases. Watch it on demand, and look out for our follow-up session on micro-segmentation.
Why trust this guide
This guidance is based on real IoT and OT deployments in regulated industries including energy, utilities, and industrial environments.
IXT designs and operates secure connectivity architectures where:
- devices are deployed across multiple countries and networks
- SIM-level identity is enforced at the network edge
- third-party access is controlled without VPNs
- audit trails are required for regulatory compliance (including NIS2)
The patterns described here reflect how these environments are secured in practice, not theoretical models.
About the author
This article was written by the IXT Connectivity and Security team.
IXT operates a full MVNO core network and delivers secure IoT connectivity across 190+ countries and 600+ mobile networks. The team works directly with industrial, utilities, and infrastructure operators to design and secure large-scale IoT and OT deployments.
Their focus is on network-level Zero Trust architecture, SIM-based identity, and secure device communication without relying on VPNs or endpoint agents.
Related articles